Branch was auto-updated.

This commit is contained in:
Bhavin Patel
2024-08-21 14:25:26 +05:30
committed by GitHub
342 changed files with 1379 additions and 1395 deletions
@@ -1,7 +1,7 @@
name: Abnormally High Number Of Cloud Infrastructure API Calls
id: 0840ddf1-8c89-46ff-b730-c8d6722478c0
version: 2
date: '2024-05-12'
version: 3
date: '2024-08-16'
author: David Dorsey, Splunk
status: experimental
type: Anomaly
@@ -47,7 +47,7 @@ tags:
- name: user
type: User
role:
- Attacker
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Abnormally High Number Of Cloud Security Group API Calls
id: d4dfb7f3-7a37-498a-b5df-f19334e871af
version: 2
date: '2024-05-22'
version: 3
date: '2024-08-16'
author: David Dorsey, Splunk
status: experimental
type: Anomaly
@@ -47,7 +47,7 @@ tags:
- name: user
type: User
role:
- Attacker
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS SAML Update identity provider
id: 2f0604c6-6030-11eb-ae93-0242ac130002
version: 2
date: '2024-05-19'
version: 3
date: '2024-08-19'
author: Rod Soto, Splunk
status: production
type: TTP
@@ -48,7 +48,6 @@ tags:
type: User
role:
- Victim
- Target
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Cloud Instance Modified By Previously Unseen User
id: 7fb15084-b14e-405a-bd61-a6de15a40722
version: 2
date: '2024-05-17'
version: 3
date: '2024-08-16'
author: Rico Valdez, Splunk
status: experimental
type: Anomaly
@@ -45,7 +45,7 @@ tags:
- name: user
type: User
role:
- Attacker
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Abnormally High AWS Instances Launched by User
id: 2a9b80d3-6340-4345-b5ad-290bf5d0dac4
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: Anomaly
@@ -36,10 +36,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: userName
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Abnormally High AWS Instances Launched by User - MLTK
id: dec41ad5-d579-42cb-b4c6-f5dbb778bbe5
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-15'
author: Jason Brewer, Splunk
status: deprecated
type: Anomaly
@@ -32,10 +32,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: src_user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Abnormally High AWS Instances Terminated by User
id: 8d301246-fccf-45e2-a8e7-3655fd14379c
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: Anomaly
@@ -36,10 +36,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: userName
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Abnormally High AWS Instances Terminated by User - MLTK
id: 1c02b86a-cd85-473e-a50b-014a9ac8fe3e
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-15'
author: Jason Brewer, Splunk
status: deprecated
type: Anomaly
@@ -31,10 +31,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: src_user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: ASL AWS Excessive Security Scanning
id: ff2bfdbc-65b7-4434-8f08-d55761d1d446
version: 1
date: '2023-06-01'
version: 2
date: '2024-08-16'
author: Patrick Bareiss, Splunk
status: deprecated
type: Anomaly
@@ -35,7 +35,7 @@ tags:
- name: identity.user.name
type: User
role:
- Attacker
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Cloud Provisioning From Previously Unseen City
id: 344a1778-0b25-490c-adb1-de8beddf59cd
version: 1
date: '2018-03-16'
version: 2
date: '2024-08-16'
author: David Dorsey, Splunk
status: deprecated
type: Anomaly
@@ -48,10 +48,10 @@ tags:
mitre_attack_id:
- T1535
observable:
- name: field
type: Unknown
- name: src_ip
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Cloud Provisioning From Previously Unseen Country
id: ceb8d3d8-06cb-49eb-beaf-829526e33ff0
version: 1
date: '2018-03-16'
version: 2
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: Anomaly
@@ -49,10 +49,10 @@ tags:
mitre_attack_id:
- T1535
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Cloud Provisioning From Previously Unseen IP Address
id: 42e15012-ac14-4801-94f4-f1acbe64880b
version: 1
date: '2018-03-16'
version: 2
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: Anomaly
@@ -46,10 +46,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Cloud Provisioning From Previously Unseen Region
id: 7971d3df-da82-4648-a6e5-b5637bea5253
version: 1
date: '2018-03-16'
version: 2
