diff --git a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml index 23aa020d39..93ac6661bd 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml @@ -1,7 +1,7 @@ name: Abnormally High Number Of Cloud Infrastructure API Calls id: 0840ddf1-8c89-46ff-b730-c8d6722478c0 -version: 2 -date: '2024-05-12' +version: 3 +date: '2024-08-16' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -47,7 +47,7 @@ tags: - name: user type: User role: - - Attacker + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml index 8eb7b0254b..50908a289d 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml @@ -1,7 +1,7 @@ name: Abnormally High Number Of Cloud Security Group API Calls id: d4dfb7f3-7a37-498a-b5df-f19334e871af -version: 2 -date: '2024-05-22' +version: 3 +date: '2024-08-16' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -47,7 +47,7 @@ tags: - name: user type: User role: - - Attacker + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_saml_update_identity_provider.yml b/detections/cloud/aws_saml_update_identity_provider.yml index d1da02fe30..6fd98c9bb6 100644 --- a/detections/cloud/aws_saml_update_identity_provider.yml +++ b/detections/cloud/aws_saml_update_identity_provider.yml @@ -1,7 +1,7 @@ name: AWS SAML Update identity provider id: 2f0604c6-6030-11eb-ae93-0242ac130002 -version: 2 -date: '2024-05-19' +version: 3 +date: '2024-08-19' author: Rod Soto, Splunk status: production type: TTP @@ -48,7 +48,6 @@ tags: type: User role: - Victim - - Target product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml b/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml index b80986d4ea..6053083aca 100644 --- a/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml +++ b/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml @@ -1,7 +1,7 @@ name: Cloud Instance Modified By Previously Unseen User id: 7fb15084-b14e-405a-bd61-a6de15a40722 -version: 2 -date: '2024-05-17' +version: 3 +date: '2024-08-16' author: Rico Valdez, Splunk status: experimental type: Anomaly @@ -45,7 +45,7 @@ tags: - name: user type: User role: - - Attacker + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml b/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml index 02a1beea15..2edc8786fb 100644 --- a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml +++ b/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml @@ -1,7 +1,7 @@ name: Abnormally High AWS Instances Launched by User id: 2a9b80d3-6340-4345-b5ad-290bf5d0dac4 -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: Anomaly @@ -36,10 +36,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: userName + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml b/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml index 29b10d287d..ce796ea01f 100644 --- a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml +++ b/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml @@ -1,7 +1,7 @@ name: Abnormally High AWS Instances Launched by User - MLTK id: dec41ad5-d579-42cb-b4c6-f5dbb778bbe5 -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-15' author: Jason Brewer, Splunk status: deprecated type: Anomaly @@ -32,10 +32,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: src_user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml index ac6a7f26c3..e0ed38a017 100644 --- a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml +++ b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml @@ -1,7 +1,7 @@ name: Abnormally High AWS Instances Terminated by User id: 8d301246-fccf-45e2-a8e7-3655fd14379c -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: Anomaly @@ -36,10 +36,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: userName + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml index 936faf0ed0..24d38d557b 100644 --- a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml +++ b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml @@ -1,7 +1,7 @@ name: Abnormally High AWS Instances Terminated by User - MLTK id: 1c02b86a-cd85-473e-a50b-014a9ac8fe3e -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-15' author: Jason Brewer, Splunk status: deprecated type: Anomaly @@ -31,10 +31,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: src_user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/asl_aws_excessive_security_scanning.yml b/detections/deprecated/asl_aws_excessive_security_scanning.yml index 8745c3d0f3..31ad8c1727 100644 --- a/detections/deprecated/asl_aws_excessive_security_scanning.yml +++ b/detections/deprecated/asl_aws_excessive_security_scanning.yml @@ -1,7 +1,7 @@ name: ASL AWS Excessive Security Scanning id: ff2bfdbc-65b7-4434-8f08-d55761d1d446 -version: 1 -date: '2023-06-01' +version: 2 +date: '2024-08-16' author: Patrick Bareiss, Splunk status: deprecated type: Anomaly @@ -35,7 +35,7 @@ tags: - name: identity.user.name type: User role: - - Attacker + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml index 0ee85cd68e..0d5eb040d0 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml @@ -1,7 +1,7 @@ name: AWS Cloud Provisioning From Previously Unseen City id: 344a1778-0b25-490c-adb1-de8beddf59cd -version: 1 -date: '2018-03-16' +version: 2 +date: '2024-08-16' author: David Dorsey, Splunk status: deprecated type: Anomaly @@ -48,10 +48,10 @@ tags: mitre_attack_id: - T1535 observable: - - name: field - type: Unknown + - name: src_ip + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml index 972bf2dc55..364b9ab482 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml @@ -1,7 +1,7 @@ name: AWS Cloud Provisioning From Previously Unseen Country id: ceb8d3d8-06cb-49eb-beaf-829526e33ff0 -version: 1 -date: '2018-03-16' +version: 2 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: Anomaly @@ -49,10 +49,10 @@ tags: mitre_attack_id: - T1535 observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml index 58590b0009..fd2b906142 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml @@ -1,7 +1,7 @@ name: AWS Cloud Provisioning From Previously Unseen IP Address id: 42e15012-ac14-4801-94f4-f1acbe64880b -version: 1 -date: '2018-03-16' +version: 2 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: Anomaly @@ -46,10 +46,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml index 2de77ce5f2..17c217ab38 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml @@ -1,7 +1,7 @@ name: AWS Cloud Provisioning From Previously Unseen Region id: 7971d3df-da82-4648-a6e5-b5637bea5253 -version: 1 -date: '2018-03-16' +version: 2 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: Anomaly @@ -48,10 +48,14 @@ tags: mitre_attack_id: - T1535 observable: - - name: field - type: Unknown + - name: user + type: User Name role: - - Unknown + - Victim + - name: src_ip + type: IP Address + role: + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml b/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml index 4602746c28..d2251fcf56 100644 --- a/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml +++ b/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml @@ -1,7 +1,7 @@ name: AWS EKS Kubernetes cluster sensitive object access id: 7f227943-2196-4d4d-8d6a-ac8cb308e61c -version: 1 -date: '2020-06-23' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -25,10 +25,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user.username + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml b/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml index ad4302443a..1e0cf56b4a 100644 --- a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml +++ b/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml @@ -1,7 +1,7 @@ name: Clients Connecting to Multiple DNS Servers id: 74ec6f18-604b-4202-a567-86b2066be3ce -version: 3 -date: '2020-07-21' +version: 4 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: TTP @@ -42,10 +42,10 @@ tags: mitre_attack_id: - T1048.003 observable: - - name: field - type: Unknown + - name: src + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/cloud_network_access_control_list_deleted.yml b/detections/deprecated/cloud_network_access_control_list_deleted.yml index 679c55e796..97bfd5318c 100644 --- a/detections/deprecated/cloud_network_access_control_list_deleted.yml +++ b/detections/deprecated/cloud_network_access_control_list_deleted.yml @@ -1,7 +1,7 @@ name: Cloud Network Access Control List Deleted id: 021abc51-1862-41dd-ad43-43c739c0a983 -version: 1 -date: '2020-09-08' +version: 2 +date: '2024-08-15' author: Peter Gael, Splunk status: deprecated type: Anomaly @@ -30,10 +30,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: userName + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml b/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml index 0c911874c3..9b8abca9a6 100644 --- a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml +++ b/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml @@ -1,7 +1,7 @@ name: Detect Activity Related to Pass the Hash Attacks id: f5939373-8054-40ad-8c64-cec478a22a4b -version: 6 -date: '2020-10-15' +version: 7 +date: '2024-08-15' author: Bhavin Patel, Patrick Bareiss, Splunk status: deprecated type: Hunting @@ -40,10 +40,6 @@ tags: type: Hostname role: - Victim - - name: EventCode - type: Other - role: - - Other product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml b/detections/deprecated/detect_api_activity_from_users_without_mfa.yml index b071794296..6c3fe88e02 100644 --- a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml +++ b/detections/deprecated/detect_api_activity_from_users_without_mfa.yml @@ -1,7 +1,7 @@ name: Detect API activity from users without MFA id: 4d46e8bd-4072-48e4-92db-0325889ef894 -version: 1 -date: '2018-05-17' +version: 2 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: Hunting @@ -50,10 +50,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml b/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml index 5614e6ced8..81446134ca 100644 --- a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml +++ b/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml @@ -1,7 +1,7 @@ name: Detect AWS API Activities From Unapproved Accounts id: ada0f478-84a8-4641-a3f1-d82362d4bd55 -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: Hunting @@ -55,10 +55,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: user + type: User Name role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml index e263b72ed3..a9790d8d06 100644 --- a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml +++ b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml @@ -1,7 +1,7 @@ name: Detect DNS requests to Phishing Sites leveraging EvilGinx2 id: 24dd17b1-e2fb-4c31-878c-d4f226595bfa -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-16' author: Bhavin Patel, Splunk status: deprecated type: TTP @@ -50,10 +50,10 @@ tags: mitre_attack_id: - T1566.003 observable: - - name: field - type: Unknown + - name: src + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_long_dns_txt_record_response.yml b/detections/deprecated/detect_long_dns_txt_record_response.yml index a4c4066d07..e25c45c902 100644 --- a/detections/deprecated/detect_long_dns_txt_record_response.yml +++ b/detections/deprecated/detect_long_dns_txt_record_response.yml @@ -1,7 +1,7 @@ name: Detect Long DNS TXT Record Response id: 05437c07-62f5-452e-afdc-04dd44815bb9 -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-15' author: Rico Valdez, Splunk status: deprecated type: TTP @@ -40,10 +40,10 @@ tags: mitre_attack_id: - T1048.003 observable: - - name: field - type: Unknown + - name: Destination IP + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml b/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml index a404feefa4..42f4e7c4f8 100644 --- a/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml +++ b/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml @@ -1,7 +1,7 @@ name: Detect Mimikatz Via PowerShell And EventCode 4703 id: 98917be2-bfc8-475a-8618-a9bb06575188 -version: 2 -date: '2019-02-27' +version: 3 +date: '2024-08-15' author: Rico Valdez, Splunk status: deprecated type: TTP @@ -36,10 +36,10 @@ tags: mitre_attack_id: - T1003.001 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_new_api_calls_from_user_roles.yml b/detections/deprecated/detect_new_api_calls_from_user_roles.yml index 7551bc3370..3c5e740357 100644 --- a/detections/deprecated/detect_new_api_calls_from_user_roles.yml +++ b/detections/deprecated/detect_new_api_calls_from_user_roles.yml @@ -1,7 +1,7 @@ name: Detect new API calls from user roles id: 22773e84-bac0-4595-b086-20d3f335b4f1 -version: 1 -date: '2018-04-16' +version: 2 +date: '2024-08-19' author: Bhavin Patel, Splunk status: deprecated type: Anomaly @@ -37,10 +37,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_new_user_aws_console_login.yml b/detections/deprecated/detect_new_user_aws_console_login.yml index fb00e3d683..885f105987 100644 --- a/detections/deprecated/detect_new_user_aws_console_login.yml +++ b/detections/deprecated/detect_new_user_aws_console_login.yml @@ -1,7 +1,7 @@ name: Detect new user AWS Console Login id: ada0f478-84a8-4641-a3f3-d82362dffd75 -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: Hunting @@ -37,10 +37,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_spike_in_aws_api_activity.yml b/detections/deprecated/detect_spike_in_aws_api_activity.yml index 6fc824e5ef..719d463311 100644 --- a/detections/deprecated/detect_spike_in_aws_api_activity.yml +++ b/detections/deprecated/detect_spike_in_aws_api_activity.yml @@ -1,7 +1,7 @@ name: Detect Spike in AWS API Activity id: ada0f478-84a8-4641-a3f1-d32362d4bd55 -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: Anomaly @@ -59,10 +59,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_spike_in_network_acl_activity.yml b/detections/deprecated/detect_spike_in_network_acl_activity.yml index 8b1cc6a0f1..8d1b7f6256 100644 --- a/detections/deprecated/detect_spike_in_network_acl_activity.yml +++ b/detections/deprecated/detect_spike_in_network_acl_activity.yml @@ -1,7 +1,7 @@ name: Detect Spike in Network ACL Activity id: ada0f478-84a8-4641-a1f1-e32372d4bd53 -version: 1 -date: '2018-05-21' +version: 2 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: Anomaly @@ -46,10 +46,10 @@ tags: mitre_attack_id: - T1562.007 observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_spike_in_security_group_activity.yml b/detections/deprecated/detect_spike_in_security_group_activity.yml index 448a1e74fe..cd711e32c0 100644 --- a/detections/deprecated/detect_spike_in_security_group_activity.yml +++ b/detections/deprecated/detect_spike_in_security_group_activity.yml @@ -1,7 +1,7 @@ name: Detect Spike in Security Group Activity id: ada0f478-84a8-4641-a3f1-e32372d4bd53 -version: 1 -date: '2018-04-18' +version: 2 +date: '2024-08-16' author: Bhavin Patel, Splunk status: deprecated type: Anomaly @@ -47,10 +47,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_usb_device_insertion.yml b/detections/deprecated/detect_usb_device_insertion.yml index 4b0a6e8380..57d3fcfd25 100644 --- a/detections/deprecated/detect_usb_device_insertion.yml +++ b/detections/deprecated/detect_usb_device_insertion.yml @@ -1,7 +1,7 @@ name: Detect USB device insertion id: 104658f4-afdc-499f-9719-17a43f9826f5 -version: 1 -date: '2017-11-27' +version: 2 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: TTP @@ -34,10 +34,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml b/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml index 7aad030ee3..0c292e1500 100644 --- a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml +++ b/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml @@ -1,7 +1,7 @@ name: Detect web traffic to dynamic domain providers id: 134da869-e264-4a8f-8d7e-fcd01c18f301 -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: TTP @@ -43,10 +43,10 @@ tags: mitre_attack_id: - T1071.001 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detection_of_dns_tunnels.yml b/detections/deprecated/detection_of_dns_tunnels.yml index 6ecfdf260a..3a2068935d 100644 --- a/detections/deprecated/detection_of_dns_tunnels.yml +++ b/detections/deprecated/detection_of_dns_tunnels.yml @@ -1,7 +1,7 @@ name: Detection of DNS Tunnels id: 104658f4-afdc-499f-9719-17a43f9826f4 -version: 2 -date: '2022-02-15' +version: 3 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: TTP @@ -56,10 +56,10 @@ tags: mitre_attack_id: - T1048.003 observable: - - name: field - type: Unknown + - name: src + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml b/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml index 078029a1fe..ec1b5aa5f3 100644 --- a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml +++ b/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml @@ -1,7 +1,7 @@ name: DNS Query Requests Resolved by Unauthorized DNS Servers id: 1a67f15a-f4ff-4170-84e9-08cf6f75d6f6 -version: 3 -date: '2020-07-21' +version: 4 +date: '2024-08-16' author: Bhavin Patel, Splunk status: deprecated type: TTP @@ -32,10 +32,10 @@ tags: mitre_attack_id: - T1071.004 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/dns_record_changed.yml b/detections/deprecated/dns_record_changed.yml index 288a4c7855..74f197f983 100644 --- a/detections/deprecated/dns_record_changed.yml +++ b/detections/deprecated/dns_record_changed.yml @@ -1,7 +1,7 @@ name: DNS record changed id: 44d3a43e-dcd5-49f7-8356-5209bb369065 -version: 3 -date: '2020-07-21' +version: 4 +date: '2024-08-15' author: Jose Hernandez, Splunk status: deprecated type: TTP @@ -48,10 +48,10 @@ tags: mitre_attack_id: - T1071.004 observable: - - name: field - type: Unknown + - name: src + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/dump_lsass_via_procdump_rename.yml b/detections/deprecated/dump_lsass_via_procdump_rename.yml index 904d367839..0c02f1f35d 100644 --- a/detections/deprecated/dump_lsass_via_procdump_rename.yml +++ b/detections/deprecated/dump_lsass_via_procdump_rename.yml @@ -1,7 +1,7 @@ name: Dump LSASS via procdump Rename id: 21276daa-663d-11eb-ae93-0242ac130002 -version: 1 -date: '2021-02-01' +version: 2 +date: '2024-08-19' author: Michael Haag, Splunk status: deprecated type: Hunting @@ -48,11 +48,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml b/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml index be0aa0099b..a112b4aeb5 100644 --- a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml +++ b/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml @@ -1,7 +1,7 @@ name: EC2 Instance Modified With Previously Unseen User id: 56f91724-cf3f-4666-84e1-e3712fb41e76 -version: 3 -date: '2020-07-21' +version: 4 +date: '2024-08-16' author: David Dorsey, Splunk status: deprecated type: Anomaly @@ -36,10 +36,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml b/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml index fa7e7c922f..5e6b7cbd2c 100644 --- a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml +++ b/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml @@ -1,7 +1,7 @@ name: EC2 Instance Started In Previously Unseen Region id: ada0f478-84a8-4641-a3f3-d82362d6fd75 -version: 1 -date: '2018-02-23' +version: 2 +date: '2024-08-16' author: Bhavin Patel, Splunk status: deprecated type: Anomaly @@ -35,10 +35,10 @@ tags: mitre_attack_id: - T1535 observable: - - name: field - type: Unknown + - name: awsRegion + type: Geo Location role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml index f4f7fec762..2da8ac4c33 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml +++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml @@ -1,7 +1,7 @@ name: EC2 Instance Started With Previously Unseen AMI id: 347ec301-601b-48b9-81aa-9ddf9c829dd3 -version: 1 -date: '2018-03-12' +version: 2 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: Anomaly @@ -36,10 +36,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml index ea7355984c..b9c50ca772 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml +++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml @@ -1,7 +1,7 @@ name: EC2 Instance Started With Previously Unseen Instance Type id: 65541c80-03c7-4e05-83c8-1dcd57a2e1ad -version: 2 -date: '2020-02-07' +version: 3 +date: '2024-08-16' author: David Dorsey, Splunk status: deprecated type: Anomaly @@ -36,10 +36,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml index cf6e38c445..4f84ff4173 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml +++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml @@ -1,7 +1,7 @@ name: EC2 Instance Started With Previously Unseen User id: 22773e84-bac0-4595-b086-20d3f735b4f1 -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-16' author: David Dorsey, Splunk status: deprecated type: Anomaly @@ -37,10 +37,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml b/detections/deprecated/execution_of_file_with_spaces_before_extension.yml index 7519f91f51..94e32b07f4 100644 --- a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml +++ b/detections/deprecated/execution_of_file_with_spaces_before_extension.yml @@ -1,7 +1,7 @@ name: Execution of File With Spaces Before Extension id: ab0353e6-a956-420b-b724-a8b4846d5d5a -version: 3 -date: '2020-11-19' +version: 4 +date: '2024-08-16' author: Rico Valdez, Splunk status: deprecated type: TTP @@ -37,10 +37,10 @@ tags: mitre_attack_id: - T1036.003 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml b/detections/deprecated/extended_period_without_successful_netbackup_backups.yml index a905b68aaa..2714384690 100644 --- a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml +++ b/detections/deprecated/extended_period_without_successful_netbackup_backups.yml @@ -1,7 +1,7 @@ name: Extended Period Without Successful Netbackup Backups id: a34aae96-ccf8-4aef-952c-3ea214444440 -version: 1 -date: '2017-09-12' +version: 2 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: Hunting @@ -28,10 +28,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/first_time_seen_command_line_argument.yml b/detections/deprecated/first_time_seen_command_line_argument.yml index b29165d760..be5547908f 100644 --- a/detections/deprecated/first_time_seen_command_line_argument.yml +++ b/detections/deprecated/first_time_seen_command_line_argument.yml @@ -1,7 +1,7 @@ name: First time seen command line argument id: a1b6e73f-98d5-470f-99ac-77aacd578473 -version: 5 -date: '2020-07-21' +version: 6 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: Hunting @@ -50,10 +50,10 @@ tags: - T1059.001 - T1059.003 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml b/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml index 5ea6f95f72..5ff224c42d 100644 --- a/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml +++ b/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml @@ -1,7 +1,7 @@ name: GCP Detect accounts with high risk roles by project id: 27af8c15-38b0-4408-b339-920170724adb -version: 1 -date: '2020-10-09' +version: 2 +date: '2024-08-19' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -35,10 +35,10 @@ tags: mitre_attack_id: - T1078 observable: - - name: field - type: Unknown + - name: data.protoPayload.authenticationInfo.principalEmail + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml b/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml index 2e938d033f..d6296abe00 100644 --- a/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml +++ b/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml @@ -1,7 +1,7 @@ name: GCP Detect high risk permissions by resource and account id: 2e70ef35-2187-431f-aedc-4503dc9b06ba -version: 1 -date: '2020-10-09' +version: 2 +date: '2024-08-16' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -34,10 +34,10 @@ tags: mitre_attack_id: - T1078 observable: - - name: field - type: Unknown + - name: data.protoPayload.authenticationInfo.principalEmail + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/gcp_detect_oauth_token_abuse.yml b/detections/deprecated/gcp_detect_oauth_token_abuse.yml index b40eddc360..7f4f9ace51 100644 --- a/detections/deprecated/gcp_detect_oauth_token_abuse.yml +++ b/detections/deprecated/gcp_detect_oauth_token_abuse.yml @@ -1,7 +1,7 @@ name: gcp detect oauth token abuse id: a7e9f7bb-8901-4ad0-8d88-0a4ab07b1972 -version: 1 -date: '2020-09-01' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -30,10 +30,10 @@ tags: mitre_attack_id: - T1078 observable: - - name: field - type: Unknown + - name: protoPayload.status.details{}.violations{}.callerIp + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml b/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml index 8639f1dc7a..a8438aaf43 100644 --- a/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml +++ b/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml @@ -1,7 +1,7 @@ name: GCP Kubernetes cluster scan detection id: db5957ec-0144-4c56-b512-9dccbe7a2d26 -version: 1 -date: '2020-04-15' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: TTP @@ -34,10 +34,10 @@ tags: mitre_attack_id: - T1526 observable: - - name: field - type: Unknown + - name: src_ip + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/identify_new_user_accounts.yml b/detections/deprecated/identify_new_user_accounts.yml index 59dbaacef0..b15a6ad266 100644 --- a/detections/deprecated/identify_new_user_accounts.yml +++ b/detections/deprecated/identify_new_user_accounts.yml @@ -1,7 +1,7 @@ name: Identify New User Accounts id: 475b9e27-17e4-46e2-b7e2-648221be3b89 -version: 1 -date: '2017-09-12' +version: 2 +date: '2024-08-16' author: Bhavin Patel, Splunk status: deprecated type: Hunting @@ -29,10 +29,10 @@ tags: mitre_attack_id: - T1078.002 observable: - - name: field - type: Unknown + - name: identity + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml b/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml index 3a946be0ee..e1f373342f 100644 --- a/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml +++ b/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml @@ -1,7 +1,7 @@ name: Kubernetes AWS detect most active service accounts by pod id: 5b30b25d-7d32-42d8-95ca-64dfcd9076e6 -version: 1 -date: '2020-06-23' +version: 2 +date: '2024-08-16' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -24,10 +24,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: sourceIPs{} + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml b/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml index 4efb07706d..88588c2b68 100644 --- a/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml +++ b/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml @@ -1,7 +1,7 @@ name: Kubernetes AWS detect RBAC authorization by account id: de7264ed-3ed9-4fef-bb01-6eefc87cefe8 -version: 1 -date: '2020-06-23' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -26,10 +26,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user.username + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml b/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml index 516dbda7eb..7d39a1e05b 100644 --- a/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml +++ b/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml @@ -1,7 +1,7 @@ name: Kubernetes AWS detect sensitive role access id: b6013a7b-85e0-4a45-b051-10b252d69569 -version: 1 -date: '2020-06-23' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -25,10 +25,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user.username + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml b/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml index 9f0651b3a9..3c8de81590 100644 --- a/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml +++ b/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml @@ -1,7 +1,7 @@ name: Kubernetes AWS detect service accounts forbidden failure access id: a6959c57-fa8f-4277-bb86-7c32fba579d5 -version: 1 -date: '2020-06-23' +version: 2 +date: '2024-08-16' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -26,10 +26,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: sourceIPs{} + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml b/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml index 2878342321..a47c5faaa9 100644 --- a/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml +++ b/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml @@ -1,7 +1,7 @@ name: Kubernetes Azure active service accounts by pod namespace id: 55a2264a-b7f0-45e5-addd-1e5ab3415c72 -version: 1 -date: '2020-05-26' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -26,10 +26,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user.username + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml b/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml index 2881d8d765..e32599cc0f 100644 --- a/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml +++ b/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml @@ -1,7 +1,7 @@ name: Kubernetes Azure detect RBAC authorization by account id: 47af7d20-0607-4079-97d7-7a29af58b54e -version: 1 -date: '2020-05-26' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -26,10 +26,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user.username + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml b/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml index e93c26f489..ec893ba9e6 100644 --- a/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml +++ b/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml @@ -1,7 +1,7 @@ name: Kubernetes Azure detect sensitive object access id: 1bba382b-07fd-4ffa-b390-8002739b76e8 -version: 1 -date: '2020-05-20' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -25,10 +25,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user.username + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml b/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml index 38bb3710cf..6534ebeab7 100644 --- a/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml +++ b/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml @@ -1,7 +1,7 @@ name: Kubernetes Azure detect sensitive role access id: f27349e5-1641-4f6a-9e68-30402be0ad4c -version: 1 -date: '2020-05-20' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -25,10 +25,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user.username + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml b/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml index 3a81b57338..10f8580344 100644 --- a/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml +++ b/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml @@ -1,7 +1,7 @@ name: Kubernetes Azure detect service accounts forbidden failure access id: 019690d7-420f-4da0-b320-f27b09961514 -version: 1 -date: '2020-05-20' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -25,10 +25,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user.username + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml b/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml index 31c7237848..290d6a258e 100644 --- a/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml +++ b/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml @@ -1,7 +1,7 @@ name: Kubernetes Azure detect suspicious kubectl calls id: 4b6d1ba8-0000-4cec-87e6-6cbbd71651b5 -version: 1 -date: '2020-05-26' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -28,10 +28,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: sourceIPs{} + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml b/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml index 4c09f89d36..ef66c8e12a 100644 --- a/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml +++ b/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml @@ -1,7 +1,7 @@ name: Kubernetes Azure pod scan fingerprint id: 86aad3e0-732f-4f66-bbbc-70df448e461d -version: 1 -date: '2020-05-20' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -25,10 +25,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: sourceIPs{} + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_azure_scan_fingerprint.yml b/detections/deprecated/kubernetes_azure_scan_fingerprint.yml index dbd4220f90..9d501762dd 100644 --- a/detections/deprecated/kubernetes_azure_scan_fingerprint.yml +++ b/detections/deprecated/kubernetes_azure_scan_fingerprint.yml @@ -1,7 +1,7 @@ name: Kubernetes Azure scan fingerprint id: c5e5bd5c-1013-4841-8b23-e7b3253c840a -version: 1 -date: '2020-05-19' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -27,10 +27,10 @@ tags: mitre_attack_id: - T1526 observable: - - name: field - type: Unknown + - name: sourceIPs{} + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml b/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml index 46481a7a42..41fc0d44e2 100644 --- a/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml +++ b/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml @@ -1,7 +1,7 @@ name: Kubernetes GCP detect most active service accounts by pod id: 7f5c2779-88a0-4824-9caa-0f606c8f260f -version: 1 -date: '2020-07-10' +version: 2 +date: '2024-08-16' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -26,10 +26,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: src_user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml b/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml index c8e0ef24ec..c944e6a2c8 100644 --- a/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml +++ b/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml @@ -1,7 +1,7 @@ name: Kubernetes GCP detect RBAC authorizations by account id: 