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: Anomaly
@@ -48,10 +48,14 @@ tags:
mitre_attack_id:
- T1535
observable:
- name: field
type: Unknown
- name: user
type: User Name
role:
- Unknown
- Victim
- name: src_ip
type: IP Address
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS EKS Kubernetes cluster sensitive object access
id: 7f227943-2196-4d4d-8d6a-ac8cb308e61c
version: 1
date: '2020-06-23'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -25,10 +25,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user.username
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Clients Connecting to Multiple DNS Servers
id: 74ec6f18-604b-4202-a567-86b2066be3ce
version: 3
date: '2020-07-21'
version: 4
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: TTP
@@ -42,10 +42,10 @@ tags:
mitre_attack_id:
- T1048.003
observable:
- name: field
type: Unknown
- name: src
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Cloud Network Access Control List Deleted
id: 021abc51-1862-41dd-ad43-43c739c0a983
version: 1
date: '2020-09-08'
version: 2
date: '2024-08-15'
author: Peter Gael, Splunk
status: deprecated
type: Anomaly
@@ -30,10 +30,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: userName
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect Activity Related to Pass the Hash Attacks
id: f5939373-8054-40ad-8c64-cec478a22a4b
version: 6
date: '2020-10-15'
version: 7
date: '2024-08-15'
author: Bhavin Patel, Patrick Bareiss, Splunk
status: deprecated
type: Hunting
@@ -40,10 +40,6 @@ tags:
type: Hostname
role:
- Victim
- name: EventCode
type: Other
role:
- Other
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect API activity from users without MFA
id: 4d46e8bd-4072-48e4-92db-0325889ef894
version: 1
date: '2018-05-17'
version: 2
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: Hunting
@@ -50,10 +50,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect AWS API Activities From Unapproved Accounts
id: ada0f478-84a8-4641-a3f1-d82362d4bd55
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: Hunting
@@ -55,10 +55,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: user
type: User Name
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect DNS requests to Phishing Sites leveraging EvilGinx2
id: 24dd17b1-e2fb-4c31-878c-d4f226595bfa
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-16'
author: Bhavin Patel, Splunk
status: deprecated
type: TTP
@@ -50,10 +50,10 @@ tags:
mitre_attack_id:
- T1566.003
observable:
- name: field
type: Unknown
- name: src
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect Long DNS TXT Record Response
id: 05437c07-62f5-452e-afdc-04dd44815bb9
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-15'
author: Rico Valdez, Splunk
status: deprecated
type: TTP
@@ -40,10 +40,10 @@ tags:
mitre_attack_id:
- T1048.003
observable:
- name: field
type: Unknown
- name: Destination IP
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect Mimikatz Via PowerShell And EventCode 4703
id: 98917be2-bfc8-475a-8618-a9bb06575188
version: 2
date: '2019-02-27'
version: 3
date: '2024-08-15'
author: Rico Valdez, Splunk
status: deprecated
type: TTP
@@ -36,10 +36,10 @@ tags:
mitre_attack_id:
- T1003.001
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect new API calls from user roles
id: 22773e84-bac0-4595-b086-20d3f335b4f1
version: 1
date: '2018-04-16'
version: 2
date: '2024-08-19'
author: Bhavin Patel, Splunk
status: deprecated
type: Anomaly
@@ -37,10 +37,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect new user AWS Console Login
id: ada0f478-84a8-4641-a3f3-d82362dffd75
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: Hunting
@@ -37,10 +37,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect Spike in AWS API Activity
id: ada0f478-84a8-4641-a3f1-d32362d4bd55
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: Anomaly
@@ -59,10 +59,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect Spike in Network ACL Activity
id: ada0f478-84a8-4641-a1f1-e32372d4bd53
version: 1
date: '2018-05-21'
version: 2
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: Anomaly
@@ -46,10 +46,10 @@ tags:
mitre_attack_id:
- T1562.007
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect Spike in Security Group Activity
id: ada0f478-84a8-4641-a3f1-e32372d4bd53
version: 1
date: '2018-04-18'
version: 2
date: '2024-08-16'
author: Bhavin Patel, Splunk
status: deprecated
type: Anomaly
@@ -47,10 +47,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect USB device insertion
id: 104658f4-afdc-499f-9719-17a43f9826f5
version: 1
date: '2017-11-27'
version: 2
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: TTP
@@ -34,10 +34,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect web traffic to dynamic domain providers
id: 134da869-e264-4a8f-8d7e-fcd01c18f301
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: TTP
@@ -43,10 +43,10 @@ tags:
mitre_attack_id:
- T1071.001
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detection of DNS Tunnels
id: 104658f4-afdc-499f-9719-17a43f9826f4
version: 2
date: '2022-02-15'
version: 3
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: TTP
@@ -56,10 +56,10 @@ tags:
mitre_attack_id:
- T1048.003
observable:
- name: field
type: Unknown
- name: src
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: DNS Query Requests Resolved by Unauthorized DNS Servers
id: 1a67f15a-f4ff-4170-84e9-08cf6f75d6f6
version: 3
date: '2020-07-21'
version: 4
date: '2024-08-16'
author: Bhavin Patel, Splunk
status: deprecated
type: TTP
@@ -32,10 +32,10 @@ tags:
mitre_attack_id:
- T1071.004
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
+5 -5
View File
@@ -1,7 +1,7 @@
name: DNS record changed
id: 44d3a43e-dcd5-49f7-8356-5209bb369065
version: 3
date: '2020-07-21'
version: 4
date: '2024-08-15'
author: Jose Hernandez, Splunk
status: deprecated
type: TTP
@@ -48,10 +48,10 @@ tags:
mitre_attack_id:
- T1071.004
observable:
- name: field
type: Unknown
- name: src
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Dump LSASS via procdump Rename
id: 21276daa-663d-11eb-ae93-0242ac130002
version: 1
date: '2021-02-01'
version: 2
date: '2024-08-19'
author: Michael Haag, Splunk
status: deprecated
type: Hunting
@@ -48,11 +48,11 @@ tags:
- name: parent_process_name
type: Process
role:
- Parent Process
- Attacker
- name: process_name
type: Process
role:
- Child Process
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: EC2 Instance Modified With Previously Unseen User
id: 56f91724-cf3f-4666-84e1-e3712fb41e76
version: 3
date: '2020-07-21'
version: 4
date: '2024-08-16'
author: David Dorsey, Splunk
status: deprecated
type: Anomaly
@@ -36,10 +36,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: EC2 Instance Started In Previously Unseen Region
id: ada0f478-84a8-4641-a3f3-d82362d6fd75
version: 1
date: '2018-02-23'
version: 2
date: '2024-08-16'
author: Bhavin Patel, Splunk
status: deprecated
type: Anomaly
@@ -35,10 +35,10 @@ tags:
mitre_attack_id:
- T1535
observable:
- name: field
type: Unknown
- name: awsRegion
type: Geo Location
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: EC2 Instance Started With Previously Unseen AMI
id: 347ec301-601b-48b9-81aa-9ddf9c829dd3
version: 1
date: '2018-03-12'
version: 2
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: Anomaly
@@ -36,10 +36,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: EC2 Instance Started With Previously Unseen Instance Type
id: 65541c80-03c7-4e05-83c8-1dcd57a2e1ad
version: 2
date: '2020-02-07'
version: 3
date: '2024-08-16'
author: David Dorsey, Splunk
status: deprecated
type: Anomaly
@@ -36,10 +36,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: EC2 Instance Started With Previously Unseen User
id: 22773e84-bac0-4595-b086-20d3f735b4f1
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-16'
author: David Dorsey, Splunk
status: deprecated
type: Anomaly
@@ -37,10 +37,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Execution of File With Spaces Before Extension
id: ab0353e6-a956-420b-b724-a8b4846d5d5a
version: 3
date: '2020-11-19'
version: 4
date: '2024-08-16'
author: Rico Valdez, Splunk
status: deprecated
type: TTP
@@ -37,10 +37,10 @@ tags:
mitre_attack_id:
- T1036.003
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Extended Period Without Successful Netbackup Backups
id: a34aae96-ccf8-4aef-952c-3ea214444440
version: 1
date: '2017-09-12'
version: 2