99487de3-7192-4b41-939d-fbe9acfb1340 -version: 1 -date: '2020-07-11' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -26,10 +26,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: src_user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml b/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml index f237528f37..c32a2b9b1a 100644 --- a/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml +++ b/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml @@ -1,7 +1,7 @@ name: Kubernetes GCP detect sensitive object access id: bdb6d596-86a0-4aba-8369-418ae8b9963a -version: 1 -date: '2020-07-11' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -26,10 +26,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: src_user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml b/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml index 84d7db1a83..dde0aacc73 100644 --- a/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml +++ b/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml @@ -1,7 +1,7 @@ name: Kubernetes GCP detect sensitive role access id: a46923f6-36b9-4806-a681-31f314907c30 -version: 1 -date: '2020-07-11' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -26,10 +26,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: src_user + type: User role: - - Unknown + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml b/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml index 4904afdb5c..a13963dfde 100644 --- a/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml +++ b/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml @@ -1,7 +1,7 @@ name: Kubernetes GCP detect service accounts forbidden failure access id: 7094808d-432a-48e7-bb3c-77e96c894f3b -version: 1 -date: '2020-06-23' +version: 2 +date: '2024-08-16' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -28,10 +28,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: src_user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml b/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml index cbdfd5e008..7b369dd41f 100644 --- a/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml +++ b/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml @@ -1,7 +1,7 @@ name: Kubernetes GCP detect suspicious kubectl calls id: a5bed417-070a-41f2-a1e4-82b6aa281557 -version: 1 -date: '2020-07-11' +version: 2 +date: '2024-08-16' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -27,10 +27,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: src_user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/monitor_dns_for_brand_abuse.yml b/detections/deprecated/monitor_dns_for_brand_abuse.yml index 8acf3ec95c..9f351633a1 100644 --- a/detections/deprecated/monitor_dns_for_brand_abuse.yml +++ b/detections/deprecated/monitor_dns_for_brand_abuse.yml @@ -1,7 +1,7 @@ name: Monitor DNS For Brand Abuse id: 24dd17b1-e2fb-4c31-878c-d4f746595bfa -version: 1 -date: '2017-09-23' +version: 2 +date: '2024-08-16' author: David Dorsey, Splunk status: deprecated type: TTP @@ -29,10 +29,14 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: query + type: Other role: - - Unknown + - Victim + - name: IPs + type: IP Address + role: + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/o365_suspicious_user_email_forwarding.yml b/detections/deprecated/o365_suspicious_user_email_forwarding.yml index b9eda6557b..69cc73978f 100644 --- a/detections/deprecated/o365_suspicious_user_email_forwarding.yml +++ b/detections/deprecated/o365_suspicious_user_email_forwarding.yml @@ -1,7 +1,7 @@ name: O365 Suspicious User Email Forwarding id: f8dfe015-dbb3-4569-ba75-b13787e06aa4 -version: 1 -date: '2020-12-16' +version: 2 +date: '2024-08-15' author: Patrick Bareiss, Splunk status: deprecated type: Anomaly @@ -38,7 +38,7 @@ tags: - name: ForwardingSmtpAddress type: Email Address role: - - Other + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml b/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml index a91c807f39..48d89eacb2 100644 --- a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml +++ b/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml @@ -1,7 +1,7 @@ name: Okta ThreatInsight Login Failure with High Unknown users id: 632663b0-4562-4aad-abe9-9f621a049738 -version: 1 -date: '2023-03-09' +version: 2 +date: '2024-08-16' author: Okta, Inc, Michael Haag, Splunk type: TTP status: deprecated @@ -30,10 +30,10 @@ tags: - T1078.001 - T1110.004 observable: - - name: outcome.reason - type: Other + - name: user + type: User role: - - Other + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml b/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml index 0ab7b85ded..d830554197 100644 --- a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml +++ b/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml @@ -1,7 +1,7 @@ name: Okta ThreatInsight Suspected PasswordSpray Attack id: 25dbad05-6682-4dd5-9ce9-8adecf0d9ae2 -version: 1 -date: '2023-03-09' +version: 2 +date: '2024-08-16' author: Okta, Inc, Michael Haag, Splunk type: TTP status: deprecated @@ -34,7 +34,7 @@ tags: - name: outcome.reason type: Other role: - - Other + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml b/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml index f6e1c13a28..b93d300b5d 100644 --- a/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml +++ b/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml @@ -1,7 +1,7 @@ name: Okta Two or More Rejected Okta Pushes id: d93f785e-4c2c-4262-b8c7-12b77a13fd39 -version: 1 -date: '2022-09-27' +version: 2 +date: '2024-08-16' author: Michael Haag, Marissa Bower, Splunk status: deprecated type: TTP @@ -42,7 +42,7 @@ tags: - name: user type: User role: - - Attacker + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/osquery_pack___coldroot_detection.yml b/detections/deprecated/osquery_pack___coldroot_detection.yml index 14ccc214ee..cacc2e6048 100644 --- a/detections/deprecated/osquery_pack___coldroot_detection.yml +++ b/detections/deprecated/osquery_pack___coldroot_detection.yml @@ -1,7 +1,7 @@ name: Osquery pack - ColdRoot detection id: a6fffe5e-05c3-4c04-badc-887607fbb8dc -version: 1 -date: '2019-01-29' +version: 2 +date: '2024-08-15' author: Rico Valdez, Splunk status: deprecated type: TTP @@ -25,10 +25,14 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: host + type: Hostname role: - - Unknown + - Victim + - name: user + type: User + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/processes_created_by_netsh.yml b/detections/deprecated/processes_created_by_netsh.yml index 9caca611a1..53d46eb369 100644 --- a/detections/deprecated/processes_created_by_netsh.yml +++ b/detections/deprecated/processes_created_by_netsh.yml @@ -1,7 +1,7 @@ name: Processes created by netsh id: b89919ed-fe5f-492c-b139-95dbb162041e -version: 5 -date: '2020-11-23' +version: 6 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: TTP @@ -43,10 +43,14 @@ tags: mitre_attack_id: - T1562.004 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim + - name: user + type: User + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/prohibited_software_on_endpoint.yml b/detections/deprecated/prohibited_software_on_endpoint.yml index 27b76ed896..49935603d1 100644 --- a/detections/deprecated/prohibited_software_on_endpoint.yml +++ b/detections/deprecated/prohibited_software_on_endpoint.yml @@ -1,7 +1,7 @@ name: Prohibited Software On Endpoint id: a51bfe1a-94f0-48cc-b4e4-b6ae50145893 -version: 2 -date: '2019-10-11' +version: 3 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: Hunting @@ -34,10 +34,14 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim + - name: user + type: User + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml b/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml index 26ee538d51..5b575ca1db 100644 --- a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml +++ b/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml @@ -1,7 +1,7 @@ name: Reg exe used to hide files directories via registry keys id: 61a7d1e6-f5d4-41d9-a9be-39a1ffe69459 -version: 2 -date: '2019-02-27' +version: 3 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: TTP @@ -32,17 +32,20 @@ tags: - Windows Defense Evasion Tactics - Suspicious Windows Registry Activities - Windows Persistence Techniques - asset_type: Endpoint confidence: 50 impact: 50 message: tbd mitre_attack_id: - T1564.001 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim + - name: user + type: User + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/remote_registry_key_modifications.yml b/detections/deprecated/remote_registry_key_modifications.yml index 8c8435ee89..ded756a184 100644 --- a/detections/deprecated/remote_registry_key_modifications.yml +++ b/detections/deprecated/remote_registry_key_modifications.yml @@ -1,7 +1,7 @@ name: Remote Registry Key modifications id: c9f4b923-f8af-4155-b697-1354f5dcbc5e -version: 3 -date: '2020-03-02' +version: 4 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: TTP @@ -31,10 +31,14 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim + - name: dest + type: Hostname + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml b/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml index e7d235b110..ea81ef6de4 100644 --- a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml +++ b/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml @@ -1,7 +1,7 @@ name: Scheduled tasks used in BadRabbit ransomware id: 1297fb80-f42a-4b4a-9c8b-78c066437cf6 -version: 3 -date: '2020-07-21' +version: 4 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: TTP @@ -13,7 +13,7 @@ data_source: search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process) as process from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe (Processes.process= "*create*" OR Processes.process= - "*delete*") by Processes.parent_process Processes.process_name Processes.user | + "*delete*") by Processes.parent_process Processes.process_name Processes.user Processes.dest | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)` | search (process=*rhaegal* OR process=*drogon* OR *viserion_*) | `scheduled_tasks_used_in_badrabbit_ransomware_filter`' how_to_implement: The detection is based on data that originates from Endpoint Detection @@ -37,10 +37,14 @@ tags: mitre_attack_id: - T1053.005 observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim + - name: dest + type: Hostname + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml b/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml index 34aa5f5d0e..b8a24e348b 100644 --- a/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml +++ b/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml @@ -1,7 +1,7 @@ name: Spectre and Meltdown Vulnerable Systems id: 354be8e0-32cd-4da0-8c47-796de13b60ea -version: 1 -date: '2017-01-07' +version: 2 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: TTP @@ -28,10 +28,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/suspicious_changes_to_file_associations.yml b/detections/deprecated/suspicious_changes_to_file_associations.yml index 08ca5c2989..a19f6078fd 100644 --- a/detections/deprecated/suspicious_changes_to_file_associations.yml +++ b/detections/deprecated/suspicious_changes_to_file_associations.yml @@ -1,7 +1,7 @@ name: Suspicious Changes to File Associations id: 1b989a0e-0129-4446-a695-f193a5b746fc -version: 4 -date: '2020-07-22' +version: 5 +date: '2024-08-16' author: Rico Valdez, Splunk status: deprecated type: TTP @@ -43,10 +43,10 @@ tags: mitre_attack_id: - T1546.001 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/suspicious_email___uba_anomaly.yml b/detections/deprecated/suspicious_email___uba_anomaly.yml index 77ca06d485..4b38e9f961 100644 --- a/detections/deprecated/suspicious_email___uba_anomaly.yml +++ b/detections/deprecated/suspicious_email___uba_anomaly.yml @@ -1,7 +1,7 @@ name: Suspicious Email - UBA Anomaly id: 56e877a6-1455-4479-ad16-0550dc1e33f8 -version: 3 -date: '2020-07-22' +version: 4 +date: '2024-08-16' author: Bhavin Patel, Splunk status: deprecated type: Anomaly @@ -35,10 +35,10 @@ tags: mitre_attack_id: - T1566 observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/suspicious_file_write.yml b/detections/deprecated/suspicious_file_write.yml index b7a2b0c9ef..ea13940470 100644 --- a/detections/deprecated/suspicious_file_write.yml +++ b/detections/deprecated/suspicious_file_write.yml @@ -1,7 +1,7 @@ name: Suspicious File Write id: 57f76b8a-32f0-42ed-b358-d9fa3ca7bac8 -version: 3 -date: '2019-04-25' +version: 4 +date: '2024-08-16' author: Rico Valdez, Splunk status: deprecated type: Hunting @@ -37,10 +37,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/suspicious_powershell_command_line_arguments.yml b/detections/deprecated/suspicious_powershell_command_line_arguments.yml index 572bb38339..1d02ccddfa 100644 --- a/detections/deprecated/suspicious_powershell_command_line_arguments.yml +++ b/detections/deprecated/suspicious_powershell_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Suspicious Powershell Command-Line Arguments id: 2cdb91d2-542c-497f-b252-be495e71f38c -version: 6 -date: '2021-01-19' +version: 7 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: TTP @@ -44,10 +44,14 @@ tags: mitre_attack_id: - T1059.001 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim + - name: user + type: User + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/suspicious_writes_to_system_volume_information.yml b/detections/deprecated/suspicious_writes_to_system_volume_information.yml index c3ea9c5edf..6ef978bb17 100644 --- a/detections/deprecated/suspicious_writes_to_system_volume_information.yml +++ b/detections/deprecated/suspicious_writes_to_system_volume_information.yml @@ -1,7 +1,7 @@ name: Suspicious writes to System Volume Information id: cd6297cd-2bdd-4aa1-84aa-5d2f84228fac -version: 2 -date: '2020-07-22' +version: 3 +date: '2024-08-15' author: Rico Valdez, Splunk status: deprecated type: Hunting @@ -30,10 +30,10 @@ tags: mitre_attack_id: - T1036 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/uncommon_processes_on_endpoint.yml b/detections/deprecated/uncommon_processes_on_endpoint.yml index 18a30cc4de..0a55effb55 100644 --- a/detections/deprecated/uncommon_processes_on_endpoint.yml +++ b/detections/deprecated/uncommon_processes_on_endpoint.yml @@ -1,7 +1,7 @@ name: Uncommon Processes On Endpoint id: 29ccce64-a10c-4389-a45f-337cb29ba1f7 -version: 4 -date: '2020-07-22' +version: 5 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: Hunting @@ -36,10 +36,10 @@ tags: mitre_attack_id: - T1204.002 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/unsigned_image_loaded_by_lsass.yml b/detections/deprecated/unsigned_image_loaded_by_lsass.yml index 5a926b6aff..226b011c06 100644 --- a/detections/deprecated/unsigned_image_loaded_by_lsass.yml +++ b/detections/deprecated/unsigned_image_loaded_by_lsass.yml @@ -1,7 +1,7 @@ name: Unsigned Image Loaded by LSASS id: 56ef054c-76ef-45f9-af4a-a634695dcd65 -version: 1 -date: '2019-12-06' +version: 2 +date: '2024-08-15' author: Patrick Bareiss, Splunk status: deprecated type: TTP @@ -33,10 +33,10 @@ tags: mitre_attack_id: - T1003.001 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/unsuccessful_netbackup_backups.yml b/detections/deprecated/unsuccessful_netbackup_backups.yml index b8457b91e5..60af44671d 100644 --- a/detections/deprecated/unsuccessful_netbackup_backups.yml +++ b/detections/deprecated/unsuccessful_netbackup_backups.yml @@ -1,7 +1,7 @@ name: Unsuccessful Netbackup backups id: a34aae96-ccf8-4aaa-952c-3ea21444444f -version: 1 -date: '2017-09-12' +version: 2 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: Hunting @@ -26,10 +26,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/web_fraud___account_harvesting.yml b/detections/deprecated/web_fraud___account_harvesting.yml index 4cf762f1ac..18acd9b5dc 100644 --- a/detections/deprecated/web_fraud___account_harvesting.yml +++ b/detections/deprecated/web_fraud___account_harvesting.yml @@ -1,7 +1,7 @@ name: Web Fraud - Account Harvesting id: bf1d7b5c-df2f-4249-a401-c09fdc221ddf -version: 1 -date: '2018-10-08' +version: 2 +date: '2024-08-16' author: Jim Apger, Splunk status: deprecated type: TTP @@ -45,10 +45,10 @@ tags: mitre_attack_id: - T1136 observable: - - name: field - type: Unknown + - name: src_user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml b/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml index 37dc1e7655..6404ea2744 100644 --- a/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml +++ b/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml @@ -1,7 +1,7 @@ name: Web Fraud - Anomalous User Clickspeed id: 31337bbb-bc22-4752-b599-ef192df2dc7a -version: 1 -date: '2018-10-08' +version: 2 +date: '2024-08-16' author: Jim Apger, Splunk status: deprecated type: Anomaly @@ -41,10 +41,10 @@ tags: mitre_attack_id: - T1078 observable: - - name: field - type: Unknown + - name: session_id + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/web_fraud___password_sharing_across_accounts.yml b/detections/deprecated/web_fraud___password_sharing_across_accounts.yml index 0819ba7af8..9c212c0df9 100644 --- a/detections/deprecated/web_fraud___password_sharing_across_accounts.yml +++ b/detections/deprecated/web_fraud___password_sharing_across_accounts.yml @@ -1,7 +1,7 @@ name: Web Fraud - Password Sharing Across Accounts id: 31337a1a-53b9-4e05-96e9-55c934cb71d3 -version: 1 -date: '2018-10-08' +version: 2 +date: '2024-08-15' author: Jim Apger, Splunk status: deprecated type: Anomaly @@ -34,10 +34,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/windows_connhost_exe_started_forcefully.yml b/detections/deprecated/windows_connhost_exe_started_forcefully.yml index 173ee8ff8a..8f3fcab9fe 100644 --- a/detections/deprecated/windows_connhost_exe_started_forcefully.yml +++ b/detections/deprecated/windows_connhost_exe_started_forcefully.yml @@ -1,7 +1,7 @@ name: Windows connhost exe started forcefully id: c114aaca-68ee-41c2-ad8c-32bf21db8769 -version: 1 -date: '2020-11-06' +version: 2 +date: '2024-08-15' author: Rod Soto, Jose Hernandez, Splunk status: deprecated type: TTP @@ -39,10 +39,10 @@ tags: mitre_attack_id: - T1059.003 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/windows_hosts_file_modification.yml b/detections/deprecated/windows_hosts_file_modification.yml index ffa7d52961..aa710401cf 100644 --- a/detections/deprecated/windows_hosts_file_modification.yml +++ b/detections/deprecated/windows_hosts_file_modification.yml @@ -1,7 +1,7 @@ name: Windows hosts file modification id: 06a6fc63-a72d-41dc-8736-7e3dd9612116 -version: 1 -date: '2018-11-02' +version: 2 +date: '2024-08-16' author: Rico Valdez, Splunk status: deprecated type: TTP @@ -31,10 +31,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/access_lsass_memory_for_dump_creation.yml b/detections/endpoint/access_lsass_memory_for_dump_creation.yml index 04d4d021a0..0c282ff14a 100644 --- a/detections/endpoint/access_lsass_memory_for_dump_creation.yml +++ b/detections/endpoint/access_lsass_memory_for_dump_creation.yml @@ -1,7 +1,7 @@ name: Access LSASS Memory for Dump Creation id: fb4c31b0-13e8-4155-8aa5-24de4b8d6717 -version: 3 -date: '2024-05-13' +version: 4 +date: '2024-08-14' author: Patrick Bareiss, Splunk status: production type: TTP @@ -50,7 +50,7 @@ tags: - name: TargetImage type: Process role: - - Target + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/account_discovery_with_net_app.yml b/detections/endpoint/account_discovery_with_net_app.yml index 9c6aa7d7a1..bf8e536cbc 100644 --- a/detections/endpoint/account_discovery_with_net_app.yml +++ b/detections/endpoint/account_discovery_with_net_app.yml @@ -1,7 +1,7 @@ name: Account Discovery With Net App id: 339805ce-ac30-11eb-b87d-acde48001122 -version: 5 -date: '2024-05-22' +version: 6 +date: '2024-08-15' author: Teoderick Contreras, Splunk, TheLawsOfChaos, Github Community status: production type: TTP @@ -61,7 +61,7 @@ tags: - name: process_name type: Process Name role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/anomalous_usage_of_7zip.yml b/detections/endpoint/anomalous_usage_of_7zip.yml index 37ed56590f..8244563d1b 100644 --- a/detections/endpoint/anomalous_usage_of_7zip.yml +++ b/detections/endpoint/anomalous_usage_of_7zip.yml @@ -1,7 +1,7 @@ name: Anomalous usage of 7zip id: 9364ee8e-a39a-11eb-8f1d-acde48001122 -version: 3 -date: '2024-05-25' +version: 4 +date: '2024-08-15' author: Michael Haag, Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,11 +64,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/any_powershell_downloadfile.yml b/detections/endpoint/any_powershell_downloadfile.yml index 5455e24e79..c76c357157 100644 --- a/detections/endpoint/any_powershell_downloadfile.yml +++ b/detections/endpoint/any_powershell_downloadfile.yml @@ -1,7 +1,7 @@ name: Any Powershell DownloadFile id: 1a93b7ea-7af7-11eb-adb5-acde48001122 -version: 4 -date: '2024-05-25' +version: 5 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -72,11 +72,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/any_powershell_downloadstring.yml b/detections/endpoint/any_powershell_downloadstring.yml index 7b8a99521f..56a372e004 100644 --- a/detections/endpoint/any_powershell_downloadstring.yml +++ b/detections/endpoint/any_powershell_downloadstring.yml @@ -1,7 +1,7 @@ name: Any Powershell DownloadString id: 4d015ef2-7adf-11eb-95da-acde48001122 -version: 4 -date: '2024-05-10' +version: 5 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -73,11 +73,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml index 4b9f66efaa..945ee8c019 100644 --- a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml +++ b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml @@ -1,7 +1,7 @@ name: Attempt To Add Certificate To Untrusted Store id: 6bc5243e-ef36-45dc-9b12-f4a6be131159 -version: 8 -date: '2024-05-12' +version: 9 +date: '2024-08-15' author: Patrick Bareiss, Rico Valdez, Splunk status: production type: TTP @@ -54,11 +54,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/attempt_to_stop_security_service.yml b/detections/endpoint/attempt_to_stop_security_service.yml index 6a3c54360b..247d5e8c65 100644 --- a/detections/endpoint/attempt_to_stop_security_service.yml +++ b/detections/endpoint/attempt_to_stop_security_service.yml @@ -1,7 +1,7 @@ name: Attempt To Stop Security Service id: c8e349c6-b97c-486e-8949-bd7bcd1f3910 -version: 5 -date: '2024-05-21' +version: 6 +date: '2024-08-14' author: Rico Valdez, Splunk status: production type: TTP @@ -61,11 +61,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml index 0ef5debd5a..8a14856d49 100644 --- a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml @@ -1,7 +1,7 @@ name: Attempted Credential Dump From Registry via Reg exe id: e9fb4a59-c5fb-440a-9f24-191fbc6b2911 -version: 8 -date: '2024-05-19' +version: 9 +date: '2024-08-14' author: Patrick Bareiss, Splunk status: production type: TTP @@ -66,11 +66,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/bcdedit_failure_recovery_modification.yml b/detections/endpoint/bcdedit_failure_recovery_modification.yml index d49abaada7..32a3673216 100644 --- a/detections/endpoint/bcdedit_failure_recovery_modification.yml +++ b/detections/endpoint/bcdedit_failure_recovery_modification.yml @@ -1,7 +1,7 @@ name: BCDEdit Failure Recovery Modification id: 809b31d2-5462-11eb-ae93-0242ac130002 -version: 2 -date: '2024-05-15' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -59,11 +59,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/bits_job_persistence.yml b/detections/endpoint/bits_job_persistence.yml index 36a409ddd5..4379bb93ab 100644 --- a/detections/endpoint/bits_job_persistence.yml +++ b/detections/endpoint/bits_job_persistence.yml @@ -1,7 +1,7 @@ name: BITS Job Persistence id: e97a5ffe-90bf-11eb-928a-acde48001122 -version: 3 -date: '2024-05-21' +version: 4 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -64,11 +64,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/bitsadmin_download_file.yml b/detections/endpoint/bitsadmin_download_file.yml index 1cf57d3352..33f0bd5274 100644 --- a/detections/endpoint/bitsadmin_download_file.yml +++ b/detections/endpoint/bitsadmin_download_file.yml @@ -1,7 +1,7 @@ name: BITSAdmin Download File id: 80630ff4-8e4c-11eb-aab5-acde48001122 -version: 4 -date: '2024-05-20' +version: 5 +date: '2024-08-15' author: Michael Haag, Sittikorn S status: production type: TTP @@ -68,11 +68,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml b/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml index 01481cc3e8..89e47268a2 100644 --- a/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml +++ b/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml @@ -1,7 +1,7 @@ name: CertUtil Download With URLCache and Split Arguments id: 415b4306-8bfb-11eb-85c4-acde48001122 -version: 4 -date: '2024-05-11' +version: 5 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -67,11 +67,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml b/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml index 8e754fd5f8..57af0886fa 100644 --- a/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml +++ b/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml @@ -1,7 +1,7 @@ name: CertUtil Download With VerifyCtl and Split Arguments id: 801ad9e4-8bfb-11eb-8b31-acde48001122 -version: 4 -date: '2024-05-17' +version: 5 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -64,11 +64,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/certutil_exe_certificate_extraction.yml b/detections/endpoint/certutil_exe_certificate_extraction.yml index c8dde3208e..f84a08cd1c 100644 --- a/detections/endpoint/certutil_exe_certificate_extraction.yml +++ b/detections/endpoint/certutil_exe_certificate_extraction.yml @@ -1,7 +1,7 @@ name: Certutil exe certificate extraction id: 337a46be-600f-11eb-ae93-0242ac130002 -version: 3 -date: '2024-05-16' +version: 4 +date: '2024-08-14' author: Rod Soto, Splunk status: production type: TTP @@ -61,11 +61,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/certutil_with_decode_argument.yml b/detections/endpoint/certutil_with_decode_argument.yml index f4c25f7b0a..b5efcb0b87 100644 --- a/detections/endpoint/certutil_with_decode_argument.yml +++ b/detections/endpoint/certutil_with_decode_argument.yml @@ -1,7 +1,7 @@ name: CertUtil With Decode Argument id: bfe94226-8c10-11eb-a4b3-acde48001122 -version: 3 -date: '2024-05-27' +version: 4 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -69,11 +69,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml b/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml index e643ff1945..33233fc057 100644 --- a/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml +++ b/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml @@ -1,7 +1,7 @@ name: Clear Unallocated Sector Using Cipher App id: cd80a6ac-c9d9-11eb-8839-acde48001122 -version: 2 -date: '2024-05-17' +version: 3 +date: '2024-08-15' author: Teoderick Contreras, Splunk status: production type: TTP @@ -59,11 +59,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/clop_common_exec_parameter.yml b/detections/endpoint/clop_common_exec_parameter.yml index f22c836b05..e01280c1e6 100644 --- a/detections/endpoint/clop_common_exec_parameter.yml +++ b/detections/endpoint/clop_common_exec_parameter.yml @@ -1,7 +1,7 @@ name: Clop Common Exec Parameter id: 5a8a2a72-8322-11eb-9ee9-acde48001122 -version: 3 -date: '2024-05-31' +version: 4 +date: '2024-08-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -59,11 +59,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/cmd_echo_pipe___escalation.yml b/detections/endpoint/cmd_echo_pipe___escalation.yml index 7f4267b42a..d2531d3245 100644 --- a/detections/endpoint/cmd_echo_pipe___escalation.yml +++ b/detections/endpoint/cmd_echo_pipe___escalation.yml @@ -1,7 +1,7 @@ name: CMD Echo Pipe - Escalation id: eb277ba0-b96b-11eb-b00e-acde48001122 -version: 3 -date: '2024-05-19' +version: 4 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -65,11 +65,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml b/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml index fd291497ce..4a0cdfcd86 100644 --- a/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml +++ b/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml @@ -1,7 +1,7 @@ name: Cmdline Tool Not Executed In CMD Shell id: 6c3f7dd8-153c-11ec-ac2d-acde48001122 -version: 3 -date: '2024-05-16' +version: 4 +date: '2024-08-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -75,11 +75,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/cobalt_strike_named_pipes.yml b/detections/endpoint/cobalt_strike_named_pipes.yml index c9057d1433..3a60b52502 100644 --- a/detections/endpoint/cobalt_strike_named_pipes.yml +++ b/detections/endpoint/cobalt_strike_named_pipes.yml @@ -1,7 +1,7 @@ name: Cobalt Strike Named Pipes id: 5876d429-0240-4709-8b93-ea8330b411b5 -version: 3 -date: '2024-05-16' +version: 4 +date: '2024-08-19' author: Michael Haag, Splunk status: production type: TTP @@ -59,7 +59,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/conti_common_exec_parameter.yml b/detections/endpoint/conti_common_exec_parameter.yml index 8d5d490ba6..1eee21b88d 100644 --- a/detections/endpoint/conti_common_exec_parameter.yml +++ b/detections/endpoint/conti_common_exec_parameter.yml @@ -1,7 +1,7 @@ name: Conti Common Exec parameter id: 624919bc-c382-11eb-adcc-acde48001122 -version: 2 -date: '2024-05-21' +version: 3 +date: '2024-08-15' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,11 +60,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/control_loading_from_world_writable_directory.yml b/detections/endpoint/control_loading_from_world_writable_directory.yml index 7347951756..ba1397c567 100644 --- a/detections/endpoint/control_loading_from_world_writable_directory.yml +++ b/detections/endpoint/control_loading_from_world_writable_directory.yml @@ -1,7 +1,7 @@ name: Control Loading from World Writable Directory id: 10423ac4-10c9-11ec-8dc4-acde48001122 -version: 2 -date: '2024-05-21' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -68,11 +68,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/create_local_admin_accounts_using_net_exe.yml b/detections/endpoint/create_local_admin_accounts_using_net_exe.yml index 4264233edf..ba8cbe5360 100644 --- a/detections/endpoint/create_local_admin_accounts_using_net_exe.yml +++ b/detections/endpoint/create_local_admin_accounts_using_net_exe.yml @@ -1,7 +1,7 @@ name: Create local admin accounts using net exe id: b89919ed-fe5f-492c-b139-151bb162040e -version: 10 -date: '2024-05-11' +version: 11 +date: '2024-08-14' author: Bhavin Patel, Splunk status: production type: TTP @@ -58,11 +58,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml index 1e5abbd05b..035e064567 100644 --- a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml +++ b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml @@ -1,7 +1,7 @@ name: Create or delete windows shares using net exe id: 743a322c-9a68-4a0f-9c17-85d9cce2a27c -version: 7 -date: '2024-05-26' +version: 8 +date: '2024-08-15' author: Bhavin Patel, Splunk status: production type: TTP @@ -57,11 +57,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/create_remote_thread_into_lsass.yml b/detections/endpoint/create_remote_thread_into_lsass.yml index 1def414675..ea1084f575 100644 --- a/detections/endpoint/create_remote_thread_into_lsass.yml +++ b/detections/endpoint/create_remote_thread_into_lsass.yml @@ -1,7 +1,7 @@ name: Create Remote Thread into LSASS id: 67d4dbef-9564-4699-8da8-03a151529edc -version: 2 -date: '2024-05-26' +version: 3 +date: '2024-08-14' author: Patrick Bareiss, Splunk status: production type: TTP @@ -43,7 +43,7 @@ tags: - name: TargetImage type: Other role: - - Other + - Attacker - name: dest type: Hostname role: diff --git a/detections/endpoint/curl_download_and_bash_execution.yml b/detections/endpoint/curl_download_and_bash_execution.yml index 5f074c7b88..233013ef6c 100644 --- a/detections/endpoint/curl_download_and_bash_execution.yml +++ b/detections/endpoint/curl_download_and_bash_execution.yml @@ -1,7 +1,7 @@ name: Curl Download and Bash Execution id: 900bc324-59f3-11ec-9fb4-acde48001122 -version: 2 -date: '2024-05-11' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -64,7 +64,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/deleting_of_net_users.yml b/detections/endpoint/deleting_of_net_users.yml index aa2aa52505..c995182dc3 100644 --- a/detections/endpoint/deleting_of_net_users.yml +++ b/detections/endpoint/deleting_of_net_users.yml @@ -1,7 +1,7 @@ name: Deleting Of Net Users id: 1c8c6f66-acce-11eb-aafb-acde48001122 -version: 3 -date: '2024-05-21' +version: 4 +date: '2024-08-15' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,11 +60,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/deleting_shadow_copies.yml b/detections/endpoint/deleting_shadow_copies.yml index ef98a61925..73b759ca68 100644 --- a/detections/endpoint/deleting_shadow_copies.yml +++ b/detections/endpoint/deleting_shadow_copies.yml @@ -1,7 +1,7 @@ name: Deleting Shadow Copies id: b89919ed-ee5f-492c-b139-95dbb162039e -version: 5 -date: '2024-05-18' +version: 6 +date: '2024-08-15' author: David Dorsey, Splunk status: production type: TTP @@ -69,11 +69,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_azurehound_command_line_arguments.yml