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: Hunting
@@ -28,10 +28,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: First time seen command line argument
id: a1b6e73f-98d5-470f-99ac-77aacd578473
version: 5
date: '2020-07-21'
version: 6
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: Hunting
@@ -50,10 +50,10 @@ tags:
- T1059.001
- T1059.003
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: GCP Detect accounts with high risk roles by project
id: 27af8c15-38b0-4408-b339-920170724adb
version: 1
date: '2020-10-09'
version: 2
date: '2024-08-19'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -35,10 +35,10 @@ tags:
mitre_attack_id:
- T1078
observable:
- name: field
type: Unknown
- name: data.protoPayload.authenticationInfo.principalEmail
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: GCP Detect high risk permissions by resource and account
id: 2e70ef35-2187-431f-aedc-4503dc9b06ba
version: 1
date: '2020-10-09'
version: 2
date: '2024-08-16'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -34,10 +34,10 @@ tags:
mitre_attack_id:
- T1078
observable:
- name: field
type: Unknown
- name: data.protoPayload.authenticationInfo.principalEmail
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: gcp detect oauth token abuse
id: a7e9f7bb-8901-4ad0-8d88-0a4ab07b1972
version: 1
date: '2020-09-01'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -30,10 +30,10 @@ tags:
mitre_attack_id:
- T1078
observable:
- name: field
type: Unknown
- name: protoPayload.status.details{}.violations{}.callerIp
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: GCP Kubernetes cluster scan detection
id: db5957ec-0144-4c56-b512-9dccbe7a2d26
version: 1
date: '2020-04-15'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: TTP
@@ -34,10 +34,10 @@ tags:
mitre_attack_id:
- T1526
observable:
- name: field
type: Unknown
- name: src_ip
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Identify New User Accounts
id: 475b9e27-17e4-46e2-b7e2-648221be3b89
version: 1
date: '2017-09-12'
version: 2
date: '2024-08-16'
author: Bhavin Patel, Splunk
status: deprecated
type: Hunting
@@ -29,10 +29,10 @@ tags:
mitre_attack_id:
- T1078.002
observable:
- name: field
type: Unknown
- name: identity
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes AWS detect most active service accounts by pod
id: 5b30b25d-7d32-42d8-95ca-64dfcd9076e6
version: 1
date: '2020-06-23'
version: 2
date: '2024-08-16'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -24,10 +24,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: sourceIPs{}
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes AWS detect RBAC authorization by account
id: de7264ed-3ed9-4fef-bb01-6eefc87cefe8
version: 1
date: '2020-06-23'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -26,10 +26,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user.username
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes AWS detect sensitive role access
id: b6013a7b-85e0-4a45-b051-10b252d69569
version: 1
date: '2020-06-23'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -25,10 +25,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user.username
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes AWS detect service accounts forbidden failure access
id: a6959c57-fa8f-4277-bb86-7c32fba579d5
version: 1
date: '2020-06-23'
version: 2
date: '2024-08-16'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -26,10 +26,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: sourceIPs{}
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes Azure active service accounts by pod namespace
id: 55a2264a-b7f0-45e5-addd-1e5ab3415c72
version: 1
date: '2020-05-26'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -26,10 +26,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user.username
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes Azure detect RBAC authorization by account
id: 47af7d20-0607-4079-97d7-7a29af58b54e
version: 1
date: '2020-05-26'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -26,10 +26,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user.username
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes Azure detect sensitive object access
id: 1bba382b-07fd-4ffa-b390-8002739b76e8
version: 1
date: '2020-05-20'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -25,10 +25,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user.username
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes Azure detect sensitive role access
id: f27349e5-1641-4f6a-9e68-30402be0ad4c
version: 1
date: '2020-05-20'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -25,10 +25,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user.username
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes Azure detect service accounts forbidden failure access
id: 019690d7-420f-4da0-b320-f27b09961514
version: 1
date: '2020-05-20'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -25,10 +25,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user.username
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes Azure detect suspicious kubectl calls
id: 4b6d1ba8-0000-4cec-87e6-6cbbd71651b5
version: 1
date: '2020-05-26'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -28,10 +28,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: sourceIPs{}
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes Azure pod scan fingerprint
id: 86aad3e0-732f-4f66-bbbc-70df448e461d
version: 1
date: '2020-05-20'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -25,10 +25,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: sourceIPs{}
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes Azure scan fingerprint
id: c5e5bd5c-1013-4841-8b23-e7b3253c840a
version: 1
date: '2020-05-19'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -27,10 +27,10 @@ tags:
mitre_attack_id:
- T1526
observable:
- name: field
type: Unknown
- name: sourceIPs{}
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes GCP detect most active service accounts by pod
id: 7f5c2779-88a0-4824-9caa-0f606c8f260f
version: 1
date: '2020-07-10'
version: 2
date: '2024-08-16'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -26,10 +26,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: src_user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes GCP detect RBAC authorizations by account
id: 99487de3-7192-4b41-939d-fbe9acfb1340
version: 1
date: '2020-07-11'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -26,10 +26,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: src_user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes GCP detect sensitive object access
id: bdb6d596-86a0-4aba-8369-418ae8b9963a
version: 1
date: '2020-07-11'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -26,10 +26,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: src_user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes GCP detect sensitive role access
id: a46923f6-36b9-4806-a681-31f314907c30
version: 1
date: '2020-07-11'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -26,10 +26,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: src_user
type: User
role:
- Unknown
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes GCP detect service accounts forbidden failure access
id: 7094808d-432a-48e7-bb3c-77e96c894f3b
version: 1
date: '2020-06-23'
version: 2
date: '2024-08-16'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -28,10 +28,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: src_user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes GCP detect suspicious kubectl calls
id: a5bed417-070a-41f2-a1e4-82b6aa281557
version: 1
date: '2020-07-11'
version: 2
date: '2024-08-16'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -27,10 +27,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: src_user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Monitor DNS For Brand Abuse
id: 24dd17b1-e2fb-4c31-878c-d4f746595bfa
version: 1
date: '2017-09-23'
version: 2
date: '2024-08-16'
author: David Dorsey, Splunk
status: deprecated
type: TTP
@@ -29,10 +29,14 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: query
type: Other
role:
- Unknown
- Victim
- name: IPs
type: IP Address
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: O365 Suspicious User Email Forwarding
id: f8dfe015-dbb3-4569-ba75-b13787e06aa4
version: 1
date: '2020-12-16'
version: 2
date: '2024-08-15'
author: Patrick Bareiss, Splunk
status: deprecated