b/detections/endpoint/detect_azurehound_command_line_arguments.yml index 23fd528463..a828f071f7 100644 --- a/detections/endpoint/detect_azurehound_command_line_arguments.yml +++ b/detections/endpoint/detect_azurehound_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Detect AzureHound Command-Line Arguments id: 26f02e96-c300-11eb-b611-acde48001122 -version: 3 -date: '2024-05-29' +version: 4 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -65,11 +65,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_baron_samedit_cve_2021_3156.yml b/detections/endpoint/detect_baron_samedit_cve_2021_3156.yml index b185a14275..678bd5d60b 100644 --- a/detections/endpoint/detect_baron_samedit_cve_2021_3156.yml +++ b/detections/endpoint/detect_baron_samedit_cve_2021_3156.yml @@ -1,7 +1,7 @@ name: Detect Baron Samedit CVE-2021-3156 id: 93fbec4e-0375-440c-8db3-4508eca470c4 -version: 2 -date: '2024-05-15' +version: 3 +date: '2024-08-16' author: Shannon Davis, Splunk status: experimental type: TTP @@ -30,7 +30,7 @@ tags: - name: dest type: Other role: - - Other + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml b/detections/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml index 4968593a16..1fa46b7c0d 100644 --- a/detections/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml +++ b/detections/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml @@ -1,7 +1,7 @@ name: Detect Baron Samedit CVE-2021-3156 Segfault id: 10f2bae0-bbe6-4984-808c-37dc1c67980d -version: 2 -date: '2024-05-28' +version: 3 +date: '2024-08-16' author: Shannon Davis, Splunk status: experimental type: TTP @@ -30,10 +30,10 @@ tags: mitre_attack_id: - T1068 observable: - - name: dest - type: Other + - name: host + type: Hostname role: - - Other + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_baron_samedit_cve_2021_3156_via_osquery.yml b/detections/endpoint/detect_baron_samedit_cve_2021_3156_via_osquery.yml index 6a17163717..1158e312ba 100644 --- a/detections/endpoint/detect_baron_samedit_cve_2021_3156_via_osquery.yml +++ b/detections/endpoint/detect_baron_samedit_cve_2021_3156_via_osquery.yml @@ -1,7 +1,7 @@ name: Detect Baron Samedit CVE-2021-3156 via OSQuery id: 1de31d5d-8fa6-4ee0-af89-17069134118a -version: 2 -date: '2024-05-13' +version: 3 +date: '2024-08-16' author: Shannon Davis, Splunk status: experimental type: TTP @@ -36,7 +36,7 @@ tags: - name: dest type: Other role: - - Other + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_computer_changed_with_anonymous_account.yml b/detections/endpoint/detect_computer_changed_with_anonymous_account.yml index c0e053fe2b..df11ec6e4e 100644 --- a/detections/endpoint/detect_computer_changed_with_anonymous_account.yml +++ b/detections/endpoint/detect_computer_changed_with_anonymous_account.yml @@ -1,7 +1,7 @@ name: Detect Computer Changed with Anonymous Account id: 1400624a-d42d-484d-8843-e6753e6e3645 -version: 2 -date: '2024-05-18' +version: 3 +date: '2024-08-14' author: Rod Soto, Jose Hernandez, Splunk status: experimental type: Hunting @@ -49,10 +49,6 @@ tags: type: Hostname role: - Victim - - name: EventCode - type: Other - role: - - Other product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_html_help_renamed.yml b/detections/endpoint/detect_html_help_renamed.yml index 96c1c6504d..1fcfd47894 100644 --- a/detections/endpoint/detect_html_help_renamed.yml +++ b/detections/endpoint/detect_html_help_renamed.yml @@ -1,7 +1,7 @@ name: Detect HTML Help Renamed id: 62fed254-513b-460e-953d-79771493a9f3 -version: 5 -date: '2024-05-16' +version: 6 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: Hunting @@ -62,11 +62,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_html_help_spawn_child_process.yml b/detections/endpoint/detect_html_help_spawn_child_process.yml index 0bf59fa7b4..113cf71403 100644 --- a/detections/endpoint/detect_html_help_spawn_child_process.yml +++ b/detections/endpoint/detect_html_help_spawn_child_process.yml @@ -1,7 +1,7 @@ name: Detect HTML Help Spawn Child Process id: 723716de-ee55-4cd4-9759-c44e7e55ba4b -version: 3 -date: '2024-05-24' +version: 4 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -66,11 +66,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_html_help_url_in_command_line.yml b/detections/endpoint/detect_html_help_url_in_command_line.yml index 39e6d921f4..bd17fc086d 100644 --- a/detections/endpoint/detect_html_help_url_in_command_line.yml +++ b/detections/endpoint/detect_html_help_url_in_command_line.yml @@ -1,7 +1,7 @@ name: Detect HTML Help URL in Command Line id: 8c5835b9-39d9-438b-817c-95f14c69a31e -version: 3 -date: '2024-05-25' +version: 4 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -65,11 +65,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml b/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml index c12f5cc105..f40540b70d 100644 --- a/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml +++ b/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml @@ -1,7 +1,7 @@ name: Detect HTML Help Using InfoTech Storage Handlers id: 0b2eefa5-5508-450d-b970-3dd2fb761aec -version: 3 -date: '2024-05-29' +version: 4 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -65,7 +65,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_mshta_inline_hta_execution.yml b/detections/endpoint/detect_mshta_inline_hta_execution.yml index 9e3393e513..834eaca9cf 100644 --- a/detections/endpoint/detect_mshta_inline_hta_execution.yml +++ b/detections/endpoint/detect_mshta_inline_hta_execution.yml @@ -1,7 +1,7 @@ name: Detect mshta inline hta execution id: a0873b32-5b68-11eb-ae93-0242ac130002 -version: 7 -date: '2024-05-21' +version: 8 +date: '2024-08-15' author: Bhavin Patel, Michael Haag, Splunk status: production type: TTP @@ -65,11 +65,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_mshta_renamed.yml b/detections/endpoint/detect_mshta_renamed.yml index e9ec5aeee1..591b2e1d27 100644 --- a/detections/endpoint/detect_mshta_renamed.yml +++ b/detections/endpoint/detect_mshta_renamed.yml @@ -1,7 +1,7 @@ name: Detect mshta renamed id: 8f45fcf0-5b68-11eb-ae93-0242ac130002 -version: 4 -date: '2024-05-17' +version: 5 +date: '2024-08-19' author: Michael Haag, Splunk status: production type: Hunting @@ -60,11 +60,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_mshta_url_in_command_line.yml b/detections/endpoint/detect_mshta_url_in_command_line.yml index 3ae2c2e361..c78fdcfa1b 100644 --- a/detections/endpoint/detect_mshta_url_in_command_line.yml +++ b/detections/endpoint/detect_mshta_url_in_command_line.yml @@ -1,7 +1,7 @@ name: Detect MSHTA Url in Command Line id: 9b3af1e6-5b68-11eb-ae93-0242ac130002 -version: 3 -date: '2024-05-26' +version: 4 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -62,11 +62,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml index 13e0540cab..d2778235e2 100644 --- a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml +++ b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml @@ -1,7 +1,7 @@ name: Detect Path Interception By Creation Of program exe id: cbef820c-e1ff-407f-887f-0a9240a2d477 -version: 6 -date: '2024-05-19' +version: 7 +date: '2024-08-15' author: Patrick Bareiss, Splunk status: production type: TTP @@ -60,11 +60,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml b/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml index 34ed7012f3..7e95149565 100644 --- a/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml +++ b/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml @@ -1,7 +1,7 @@ name: Detect processes used for System Network Configuration Discovery id: a51bfe1a-94f0-48cc-b1e4-16ae10145893 -version: 3 -date: '2024-05-19' +version: 4 +date: '2024-08-14' author: Bhavin Patel, Splunk status: production type: TTP @@ -63,11 +63,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml index 42b3afa82c..d172a73497 100644 --- a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml +++ b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml @@ -1,7 +1,7 @@ name: Detect Prohibited Applications Spawning cmd exe id: dcfd6b40-42f9-469d-a433-2e53f7486664 -version: 7 -date: '2024-05-16' +version: 8 +date: '2024-08-14' author: Bhavin Patel, Splunk status: production type: Hunting @@ -62,11 +62,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_psexec_with_accepteula_flag.yml b/detections/endpoint/detect_psexec_with_accepteula_flag.yml index 7425d35887..12b4ccafa8 100644 --- a/detections/endpoint/detect_psexec_with_accepteula_flag.yml +++ b/detections/endpoint/detect_psexec_with_accepteula_flag.yml @@ -1,7 +1,7 @@ name: Detect PsExec With accepteula Flag id: 27c3a83d-cada-47c6-9042-67baf19d2574 -version: 5 -date: '2024-05-23' +version: 6 +date: '2024-08-15' author: Bhavin Patel, Splunk status: production type: TTP @@ -72,11 +72,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_rclone_command_line_usage.yml b/detections/endpoint/detect_rclone_command_line_usage.yml index 4f19089aa9..1d4f8d0d66 100644 --- a/detections/endpoint/detect_rclone_command_line_usage.yml +++ b/detections/endpoint/detect_rclone_command_line_usage.yml @@ -1,7 +1,7 @@ name: Detect RClone Command-Line Usage id: 32e0baea-b3f1-11eb-a2ce-acde48001122 -version: 3 -date: '2024-05-26' +version: 4 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -65,11 +65,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_regasm_spawning_a_process.yml b/detections/endpoint/detect_regasm_spawning_a_process.yml index 20f4394891..4bc1491bfd 100644 --- a/detections/endpoint/detect_regasm_spawning_a_process.yml +++ b/detections/endpoint/detect_regasm_spawning_a_process.yml @@ -1,7 +1,7 @@ name: Detect Regasm Spawning a Process id: 72170ec5-f7d2-42f5-aefb-2b8be6aad15f -version: 4 -date: '2024-05-26' +version: 5 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -69,11 +69,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_regasm_with_network_connection.yml b/detections/endpoint/detect_regasm_with_network_connection.yml index ad207b3369..231770a635 100644 --- a/detections/endpoint/detect_regasm_with_network_connection.yml +++ b/detections/endpoint/detect_regasm_with_network_connection.yml @@ -1,7 +1,7 @@ name: Detect Regasm with Network Connection id: 07921114-6db4-4e2e-ae58-3ea8a52ae93f -version: 4 -date: '2024-05-24' +version: 5 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -54,7 +54,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml b/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml index 8bba49bde1..9501aa1fcb 100644 --- a/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml +++ b/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Detect Regasm with no Command Line Arguments id: c3bc1430-04e7-4178-835f-047d8e6e97df -version: 4 -date: '2024-05-26' +version: 5 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -64,11 +64,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_regsvcs_spawning_a_process.yml b/detections/endpoint/detect_regsvcs_spawning_a_process.yml index 646e697301..c2fb510964 100644 --- a/detections/endpoint/detect_regsvcs_spawning_a_process.yml +++ b/detections/endpoint/detect_regsvcs_spawning_a_process.yml @@ -1,7 +1,7 @@ name: Detect Regsvcs Spawning a Process id: bc477b57-5c21-4ab6-9c33-668772e7f114 -version: 3 -date: '2024-05-24' +version: 4 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -64,11 +64,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_regsvcs_with_network_connection.yml b/detections/endpoint/detect_regsvcs_with_network_connection.yml index 10b6cd44f8..fb7b596429 100644 --- a/detections/endpoint/detect_regsvcs_with_network_connection.yml +++ b/detections/endpoint/detect_regsvcs_with_network_connection.yml @@ -1,7 +1,7 @@ name: Detect Regsvcs with Network Connection id: e3e7a1c0-f2b9-445c-8493-f30a63522d1a -version: 4 -date: '2024-05-19' +version: 5 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -54,7 +54,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml b/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml index 0a0fe2847a..0454c0a987 100644 --- a/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml +++ b/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Detect Regsvcs with No Command Line Arguments id: 6b74d578-a02e-4e94-a0d1-39440d0bf254 -version: 4 -date: '2024-05-19' +version: 5 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -62,11 +62,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_regsvr32_application_control_bypass.yml b/detections/endpoint/detect_regsvr32_application_control_bypass.yml index ccb6c34f83..d42ce4f9f0 100644 --- a/detections/endpoint/detect_regsvr32_application_control_bypass.yml +++ b/detections/endpoint/detect_regsvr32_application_control_bypass.yml @@ -1,7 +1,7 @@ name: Detect Regsvr32 Application Control Bypass id: 070e9b80-6252-11eb-ae93-0242ac130002 -version: 3 -date: '2024-05-22' +version: 4 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -67,11 +67,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_renamed_7_zip.yml b/detections/endpoint/detect_renamed_7_zip.yml index 4e2ebc0a7f..e5c8ad816f 100644 --- a/detections/endpoint/detect_renamed_7_zip.yml +++ b/detections/endpoint/detect_renamed_7_zip.yml @@ -1,7 +1,7 @@ name: Detect Renamed 7-Zip id: 4057291a-b8cf-11eb-95fe-acde48001122 -version: 3 -date: '2024-05-20' +version: 4 +date: '2024-08-19' author: Michael Haag, Splunk status: production type: Hunting @@ -60,11 +60,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_renamed_psexec.yml b/detections/endpoint/detect_renamed_psexec.yml index 9d7d8bc7d4..a9236778b2 100644 --- a/detections/endpoint/detect_renamed_psexec.yml +++ b/detections/endpoint/detect_renamed_psexec.yml @@ -1,7 +1,7 @@ name: Detect Renamed PSExec id: 683e6196-b8e8-11eb-9a79-acde48001122 -version: 6 -date: '2024-07-23' +version: 7 +date: '2024-08-19' author: Michael Haag, Splunk, Alex Oberkircher, Github Community status: production type: Hunting @@ -69,11 +69,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_renamed_rclone.yml b/detections/endpoint/detect_renamed_rclone.yml index 7f6f2869a7..d6032f2c99 100644 --- a/detections/endpoint/detect_renamed_rclone.yml +++ b/detections/endpoint/detect_renamed_rclone.yml @@ -1,7 +1,7 @@ name: Detect Renamed RClone id: 6dca1124-b3ec-11eb-9328-acde48001122 -version: 3 -date: '2024-05-15' +version: 4 +date: '2024-08-19' author: Michael Haag, Splunk status: production type: Hunting @@ -61,11 +61,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_renamed_winrar.yml b/detections/endpoint/detect_renamed_winrar.yml index b5f4ed522a..1926d1a1ec 100644 --- a/detections/endpoint/detect_renamed_winrar.yml +++ b/detections/endpoint/detect_renamed_winrar.yml @@ -1,7 +1,7 @@ name: Detect Renamed WinRAR id: 1b7bfb2c-b8e6-11eb-99ac-acde48001122 -version: 4 -date: '2024-05-25' +version: 5 +date: '2024-08-19' author: Michael Haag, Splunk status: production type: Hunting @@ -60,11 +60,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml b/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml index f8f73f69f3..71b09f18ff 100644 --- a/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml +++ b/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml @@ -1,7 +1,7 @@ name: Detect Rundll32 Application Control Bypass - advpack id: 4aefadfe-9abd-4bf8-b3fd-867e9ef95bf8 -version: 3 -date: '2024-05-17' +version: 4 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -65,11 +65,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml b/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml index 9d20f58aff..6f39892922 100644 --- a/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml +++ b/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml @@ -1,7 +1,7 @@ name: Detect Rundll32 Application Control Bypass - setupapi id: 61e7b44a-6088-4f26-b788-9a96ba13b37a -version: 3 -date: '2024-05-11' +version: 4 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -65,11 +65,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml b/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml index 721f1d0f62..f41c2113db 100644 --- a/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml +++ b/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml @@ -1,7 +1,7 @@ name: Detect Rundll32 Application Control Bypass - syssetup id: 71b9bf37-cde1-45fb-b899-1b0aa6fa1183 -version: 3 -date: '2024-05-27' +version: 4 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -65,11 +65,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disabling_net_user_account.yml b/detections/endpoint/disabling_net_user_account.yml index fcc5590493..30f988413b 100644 --- a/detections/endpoint/disabling_net_user_account.yml +++ b/detections/endpoint/disabling_net_user_account.yml @@ -1,7 +1,7 @@ name: Disabling Net User Account id: c0325326-acd6-11eb-98c2-acde48001122 -version: 3 -date: '2024-05-23' +version: 4 +date: '2024-08-15' author: Teoderick Contreras, Splunk status: production type: TTP @@ -57,11 +57,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml b/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml index 1788a42946..fd13045f93 100644 --- a/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml +++ b/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml @@ -1,7 +1,7 @@ name: DLLHost with no Command Line Arguments with Network id: f1c07594-a141-11eb-8407-acde48001122 -version: 5 -date: '2024-05-26' +version: 6 +date: '2024-08-14' author: Steven Dick, Michael Haag, Splunk status: experimental type: TTP @@ -63,11 +63,11 @@ tags: - name: parent_image type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/dns_exfiltration_using_nslookup_app.yml b/detections/endpoint/dns_exfiltration_using_nslookup_app.yml index ce76b2bb3e..731d77825d 100644 --- a/detections/endpoint/dns_exfiltration_using_nslookup_app.yml +++ b/detections/endpoint/dns_exfiltration_using_nslookup_app.yml @@ -1,7 +1,7 @@ name: DNS Exfiltration Using Nslookup App id: 2452e632-9e0d-11eb-bacd-acde48001122 -version: 2 -date: '2024-05-19' +version: 3 +date: '2024-08-15' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,11 +64,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/domain_account_discovery_with_dsquery.yml b/detections/endpoint/domain_account_discovery_with_dsquery.yml index 9568e08f11..75239be94a 100644 --- a/detections/endpoint/domain_account_discovery_with_dsquery.yml +++ b/detections/endpoint/domain_account_discovery_with_dsquery.yml @@ -1,7 +1,7 @@ name: Domain Account Discovery with Dsquery id: b1a8ce04-04c2-11ec-bea7-acde48001122 -version: 2 -date: '2024-05-26' +version: 3 +date: '2024-08-14' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: Hunting @@ -58,7 +58,7 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/domain_account_discovery_with_net_app.yml b/detections/endpoint/domain_account_discovery_with_net_app.yml index afcc6c7711..3e76b9972f 100644 --- a/detections/endpoint/domain_account_discovery_with_net_app.yml +++ b/detections/endpoint/domain_account_discovery_with_net_app.yml @@ -1,7 +1,7 @@ name: Domain Account Discovery With Net App id: 98f6a534-04c2-11ec-96b2-acde48001122 -version: 2 -date: '2024-05-27' +version: 3 +date: '2024-08-14' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -59,7 +59,7 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/domain_account_discovery_with_wmic.yml b/detections/endpoint/domain_account_discovery_with_wmic.yml index 0bc293890b..00a62ab62b 100644 --- a/detections/endpoint/domain_account_discovery_with_wmic.yml +++ b/detections/endpoint/domain_account_discovery_with_wmic.yml @@ -1,7 +1,7 @@ name: Domain Account Discovery with Wmic id: 383572e0-04c5-11ec-bdcc-acde48001122 -version: 2 -date: '2024-05-11' +version: 3 +date: '2024-08-14' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,7 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/dsquery_domain_discovery.yml b/detections/endpoint/dsquery_domain_discovery.yml index c93cf5eeaf..23b7ff6d42 100644 --- a/detections/endpoint/dsquery_domain_discovery.yml +++ b/detections/endpoint/dsquery_domain_discovery.yml @@ -1,7 +1,7 @@ name: DSQuery Domain Discovery id: cc316032-924a-11eb-91a2-acde48001122 -version: 2 -date: '2024-05-31' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -62,11 +62,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml index f74ff6c01a..9a57399487 100644 --- a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml +++ b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml @@ -1,7 +1,7 @@ name: Dump LSASS via comsvcs DLL id: 8943b567-f14d-4ee8-a0bb-2121d4ce3184 -version: 3 -date: '2024-05-25' +version: 4 +date: '2024-08-14' author: Patrick Bareiss, Splunk status: production type: TTP @@ -63,11 +63,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/dump_lsass_via_procdump.yml b/detections/endpoint/dump_lsass_via_procdump.yml index c43a1f303b..6f132ed1b3 100644 --- a/detections/endpoint/dump_lsass_via_procdump.yml +++ b/detections/endpoint/dump_lsass_via_procdump.yml @@ -1,7 +1,7 @@ name: Dump LSASS via procdump id: 3742ebfe-64c2-11eb-ae93-0242ac130002 -version: 4 -date: '2024-05-11' +version: 5 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -63,11 +63,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/esentutl_sam_copy.yml b/detections/endpoint/esentutl_sam_copy.yml index 484a90ff0c..8f9cfe3e28 100644 --- a/detections/endpoint/esentutl_sam_copy.yml +++ b/detections/endpoint/esentutl_sam_copy.yml @@ -1,7 +1,7 @@ name: Esentutl SAM Copy id: d372f928-ce4f-11eb-a762-acde48001122 -version: 2 -date: '2024-05-16' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Hunting @@ -61,11 +61,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/excel_spawning_powershell.yml b/detections/endpoint/excel_spawning_powershell.yml index a3e559a028..c6f1b400cd 100644 --- a/detections/endpoint/excel_spawning_powershell.yml +++ b/detections/endpoint/excel_spawning_powershell.yml @@ -1,7 +1,7 @@ name: Excel Spawning PowerShell id: 42d40a22-9be3-11eb-8f08-acde48001122 -version: 3 -date: '2024-05-15' +version: 4 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -60,11 +60,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/excel_spawning_windows_script_host.yml b/detections/endpoint/excel_spawning_windows_script_host.yml index 0dbb970645..8b05de1a31 100644 --- a/detections/endpoint/excel_spawning_windows_script_host.yml +++ b/detections/endpoint/excel_spawning_windows_script_host.yml @@ -1,7 +1,7 @@ name: Excel Spawning Windows Script Host id: 57fe880a-9be3-11eb-9bf3-acde48001122 -version: 3 -date: '2024-05-20' +version: 4 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -61,11 +61,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/excessive_attempt_to_disable_services.yml b/detections/endpoint/excessive_attempt_to_disable_services.yml index 289c6878be..495f558e24 100644 --- a/detections/endpoint/excessive_attempt_to_disable_services.yml +++ b/detections/endpoint/excessive_attempt_to_disable_services.yml @@ -1,7 +1,7 @@ name: Excessive Attempt To Disable Services id: 8fa2a0f0-acd9-11eb-8994-acde48001122 -version: 2 -date: '2024-05-04' +version: 3 +date: '2024-08-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -55,7 +55,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml index 84c8c83e3d..a6aa5f7d1e 100644 --- a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml +++ b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml @@ -1,7 +1,7 @@ name: Excessive number of service control start as disabled id: 77592bec-d5cc-11eb-9e60-acde48001122 -version: 2 -date: '2024-05-19' +version: 3 +date: '2024-08-15' author: Michael Hart, Splunk status: production type: Anomaly @@ -59,7 +59,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/excessive_service_stop_attempt.yml b/detections/endpoint/excessive_service_stop_attempt.yml index d9f2ccc4cb..ffdff1ffd8 100644 --- a/detections/endpoint/excessive_service_stop_attempt.yml +++ b/detections/endpoint/excessive_service_stop_attempt.yml @@ -1,7 +1,7 @@ name: Excessive Service Stop Attempt id: ae8d3f4a-acd7-11eb-8846-acde48001122 -version: 3 -date: '2024-05-25' +version: 4 +date: '2024-08-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -57,7 +57,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/excessive_usage_of_cacls_app.yml b/detections/endpoint/excessive_usage_of_cacls_app.yml index c25a3d7d46..17b22ae2dd 100644 --- a/detections/endpoint/excessive_usage_of_cacls_app.yml +++ b/detections/endpoint/excessive_usage_of_cacls_app.yml @@ -1,7 +1,7 @@ name: Excessive Usage Of Cacls App id: 0bdf6092-af17-11eb-939a-acde48001122 -version: 2 -date: '2024-05-15' +version: 3 +date: '2024-08-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -57,7 +57,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/excessive_usage_of_taskkill.yml b/detections/endpoint/excessive_usage_of_taskkill.yml index 448d2a796a..06abc48814 100644 --- a/detections/endpoint/excessive_usage_of_taskkill.yml +++ b/detections/endpoint/excessive_usage_of_taskkill.yml @@ -1,7 +1,7 @@ name: Excessive Usage Of Taskkill id: fe5bca48-accb-11eb-a67c-acde48001122 -version: 2 -date: '2024-05-23' +version: 3 +date: '2024-08-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: - name: parent_process_name type: Process Name role: - - Parent Process - Attacker product: - Splunk Enterprise diff --git a/detections/endpoint/execution_of_file_with_multiple_extensions.yml b/detections/endpoint/execution_of_file_with_multiple_extensions.yml index 2fe73696eb..00114026b3 100644 --- a/detections/endpoint/execution_of_file_with_multiple_extensions.yml +++ b/detections/endpoint/execution_of_file_with_multiple_extensions.yml @@ -1,7 +1,7 @@ name: Execution of File with Multiple Extensions id: b06a555e-dce0-417d-a2eb-28a5d8d66ef7 -version: 4 -date: '2024-05-26' +version: 5 +date: '2024-08-14' author: Rico Valdez, Teoderick Contreras, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: - name: process_name type: Process role: - - Parent Process - Attacker product: - Splunk Enterprise diff --git a/detections/endpoint/file_with_samsam_extension.yml b/detections/endpoint/file_with_samsam_extension.yml index 5a80d37e93..a0d5fabec5 100644 --- a/detections/endpoint/file_with_samsam_extension.yml +++ b/detections/endpoint/file_with_samsam_extension.yml @@ -1,7 +1,7 @@ name: File with Samsam Extension id: 02c6cfc2-ae66-4735-bfc7-6291da834cbf -version: 2 -date: '2024-05-22' +version: 3 +date: '2024-08-14' author: Rico Valdez, Splunk status: production type: TTP @@ -45,7 +45,6 @@ tags: - name: file_name type: File Name role: - - Other - Attacker product: - Splunk Enterprise diff --git a/detections/endpoint/first_time_seen_child_process_of_zoom.yml b/detections/endpoint/first_time_seen_child_process_of_zoom.yml index 75ddc76ae6..a76f94fe85 100644 --- a/detections/endpoint/first_time_seen_child_process_of_zoom.yml +++ b/detections/endpoint/first_time_seen_child_process_of_zoom.yml @@ -1,7 +1,7 @@ name: First Time Seen Child Process of Zoom id: e91bd102-d630-4e76-ab73-7e3ba22c5961 -version: 2 -date: '2024-05-20' +version: 3 +date: '2024-08-19' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -62,7 +62,6 @@ tags: type: Process Name role: - Attacker - - Child Process product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml b/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml index d349cb5654..a324c534cf 100644 --- a/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml +++ b/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml @@ -1,7 +1,7 @@ name: Get ADDefaultDomainPasswordPolicy with Powershell id: 36e46ebe-065a-11ec-b4c7-acde48001122 -version: 2 -date: '2024-05-14' +version: 3 +date: '2024-08-14' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -59,7 +59,7 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/get_aduser_with_powershell.yml b/detections/endpoint/get_aduser_with_powershell.yml index 4b3d94f474..d09a8cae5e 100644 --- a/detections/endpoint/get_aduser_with_powershell.yml +++ b/detections/endpoint/get_aduser_with_powershell.yml @@ -1,7 +1,7 @@ name: Get ADUser with PowerShell id: 0b6ee3f4-04e3-11ec-a87d-acde48001122 -version: 2 -date: '2024-05-21' +version: 3 +date: '2024-08-14' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: Hunting @@ -61,7 +61,7 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml b/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml index 32f37856d5..ac5343f902 100644 --- a/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml +++ b/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml @@ -1,7 +1,7 @@ name: Get ADUserResultantPasswordPolicy with Powershell id: 8b5ef342-065a-11ec-b0fc-acde48001122 -version: 2 -date: '2024-05-25' +version: 3 +date: '2024-08-14' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -60,7 +60,7 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/get_domainpolicy_with_powershell.yml b/detections/endpoint/get_domainpolicy_with_powershell.yml index 7a2e87b802..44c3c76536 100644 --- a/detections/endpoint/get_domainpolicy_with_powershell.yml +++ b/detections/endpoint/get_domainpolicy_with_powershell.yml @@ -1,7 +1,7 @@ name: Get DomainPolicy with Powershell id: b8f9947e-065a-11ec-aafb-acde48001122 -version: 2 -date: '2024-05-19' +version: 3 +date: '2024-08-14' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -59,7 +59,7 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/get_domainuser_with_powershell.yml b/detections/endpoint/get_domainuser_with_powershell.yml index da73ac277b..c19b3d9d3d 100644 --- a/detections/endpoint/get_domainuser_with_powershell.yml +++ b/detections/endpoint/get_domainuser_with_powershell.yml @@ -1,7 +1,7 @@ name: Get DomainUser with PowerShell id: 9a5a41d6-04e7-11ec-923c-acde48001122 -version: 2 -date: '2024-05-22' +version: 3 +date: '2024-08-14' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -60,7 +60,7 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml index d2cde911cf..8a5e541ed3 100644 --- a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml +++ b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml @@ -1,7 +1,7 @@ name: GetWmiObject DS User with PowerShell id: 22d3b118-04df-11ec-8fa3-acde48001122 -version: 2 -date: '2024-05-16' +version: 3 +date: '2024-08-14' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -59,7 +59,7 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml b/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml index 76ce24e0be..b9ea5e0814 100644 --- a/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml +++ b/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml @@ -1,7 +1,7 @@ name: GPUpdate with no Command Line Arguments with Network id: 2c853856-a140-11eb-a5b5-acde48001122 -version: 3 -date: '2024-05-25' +version: 4 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: - name: parent_process_name type: Process Name role: - - Parent Process - Attacker - name: C2 type: IP Address diff --git a/detections/endpoint/high_process_termination_frequency.yml b/detections/endpoint/high_process_termination_frequency.yml index b70fe60b7e..1dabbbbd44 100644 --- a/detections/endpoint/high_process_termination_frequency.yml +++ b/detections/endpoint/high_process_termination_frequency.yml @@ -1,7 +1,7 @@ name: High Process Termination Frequency id: 17cd75b2-8666-11eb-9ab4-acde48001122 -version: 3 -date: '2024-05-12' +version: 4 +date: '2024-08-14' author: Teoderick Contreras status: production type: Anomaly @@ -47,7 +47,7 @@ tags: - name: proc_terminated type: Process role: - - Target + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/hunting_3cxdesktopapp_software.yml b/detections/endpoint/hunting_3cxdesktopapp_software.yml index d9914ac6c4..c29c644b5a 100644 --- a/detections/endpoint/hunting_3cxdesktopapp_software.yml +++ b/detections/endpoint/hunting_3cxdesktopapp_software.yml @@ -1,7 +1,7 @@ name: Hunting 3CXDesktopApp Software id: 553d0429-1a1c-44bf-b3f5-a8513deb9ee5 -version: 2 -date: '2024-05-14' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk type: Hunting status: production @@ -59,7 +59,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/java_class_file_download_by_java_user_agent.yml b/detections/endpoint/java_class_file_download_by_java_user_agent.yml index 77213e3c78..45d6b599b1 100644 --- a/detections/endpoint/java_class_file_download_by_java_user_agent.yml +++ b/detections/endpoint/java_class_file_download_by_java_user_agent.yml @@ -1,7 +1,7 @@ name: Java Class File download by Java User Agent id: 8281ce42-5c50-11ec-82d2-acde48001122 -version: 2 -date: '2024-05-16' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -45,11 +45,7 @@ tags: - name: http_user_agent type: Other role: - - Other - - name: http_method - type: Other - role: - - Other + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/java_writing_jsp_file.yml b/detections/endpoint/java_writing_jsp_file.yml index d52ac5996c..07a2d74c85 100644 --- a/detections/endpoint/java_writing_jsp_file.yml +++ b/detections/endpoint/java_writing_jsp_file.yml @@ -1,7 +1,7 @@ name: Java Writing JSP File id: eb65619c-4f8d-4383-a975-d352765d344b -version: 3 -date: '2024-05-27' +version: 4 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -59,7 +59,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/known_services_killed_by_ransomware.yml b/detections/endpoint/known_services_killed_by_ransomware.yml index 