type: Anomaly
@@ -38,7 +38,7 @@ tags:
- name: ForwardingSmtpAddress
type: Email Address
role:
- Other
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Okta ThreatInsight Login Failure with High Unknown users
id: 632663b0-4562-4aad-abe9-9f621a049738
version: 1
date: '2023-03-09'
version: 2
date: '2024-08-16'
author: Okta, Inc, Michael Haag, Splunk
type: TTP
status: deprecated
@@ -30,10 +30,10 @@ tags:
- T1078.001
- T1110.004
observable:
- name: outcome.reason
type: Other
- name: user
type: User
role:
- Other
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Okta ThreatInsight Suspected PasswordSpray Attack
id: 25dbad05-6682-4dd5-9ce9-8adecf0d9ae2
version: 1
date: '2023-03-09'
version: 2
date: '2024-08-16'
author: Okta, Inc, Michael Haag, Splunk
type: TTP
status: deprecated
@@ -34,7 +34,7 @@ tags:
- name: outcome.reason
type: Other
role:
- Other
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Okta Two or More Rejected Okta Pushes
id: d93f785e-4c2c-4262-b8c7-12b77a13fd39
version: 1
date: '2022-09-27'
version: 2
date: '2024-08-16'
author: Michael Haag, Marissa Bower, Splunk
status: deprecated
type: TTP
@@ -42,7 +42,7 @@ tags:
- name: user
type: User
role:
- Attacker
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Osquery pack - ColdRoot detection
id: a6fffe5e-05c3-4c04-badc-887607fbb8dc
version: 1
date: '2019-01-29'
version: 2
date: '2024-08-15'
author: Rico Valdez, Splunk
status: deprecated
type: TTP
@@ -25,10 +25,14 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: host
type: Hostname
role:
- Unknown
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Processes created by netsh
id: b89919ed-fe5f-492c-b139-95dbb162041e
version: 5
date: '2020-11-23'
version: 6
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: TTP
@@ -43,10 +43,14 @@ tags:
mitre_attack_id:
- T1562.004
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Prohibited Software On Endpoint
id: a51bfe1a-94f0-48cc-b4e4-b6ae50145893
version: 2
date: '2019-10-11'
version: 3
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: Hunting
@@ -34,10 +34,14 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Reg exe used to hide files directories via registry keys
id: 61a7d1e6-f5d4-41d9-a9be-39a1ffe69459
version: 2
date: '2019-02-27'
version: 3
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: TTP
@@ -32,17 +32,20 @@ tags:
- Windows Defense Evasion Tactics
- Suspicious Windows Registry Activities
- Windows Persistence Techniques
asset_type: Endpoint
confidence: 50
impact: 50
message: tbd
mitre_attack_id:
- T1564.001
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Remote Registry Key modifications
id: c9f4b923-f8af-4155-b697-1354f5dcbc5e
version: 3
date: '2020-03-02'
version: 4
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: TTP
@@ -31,10 +31,14 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
- name: dest
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Scheduled tasks used in BadRabbit ransomware
id: 1297fb80-f42a-4b4a-9c8b-78c066437cf6
version: 3
date: '2020-07-21'
version: 4
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: TTP
@@ -13,7 +13,7 @@ data_source:
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime values(Processes.process) as process from datamodel=Endpoint.Processes
where Processes.process_name=schtasks.exe (Processes.process= "*create*" OR Processes.process=
"*delete*") by Processes.parent_process Processes.process_name Processes.user |
"*delete*") by Processes.parent_process Processes.process_name Processes.user Processes.dest |
`drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`
| search (process=*rhaegal* OR process=*drogon* OR *viserion_*) | `scheduled_tasks_used_in_badrabbit_ransomware_filter`'
how_to_implement: The detection is based on data that originates from Endpoint Detection
@@ -37,10 +37,14 @@ tags:
mitre_attack_id:
- T1053.005
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
- name: dest
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Spectre and Meltdown Vulnerable Systems
id: 354be8e0-32cd-4da0-8c47-796de13b60ea
version: 1
date: '2017-01-07'
version: 2
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: TTP
@@ -28,10 +28,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Suspicious Changes to File Associations
id: 1b989a0e-0129-4446-a695-f193a5b746fc
version: 4
date: '2020-07-22'
version: 5
date: '2024-08-16'
author: Rico Valdez, Splunk
status: deprecated
type: TTP
@@ -43,10 +43,10 @@ tags:
mitre_attack_id:
- T1546.001
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Suspicious Email - UBA Anomaly
id: 56e877a6-1455-4479-ad16-0550dc1e33f8
version: 3
date: '2020-07-22'
version: 4
date: '2024-08-16'
author: Bhavin Patel, Splunk
status: deprecated
type: Anomaly
@@ -35,10 +35,10 @@ tags:
mitre_attack_id:
- T1566
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Suspicious File Write
id: 57f76b8a-32f0-42ed-b358-d9fa3ca7bac8
version: 3
date: '2019-04-25'
version: 4
date: '2024-08-16'
author: Rico Valdez, Splunk
status: deprecated
type: Hunting
@@ -37,10 +37,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Suspicious Powershell Command-Line Arguments
id: 2cdb91d2-542c-497f-b252-be495e71f38c
version: 6
date: '2021-01-19'
version: 7
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: TTP
@@ -44,10 +44,14 @@ tags:
mitre_attack_id:
- T1059.001
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Suspicious writes to System Volume Information
id: cd6297cd-2bdd-4aa1-84aa-5d2f84228fac
version: 2
date: '2020-07-22'
version: 3
date: '2024-08-15'
author: Rico Valdez, Splunk
status: deprecated
type: Hunting
@@ -30,10 +30,10 @@ tags:
mitre_attack_id:
- T1036
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Uncommon Processes On Endpoint
id: 29ccce64-a10c-4389-a45f-337cb29ba1f7
version: 4
date: '2020-07-22'
version: 5
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: Hunting
@@ -36,10 +36,10 @@ tags:
mitre_attack_id:
- T1204.002
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Unsigned Image Loaded by LSASS
id: 56ef054c-76ef-45f9-af4a-a634695dcd65
version: 1
date: '2019-12-06'
version: 2
date: '2024-08-15'
author: Patrick Bareiss, Splunk
status: deprecated
type: TTP
@@ -33,10 +33,10 @@ tags:
mitre_attack_id:
- T1003.001
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Unsuccessful Netbackup backups
id: a34aae96-ccf8-4aaa-952c-3ea21444444f
version: 1
date: '2017-09-12'
version: 2
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: Hunting
@@ -26,10 +26,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Web Fraud - Account Harvesting
id: bf1d7b5c-df2f-4249-a401-c09fdc221ddf
version: 1
date: '2018-10-08'
version: 2
date: '2024-08-16'
author: Jim Apger, Splunk
status: deprecated
type: TTP
@@ -45,10 +45,10 @@ tags:
mitre_attack_id:
- T1136
observable:
- name: field
type: Unknown
- name: src_user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Web Fraud - Anomalous User Clickspeed
id: 31337bbb-bc22-4752-b599-ef192df2dc7a
version: 1
date: '2018-10-08'
version: 2
date: '2024-08-16'
author: Jim Apger, Splunk
status: deprecated
type: Anomaly
@@ -41,10 +41,10 @@ tags:
mitre_attack_id:
- T1078
observable:
- name: field
type: Unknown
- name: session_id
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Web Fraud - Password Sharing Across Accounts
id: 31337a1a-53b9-4e05-96e9-55c934cb71d3
version: 1
date: '2018-10-08'
version: 2
date: '2024-08-15'
author: Jim Apger, Splunk
status: deprecated
type: Anomaly
@@ -34,10 +34,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Windows connhost exe started forcefully
id: c114aaca-68ee-41c2-ad8c-32bf21db8769
version: 1
date: '2020-11-06'
version: 2
date: '2024-08-15'
author: Rod Soto, Jose Hernandez, Splunk
status: deprecated
type: TTP
@@ -39,10 +39,10 @@ tags:
mitre_attack_id:
- T1059.003
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Windows hosts file modification
id: 06a6fc63-a72d-41dc-8736-7e3dd9612116
version: 1
date: '2018-11-02'
version: 2
date: '2024-08-16'
author: Rico Valdez, Splunk
status: deprecated
type: TTP
@@ -31,10 +31,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Access LSASS Memory for Dump Creation
id: fb4c31b0-13e8-4155-8aa5-24de4b8d6717
version: 3
date: '2024-05-13'
version: 4
date: '2024-08-14'
author: Patrick Bareiss, Splunk
status: production
type: TTP
@@ -50,7 +50,7 @@ tags:
- name: TargetImage
type: Process
role:
- Target
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Account Discovery With Net App
id: 339805ce-ac30-11eb-b87d-acde48001122
version: 5
date: '2024-05-22'
version: 6
date: '2024-08-15'
author: Teoderick Contreras, Splunk, TheLawsOfChaos, Github Community
status: production
type: TTP
@@ -61,7 +61,7 @@ tags:
- name: process_name
type: Process Name
role:
- Child Process
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Anomalous usage of 7zip
id: 9364ee8e-a39a-11eb-8f1d-acde48001122
version: 3
date: '2024-05-25'
version: 4
date: '2024-08-15'
author: Michael Haag, Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -64,11 +64,11 @@ tags:
- name: parent_process_name
type: Process
role:
- Parent Process
- Attacker
- name: process_name
type: Process
role:
- Child Process
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Any Powershell DownloadFile
id: 1a93b7ea-7af7-11eb-adb5-acde48001122
version: 4
date: '2024-05-25'
version: 5
date: '2024-08-14'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -72,11 +72,11 @@ tags:
- name: parent_process_name
type: Process
role:
- Parent Process
- Attacker
- name: process_name
type: Process
role:
- Child Process
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Any Powershell DownloadString
id: 4d015ef2-7adf-11eb-95da-acde48001122
version: 4
date: '2024-05-10'
version: 5
date: '2024-08-14'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -73,11 +73,11 @@ tags:
- name: parent_process_name
type: Process
role:
- Parent Process
- Attacker
- name: process_name
type: Process
role:
- Child Process
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Attempt To Add Certificate To Untrusted Store
id: 6bc5243e-ef36-45dc-9b12-f4a6be131159
version: 8
date: '2024-05-12'
version: 9
date: '2024-08-15'
author: Patrick Bareiss, Rico Valdez, Splunk
status: production
type: TTP
@@ -54,11 +54,11 @@ tags:
- name: parent_process_name
type: Process
role:
- Parent Process
- Attacker
- name: process_name
type: Process
role:
- Child Process
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Attempt To Stop Security Service
id: c8e349c6-b97c-486e-8949-bd7bcd1f3910
version: 5
date: '2024-05-21'
version: 6
date: '2024-08-14'
author: Rico Valdez, Splunk
status: production
type: TTP
@@ -61,11 +61,11 @@ tags:
- name: parent_process_name
type: Process
role:
- Parent Process
- Attacker
- name: process_name
type: Process
role:
- Child Process
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Attempted Credential Dump From Registry via Reg exe
id: e9fb4a59-c5fb-440a-9f24-191fbc6b2911
version: 8
date: '2024-05-19'
version: 9
date: '2024-08-14'
author: Patrick Bareiss, Splunk
status: production
type: TTP
@@ -66,11 +66,11 @@ tags:
- name: parent_process_name
type: Process
role:
- Parent Process
- Attacker
- name: process_name
type: Process
role:
- Child Process
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: BCDEdit Failure Recovery Modification
id: 809b31d2-5462-11eb-ae93-0242ac130002
version: 2
date: '2024-05-15'
version: 3
date: '2024-08-14'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -59,11 +59,11 @@ tags:
- name: parent_process_name
type: Process
role:
- Parent Process
- Attacker
- name: process_name
type: Process
role:
- Child Process
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
+4 -4
View File
@@ -1,7 +1,7 @@
name: BITS Job Persistence
id: e97a5ffe-90bf-11eb-928a-acde48001122
version: 3
date: '2024-05-21'
version: 4
date: '2024-08-14'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -64,11 +64,11 @@ tags:
- name: parent_process_name
type: Process
role:
- Parent Process
- Attacker
- name: process_name
type: Process
role:
- Child Process
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: BITSAdmin Download File
id: 80630ff4-8e4c-11eb-aab5-acde48001122
version: 4
date: '2024-05-20'
version: 5
date: '2024-08-15'
author: Michael Haag, Sittikorn S
status: production
type: TTP
@@ -68,11 +68,11 @@ tags:
- name: parent_process_name
type: Process
role:
- Parent Process
- Attacker
- name: process_name
type: Process
role:
- Child Process
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security

Some files were not shown because too many files have changed in this diff Show More