0a0cb065f2..978c922db2 100644 --- a/detections/endpoint/known_services_killed_by_ransomware.yml +++ b/detections/endpoint/known_services_killed_by_ransomware.yml @@ -1,7 +1,7 @@ name: Known Services Killed by Ransomware id: 3070f8e0-c528-11eb-b2a0-acde48001122 -version: 3 -date: '2024-05-29' +version: 4 +date: '2024-08-16' author: Teoderick Contreras, Splunk status: production type: TTP @@ -52,7 +52,7 @@ tags: - name: param1 type: Other role: - - Other + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_apt_get_privilege_escalation.yml b/detections/endpoint/linux_apt_get_privilege_escalation.yml index 3f64e0e5be..349a242d94 100644 --- a/detections/endpoint/linux_apt_get_privilege_escalation.yml +++ b/detections/endpoint/linux_apt_get_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux apt-get Privilege Escalation id: d870ce3b-e796-402f-b2af-cab4da1223f2 -version: 2 -date: '2024-05-22' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -55,11 +55,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_apt_privilege_escalation.yml b/detections/endpoint/linux_apt_privilege_escalation.yml index 388b86e419..0057162ea8 100644 --- a/detections/endpoint/linux_apt_privilege_escalation.yml +++ b/detections/endpoint/linux_apt_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux APT Privilege Escalation id: 4d5a05fa-77d9-4fd0-af9c-05704f9f9a88 -version: 2 -date: '2024-05-22' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -55,11 +55,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_awk_privilege_escalation.yml b/detections/endpoint/linux_awk_privilege_escalation.yml index a7fea37ec7..d4bcae6333 100644 --- a/detections/endpoint/linux_awk_privilege_escalation.yml +++ b/detections/endpoint/linux_awk_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux AWK Privilege Escalation id: 4510cae0-96a2-4840-9919-91d262db210a -version: 2 -date: '2024-05-26' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -54,11 +54,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_busybox_privilege_escalation.yml b/detections/endpoint/linux_busybox_privilege_escalation.yml index b32e411a9b..16b0477dff 100644 --- a/detections/endpoint/linux_busybox_privilege_escalation.yml +++ b/detections/endpoint/linux_busybox_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Busybox Privilege Escalation id: 387c4e78-f4a4-413d-ad44-e9f7bc4642c9 -version: 2 -date: '2024-05-27' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -54,11 +54,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_c89_privilege_escalation.yml b/detections/endpoint/linux_c89_privilege_escalation.yml index 912bcac714..c9f84f4d5f 100644 --- a/detections/endpoint/linux_c89_privilege_escalation.yml +++ b/detections/endpoint/linux_c89_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux c89 Privilege Escalation id: 54c95f4d-3e5d-44be-9521-ea19ba62f7a8 -version: 2 -date: '2024-05-30' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -54,11 +54,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_c99_privilege_escalation.yml b/detections/endpoint/linux_c99_privilege_escalation.yml index a13ecbdf76..0abf08917e 100644 --- a/detections/endpoint/linux_c99_privilege_escalation.yml +++ b/detections/endpoint/linux_c99_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux c99 Privilege Escalation id: e1c6dec5-2249-442d-a1f9-99a4bd228183 -version: 2 -date: '2024-05-21' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -54,11 +54,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_clipboard_data_copy.yml b/detections/endpoint/linux_clipboard_data_copy.yml index 4281335323..0ce6bfdb93 100644 --- a/detections/endpoint/linux_clipboard_data_copy.yml +++ b/detections/endpoint/linux_clipboard_data_copy.yml @@ -1,7 +1,7 @@ name: Linux Clipboard Data Copy id: 7173b2ad-6146-418f-85ae-c3479e4515fc -version: 2 -date: '2024-05-17' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Anomaly @@ -56,7 +56,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_composer_privilege_escalation.yml b/detections/endpoint/linux_composer_privilege_escalation.yml index 4860e1f884..73261c22e1 100644 --- a/detections/endpoint/linux_composer_privilege_escalation.yml +++ b/detections/endpoint/linux_composer_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Composer Privilege Escalation id: a3bddf71-6ba3-42ab-a6b2-396929b16d92 -version: 2 -date: '2024-05-28' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -55,11 +55,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_cpulimit_privilege_escalation.yml b/detections/endpoint/linux_cpulimit_privilege_escalation.yml index 2b3e30b903..285fcddf69 100644 --- a/detections/endpoint/linux_cpulimit_privilege_escalation.yml +++ b/detections/endpoint/linux_cpulimit_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Cpulimit Privilege Escalation id: d4e40b7e-aad3-4a7d-aac8-550ea5222be5 -version: 2 -date: '2024-05-23' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -54,11 +54,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_csvtool_privilege_escalation.yml b/detections/endpoint/linux_csvtool_privilege_escalation.yml index d64d789396..82f295b13b 100644 --- a/detections/endpoint/linux_csvtool_privilege_escalation.yml +++ b/detections/endpoint/linux_csvtool_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Csvtool Privilege Escalation id: f8384f9e-1a5c-4c3a-96d6-8a7e5a38a8b8 -version: 2 -date: '2024-05-20' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -53,11 +53,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_curl_upload_file.yml b/detections/endpoint/linux_curl_upload_file.yml index 108708e413..0ace0a70ea 100644 --- a/detections/endpoint/linux_curl_upload_file.yml +++ b/detections/endpoint/linux_curl_upload_file.yml @@ -1,7 +1,7 @@ name: Linux Curl Upload File id: c1de2d9a-0c02-4bb4-a49a-510c6e9cf2bf -version: 2 -date: '2024-05-28' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -63,7 +63,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_decode_base64_to_shell.yml b/detections/endpoint/linux_decode_base64_to_shell.yml index 6a9f2be9a7..1bacea6b8c 100644 --- a/detections/endpoint/linux_decode_base64_to_shell.yml +++ b/detections/endpoint/linux_decode_base64_to_shell.yml @@ -1,7 +1,7 @@ name: Linux Decode Base64 to Shell id: 637b603e-1799-40fd-bf87-47ecbd551b66 -version: 3 -date: '2024-06-25' +version: 4 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -53,11 +53,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_docker_privilege_escalation.yml b/detections/endpoint/linux_docker_privilege_escalation.yml index e0ff97e473..62b6368e66 100644 --- a/detections/endpoint/linux_docker_privilege_escalation.yml +++ b/detections/endpoint/linux_docker_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Docker Privilege Escalation id: 2e7bfb78-85f6-47b5-bc2f-15813a4ef2b3 -version: 2 -date: '2024-05-24' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -54,11 +54,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_emacs_privilege_escalation.yml b/detections/endpoint/linux_emacs_privilege_escalation.yml index 80663bbd03..526bdbbba8 100644 --- a/detections/endpoint/linux_emacs_privilege_escalation.yml +++ b/detections/endpoint/linux_emacs_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Emacs Privilege Escalation id: 92033cab-1871-483d-a03b-a7ce98665cfc -version: 2 -date: '2024-05-24' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -54,11 +54,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_find_privilege_escalation.yml b/detections/endpoint/linux_find_privilege_escalation.yml index 337e22a5a1..8520191741 100644 --- a/detections/endpoint/linux_find_privilege_escalation.yml +++ b/detections/endpoint/linux_find_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Find Privilege Escalation id: 2ff4e0c2-8256-4143-9c07-1e39c7231111 -version: 2 -date: '2024-05-28' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -55,11 +55,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_gdb_privilege_escalation.yml b/detections/endpoint/linux_gdb_privilege_escalation.yml index a4d996349f..bcbb89d7bf 100644 --- a/detections/endpoint/linux_gdb_privilege_escalation.yml +++ b/detections/endpoint/linux_gdb_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux GDB Privilege Escalation id: 310b7da2-ab52-437f-b1bf-0bd458674308 -version: 2 -date: '2024-05-16' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -53,11 +53,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_gem_privilege_escalation.yml b/detections/endpoint/linux_gem_privilege_escalation.yml index 8b642f2b9a..dbf9ac3d32 100644 --- a/detections/endpoint/linux_gem_privilege_escalation.yml +++ b/detections/endpoint/linux_gem_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Gem Privilege Escalation id: 0115482a-5dcb-4bb0-bcca-5d095d224236 -version: 2 -date: '2024-05-24' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -54,11 +54,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_gnu_awk_privilege_escalation.yml b/detections/endpoint/linux_gnu_awk_privilege_escalation.yml index 739707132d..62d55ecc65 100644 --- a/detections/endpoint/linux_gnu_awk_privilege_escalation.yml +++ b/detections/endpoint/linux_gnu_awk_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux GNU Awk Privilege Escalation id: 0dcf43b9-50d8-42a6-acd9-d1c9201fe6ae -version: 2 -date: '2024-05-16' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -53,11 +53,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_ingress_tool_transfer_hunting.yml b/detections/endpoint/linux_ingress_tool_transfer_hunting.yml index 207c64c6cd..2ee962a3c8 100644 --- a/detections/endpoint/linux_ingress_tool_transfer_hunting.yml +++ b/detections/endpoint/linux_ingress_tool_transfer_hunting.yml @@ -1,7 +1,7 @@ name: Linux Ingress Tool Transfer Hunting id: 52fd468b-cb6d-48f5-b16a-92f1c9bb10cf -version: 2 -date: '2024-05-10' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Hunting @@ -60,7 +60,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_ingress_tool_transfer_with_curl.yml b/detections/endpoint/linux_ingress_tool_transfer_with_curl.yml index c0c2a18a16..9403068447 100644 --- a/detections/endpoint/linux_ingress_tool_transfer_with_curl.yml +++ b/detections/endpoint/linux_ingress_tool_transfer_with_curl.yml @@ -1,7 +1,7 @@ name: Linux Ingress Tool Transfer with Curl id: 8c1de57d-abc1-4b41-a727-a7a8fc5e0857 -version: 2 -date: '2024-05-23' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Anomaly @@ -59,7 +59,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_java_spawning_shell.yml b/detections/endpoint/linux_java_spawning_shell.yml index 991d68fae9..6aacf7ab9e 100644 --- a/detections/endpoint/linux_java_spawning_shell.yml +++ b/detections/endpoint/linux_java_spawning_shell.yml @@ -1,7 +1,7 @@ name: Linux Java Spawning Shell id: 7b09db8a-5c20-11ec-9945-acde48001122 -version: 2 -date: '2024-05-13' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -59,11 +59,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_kernel_module_enumeration.yml b/detections/endpoint/linux_kernel_module_enumeration.yml index 9716b729ca..5491a9a081 100644 --- a/detections/endpoint/linux_kernel_module_enumeration.yml +++ b/detections/endpoint/linux_kernel_module_enumeration.yml @@ -1,7 +1,7 @@ name: Linux Kernel Module Enumeration id: 6df99886-0e04-4c11-8b88-325747419278 -version: 2 -date: '2024-05-15' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Anomaly @@ -56,11 +56,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_make_privilege_escalation.yml b/detections/endpoint/linux_make_privilege_escalation.yml index 45512b41a9..3b2489e761 100644 --- a/detections/endpoint/linux_make_privilege_escalation.yml +++ b/detections/endpoint/linux_make_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Make Privilege Escalation id: 80b22836-5091-4944-80ee-f733ac443f4f -version: 2 -date: '2024-05-12' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -53,11 +53,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_mysql_privilege_escalation.yml b/detections/endpoint/linux_mysql_privilege_escalation.yml index 5d3a2ddc22..8534760d6b 100644 --- a/detections/endpoint/linux_mysql_privilege_escalation.yml +++ b/detections/endpoint/linux_mysql_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux MySQL Privilege Escalation id: c0d810f4-230c-44ea-b703-989da02ff145 -version: 2 -date: '2024-05-17' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -54,11 +54,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_ngrok_reverse_proxy_usage.yml b/detections/endpoint/linux_ngrok_reverse_proxy_usage.yml index 0f435fca52..4fccf989cf 100644 --- a/detections/endpoint/linux_ngrok_reverse_proxy_usage.yml +++ b/detections/endpoint/linux_ngrok_reverse_proxy_usage.yml @@ -1,7 +1,7 @@ name: Linux Ngrok Reverse Proxy Usage id: bc84d574-708c-467d-b78a-4c1e20171f97 -version: 2 -date: '2024-05-28' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Anomaly @@ -59,11 +59,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_node_privilege_escalation.yml b/detections/endpoint/linux_node_privilege_escalation.yml index 6b7f465551..611f5d8740 100644 --- a/detections/endpoint/linux_node_privilege_escalation.yml +++ b/detections/endpoint/linux_node_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Node Privilege Escalation id: 2e58a4ff-398f-42f4-8fd0-e01ebfe2a8ce -version: 2 -date: '2024-05-29' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -56,11 +56,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml b/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml index a5757d1f28..89f4a9e397 100644 --- a/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml +++ b/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml @@ -1,7 +1,7 @@ name: Linux Obfuscated Files or Information Base64 Decode id: 303b38b2-c03f-44e2-8f41-4594606fcfc7 -version: 3 -date: '2024-06-25' +version: 4 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Anomaly @@ -55,11 +55,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_octave_privilege_escalation.yml b/detections/endpoint/linux_octave_privilege_escalation.yml index 91976f6e5f..22932b779b 100644 --- a/detections/endpoint/linux_octave_privilege_escalation.yml +++ b/detections/endpoint/linux_octave_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Octave Privilege Escalation id: 78f7487d-42ce-4f7f-8685-2159b25fb477 -version: 2 -date: '2024-05-18' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -55,11 +55,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_openvpn_privilege_escalation.yml b/detections/endpoint/linux_openvpn_privilege_escalation.yml index cf1aadc893..31b31ab770 100644 --- a/detections/endpoint/linux_openvpn_privilege_escalation.yml +++ b/detections/endpoint/linux_openvpn_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux OpenVPN Privilege Escalation id: d25feebe-fa1c-4754-8a1e-afb03bedc0f2 -version: 2 -date: '2024-05-15' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -55,11 +55,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_php_privilege_escalation.yml b/detections/endpoint/linux_php_privilege_escalation.yml index 3b41c80d4c..0baf905554 100644 --- a/detections/endpoint/linux_php_privilege_escalation.yml +++ b/detections/endpoint/linux_php_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux PHP Privilege Escalation id: 4fc4c031-e5be-4cc0-8cf9-49f9f507bcb5 -version: 2 -date: '2024-05-19' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -54,11 +54,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_pkexec_privilege_escalation.yml b/detections/endpoint/linux_pkexec_privilege_escalation.yml index 118b7f8937..72b1f908d6 100644 --- a/detections/endpoint/linux_pkexec_privilege_escalation.yml +++ b/detections/endpoint/linux_pkexec_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux pkexec Privilege Escalation id: 03e22c1c-8086-11ec-ac2e-acde48001122 -version: 2 -date: '2024-05-27' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -61,11 +61,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_proxy_socks_curl.yml b/detections/endpoint/linux_proxy_socks_curl.yml index 00d9d54891..8f2f949595 100644 --- a/detections/endpoint/linux_proxy_socks_curl.yml +++ b/detections/endpoint/linux_proxy_socks_curl.yml @@ -1,7 +1,7 @@ name: Linux Proxy Socks Curl id: bd596c22-ad1e-44fc-b242-817253ce8b08 -version: 2 -date: '2024-05-19' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -64,7 +64,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_puppet_privilege_escalation.yml b/detections/endpoint/linux_puppet_privilege_escalation.yml index fc160989a9..7dded91053 100644 --- a/detections/endpoint/linux_puppet_privilege_escalation.yml +++ b/detections/endpoint/linux_puppet_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Puppet Privilege Escalation id: 1d19037f-466e-4d56-8d87-36fafd9aa3ce -version: 2 -date: '2024-05-17' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -55,11 +55,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_rpm_privilege_escalation.yml b/detections/endpoint/linux_rpm_privilege_escalation.yml index 69c6e106e7..e005b053c8 100644 --- a/detections/endpoint/linux_rpm_privilege_escalation.yml +++ b/detections/endpoint/linux_rpm_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux RPM Privilege Escalation id: f8e58a23-cecd-495f-9c65-6c76b4cb9774 -version: 2 -date: '2024-05-21' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -55,11 +55,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_ruby_privilege_escalation.yml b/detections/endpoint/linux_ruby_privilege_escalation.yml index a4ebe6d2ad..1e6029b481 100644 --- a/detections/endpoint/linux_ruby_privilege_escalation.yml +++ b/detections/endpoint/linux_ruby_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Ruby Privilege Escalation id: 097b28b5-7004-4d40-a715-7e390501788b -version: 2 -date: '2024-05-25' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -53,11 +53,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_sqlite3_privilege_escalation.yml b/detections/endpoint/linux_sqlite3_privilege_escalation.yml index 24fd1e2fed..cba1176f0a 100644 --- a/detections/endpoint/linux_sqlite3_privilege_escalation.yml +++ b/detections/endpoint/linux_sqlite3_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Sqlite3 Privilege Escalation id: ab75dbb7-c3ba-4689-9c1b-8d2717bdcba1 -version: 2 -date: '2024-05-13' +version: 3 +date: '2024-08-14' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -54,11 +54,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_ssh_authorized_keys_modification.yml b/detections/endpoint/linux_ssh_authorized_keys_modification.yml index 2caccf2eb4..4279e16534 100644 --- a/detections/endpoint/linux_ssh_authorized_keys_modification.yml +++ b/detections/endpoint/linux_ssh_authorized_keys_modification.yml @@ -1,7 +1,7 @@ name: Linux SSH Authorized Keys Modification id: f5ab595e-28e5-4327-8077-5008ba97c850 -version: 2 -date: '2024-05-12' +version: 3 +date: '2024-08-16' author: Michael Haag, Splunk status: production type: Anomaly @@ -57,11 +57,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_ssh_remote_services_script_execute.yml b/detections/endpoint/linux_ssh_remote_services_script_execute.yml index 9e13bd446e..842b3c1fc8 100644 --- a/detections/endpoint/linux_ssh_remote_services_script_execute.yml +++ b/detections/endpoint/linux_ssh_remote_services_script_execute.yml @@ -1,7 +1,7 @@ name: Linux SSH Remote Services Script Execute id: aa1748dd-4a5c-457a-9cf6-ca7b4eb711b3 -version: 2 -date: '2024-05-13' +version: 3 +date: '2024-08-16' author: Michael Haag, Splunk status: production type: TTP @@ -56,7 +56,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/malicious_inprocserver32_modification.yml b/detections/endpoint/malicious_inprocserver32_modification.yml index 4ebe25fee1..f5585eb2ae 100644 --- a/detections/endpoint/malicious_inprocserver32_modification.yml +++ b/detections/endpoint/malicious_inprocserver32_modification.yml @@ -1,7 +1,7 @@ name: Malicious InProcServer32 Modification id: 127c8d08-25ff-11ec-9223-acde48001122 -version: 2 -date: '2024-05-30' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -63,7 +63,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/mimikatz_passtheticket_commandline_parameters.yml b/detections/endpoint/mimikatz_passtheticket_commandline_parameters.yml index 2b34a30818..22b4bbc9a1 100644 --- a/detections/endpoint/mimikatz_passtheticket_commandline_parameters.yml +++ b/detections/endpoint/mimikatz_passtheticket_commandline_parameters.yml @@ -1,7 +1,7 @@ name: Mimikatz PassTheTicket CommandLine Parameters id: 13bbd574-83ac-11ec-99d4-acde48001122 -version: 2 -date: '2024-05-30' +version: 3 +date: '2024-08-15' author: Mauricio Velazco, Splunk status: production type: TTP @@ -63,7 +63,7 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/msi_module_loaded_by_non_system_binary.yml b/detections/endpoint/msi_module_loaded_by_non_system_binary.yml index 9e694af832..83fec4ebc4 100644 --- a/detections/endpoint/msi_module_loaded_by_non_system_binary.yml +++ b/detections/endpoint/msi_module_loaded_by_non_system_binary.yml @@ -1,7 +1,7 @@ name: MSI Module Loaded by Non-System Binary id: ccb98a66-5851-11ec-b91c-acde48001122 -version: 2 -date: '2024-05-29' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Hunting @@ -43,10 +43,14 @@ tags: - T1574.002 - T1574 observable: + - name: dest + type: Hostname + role: + - Victim - name: process_name type: Process Name role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/notepad_with_no_command_line_arguments.yml b/detections/endpoint/notepad_with_no_command_line_arguments.yml index 25f31f4117..cd4bda96bc 100644 --- a/detections/endpoint/notepad_with_no_command_line_arguments.yml +++ b/detections/endpoint/notepad_with_no_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Notepad with no Command Line Arguments id: 5adbc5f1-9a2f-41c1-a810-f37e015f8179 -version: 2 -date: '2024-05-18' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk type: TTP status: production @@ -56,11 +56,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/office_product_spawning_windows_script_host.yml b/detections/endpoint/office_product_spawning_windows_script_host.yml index 0ac2621443..4da6dc2d1f 100644 --- a/detections/endpoint/office_product_spawning_windows_script_host.yml +++ b/detections/endpoint/office_product_spawning_windows_script_host.yml @@ -1,7 +1,7 @@ name: Office Product Spawning Windows Script Host id: b3628a5b-8d02-42fa-a891-eebf2351cbe1 -version: 6 -date: '2024-05-17' +version: 7 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -60,11 +60,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/office_product_writing_cab_or_inf.yml b/detections/endpoint/office_product_writing_cab_or_inf.yml index ca2b9bca25..0615efc972 100644 --- a/detections/endpoint/office_product_writing_cab_or_inf.yml +++ b/detections/endpoint/office_product_writing_cab_or_inf.yml @@ -1,7 +1,7 @@ name: Office Product Writing cab or inf id: f48cd1d4-125a-11ec-a447-acde48001122 -version: 5 -date: '2024-05-27' +version: 6 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -64,7 +64,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/office_spawning_control.yml b/detections/endpoint/office_spawning_control.yml index 4c426962fa..4e0e9e35d7 100644 --- a/detections/endpoint/office_spawning_control.yml +++ b/detections/endpoint/office_spawning_control.yml @@ -1,7 +1,7 @@ name: Office Spawning Control id: 053e027c-10c7-11ec-8437-acde48001122 -version: 5 -date: '2024-05-11' +version: 6 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -64,11 +64,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/password_policy_discovery_with_net.yml b/detections/endpoint/password_policy_discovery_with_net.yml index 6b697a7d73..fee7a23d00 100644 --- a/detections/endpoint/password_policy_discovery_with_net.yml +++ b/detections/endpoint/password_policy_discovery_with_net.yml @@ -1,7 +1,7 @@ name: Password Policy Discovery with Net id: 09336538-065a-11ec-8665-acde48001122 -version: 2 -date: '2024-05-19' +version: 3 +date: '2024-08-15' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: Hunting @@ -58,7 +58,7 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/process_writing_dynamicwrapperx.yml b/detections/endpoint/process_writing_dynamicwrapperx.yml index ba6276e497..67f8b817d5 100644 --- a/detections/endpoint/process_writing_dynamicwrapperx.yml +++ b/detections/endpoint/process_writing_dynamicwrapperx.yml @@ -1,7 +1,7 @@ name: Process Writing DynamicWrapperX id: b0a078e4-2601-11ec-9aec-acde48001122 -version: 2 -date: '2024-05-21' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: Hunting @@ -64,7 +64,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/processes_tapping_keyboard_events.yml b/detections/endpoint/processes_tapping_keyboard_events.yml index 78f429cedd..99652a9203 100644 --- a/detections/endpoint/processes_tapping_keyboard_events.yml +++ b/detections/endpoint/processes_tapping_keyboard_events.yml @@ -1,7 +1,7 @@ name: Processes Tapping Keyboard Events id: 2a371608-331d-4034-ae2c-21dda8f1d0ec -version: 2 -date: '2024-05-13' +version: 3 +date: '2024-08-14' author: Jose Hernandez, Splunk status: experimental type: TTP @@ -39,7 +39,7 @@ tags: - name: dest type: Other role: - - Other + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/randomly_generated_windows_service_name.yml b/detections/endpoint/randomly_generated_windows_service_name.yml index 24a5d97d46..386eae5efc 100644 --- a/detections/endpoint/randomly_generated_windows_service_name.yml +++ b/detections/endpoint/randomly_generated_windows_service_name.yml @@ -1,7 +1,7 @@ name: Randomly Generated Windows Service Name id: 2032a95a-5165-11ec-a2c3-3e22fbd008af -version: 2 -date: '2024-05-30' +version: 3 +date: '2024-08-19' author: Mauricio Velazco, Splunk status: experimental type: Hunting @@ -35,10 +35,6 @@ tags: - T1543 - T1543.003 observable: - - name: Service_File_Name - type: Other - role: - - Other - name: ComputerName type: Endpoint role: diff --git a/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml b/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml index 818f60890d..ce1d72e2d6 100644 --- a/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml +++ b/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml @@ -1,7 +1,7 @@ name: Regsvr32 Silent and Install Param Dll Loading id: f421c250-24e7-11ec-bc43-acde48001122 -version: 2 -date: '2024-05-29' +version: 3 +date: '2024-08-15' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -65,11 +65,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml b/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml index ef55514830..494b6839b9 100644 --- a/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml +++ b/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml @@ -1,7 +1,7 @@ name: Regsvr32 with Known Silent Switch Cmdline id: c9ef7dc4-eeaf-11eb-b2b6-acde48001122 -version: 3 -date: '2024-05-11' +version: 4 +date: '2024-08-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -65,11 +65,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/rubeus_command_line_parameters.yml b/detections/endpoint/rubeus_command_line_parameters.yml index 24bb8f5c65..73c9ac3726 100644 --- a/detections/endpoint/rubeus_command_line_parameters.yml +++ b/detections/endpoint/rubeus_command_line_parameters.yml @@ -1,7 +1,7 @@ name: Rubeus Command Line Parameters id: cca37478-8377-11ec-b59a-acde48001122 -version: 2 -date: '2024-05-14' +version: 3 +date: '2024-08-15' author: Mauricio Velazco, Splunk status: production type: TTP @@ -71,7 +71,7 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access.yml b/detections/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access.yml index 4b8c89fca1..9f2a73434f 100644 --- a/detections/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access.yml +++ b/detections/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access.yml @@ -1,7 +1,7 @@ name: Rubeus Kerberos Ticket Exports Through Winlogon Access id: 5ed8c50a-8869-11ec-876f-acde48001122 -version: 2 -date: '2024-05-27' +version: 3 +date: '2024-08-14' author: Mauricio Velazco, Splunk status: production type: TTP @@ -52,7 +52,7 @@ tags: - name: TargetImage type: Process role: - - Target + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/rundll32_control_rundll_hunt.yml b/detections/endpoint/rundll32_control_rundll_hunt.yml index 2415080e37..d5b4d68298 100644 --- a/detections/endpoint/rundll32_control_rundll_hunt.yml +++ b/detections/endpoint/rundll32_control_rundll_hunt.yml @@ -1,7 +1,7 @@ name: Rundll32 Control RunDLL Hunt id: c8e7ced0-10c5-11ec-8b03-acde48001122 -version: 2 -date: '2024-05-23' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Hunting @@ -68,11 +68,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml b/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml index 951b4f5ea3..10726ecac2 100644 --- a/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml +++ b/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml @@ -1,7 +1,7 @@ name: Rundll32 Control RunDLL World Writable Directory id: 1adffe86-10c3-11ec-8ce6-acde48001122 -version: 2 -date: '2024-05-28' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -69,11 +69,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml index 9e3e1f57cd..3c4010fe40 100644 --- a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml +++ b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml @@ -1,7 +1,7 @@ name: Schtasks scheduling job on remote system id: 1297fb80-f42a-4b4a-9c8a-88c066237cf6 -version: 7 -date: '2024-05-14' +version: 8 +date: '2024-08-14' author: David Dorsey, Mauricio Velazco, Splunk status: production type: TTP @@ -65,7 +65,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml b/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml index 780b947022..f69973f58e 100644 --- a/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml +++ b/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml @@ -1,7 +1,7 @@ name: ServicePrincipalNames Discovery with SetSPN id: ae8b3efc-2d2e-11ec-8b57-acde48001122 -version: 2 -date: '2024-05-13' +version: 3 +date: '2024-08-19' author: Michael Haag, Splunk status: production type: TTP @@ -68,11 +68,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml index 3b96b3f5bd..1fed0f08be 100644 --- a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml +++ b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml @@ -1,7 +1,7 @@ name: Set Default PowerShell Execution Policy To Unrestricted or Bypass id: c2590137-0b08-4985-9ec5-6ae23d92f63d -version: 9 -date: '2024-05-12' +version: 10 +date: '2024-08-14' author: Steven Dick, Patrick Bareiss, Splunk status: production type: TTP @@ -67,9 +67,9 @@ tags: role: - Victim - name: registry_path - type: Unknown + type: Other role: - - Other + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/shim_database_file_creation.yml b/detections/endpoint/shim_database_file_creation.yml index 737398ef05..b9507ba4ae 100644 --- a/detections/endpoint/shim_database_file_creation.yml +++ b/detections/endpoint/shim_database_file_creation.yml @@ -1,7 +1,7 @@ name: Shim Database File Creation id: 6e4c4588-ba2f-42fa-97e6-9f6f548eaa33 -version: 4 -date: '2024-05-19' +version: 5 +date: '2024-08-14' author: David Dorsey, Splunk status: production type: TTP @@ -45,7 +45,7 @@ tags: - name: file_path type: File role: - - Other + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/spoolsv_suspicious_process_access.yml b/detections/endpoint/spoolsv_suspicious_process_access.yml index 5321e878ab..bed8fff9a4 100644 --- a/detections/endpoint/spoolsv_suspicious_process_access.yml +++ b/detections/endpoint/spoolsv_suspicious_process_access.yml @@ -1,7 +1,7 @@ name: Spoolsv Suspicious Process Access id: 799b606e-da81-11eb-93f8-acde48001122 -version: 2 -date: '2024-05-16' +version: 3 +date: '2024-08-14' author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk status: production type: TTP @@ -50,11 +50,11 @@ tags: - name: ProcessID type: Process role: - - Parent Process + - Attacker - name: TargetImage type: Process Name role: - - Target + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_plistbuddy_usage_via_osquery.yml b/detections/endpoint/suspicious_plistbuddy_usage_via_osquery.yml index abeb9ae75c..8fdbbf11ed 100644 --- a/detections/endpoint/suspicious_plistbuddy_usage_via_osquery.yml +++ b/detections/endpoint/suspicious_plistbuddy_usage_via_osquery.yml @@ -1,7 +1,7 @@ name: Suspicious PlistBuddy Usage via OSquery id: 20ba6c32-c733-4a32-b64e-2688cf231399 -version: 2 -date: '2024-05-22' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: experimental type: TTP @@ -36,9 +36,9 @@ tags: - T1543 observable: - name: dest - type: Other + type: Hostname role: - - Other + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_reg_exe_process.yml b/detections/endpoint/suspicious_reg_exe_process.yml index 6cfea57cca..f93da73ead 100644 --- a/detections/endpoint/suspicious_reg_exe_process.yml +++ b/detections/endpoint/suspicious_reg_exe_process.yml @@ -1,7 +1,7 @@ name: Suspicious Reg exe Process id: a6b3ab4e-dd77-4213-95fa-fc94701995e0 -version: 5 -date: '2024-05-19' +version: 6 +date: '2024-08-15' author: David Dorsey, Splunk status: production type: Anomaly @@ -66,11 +66,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml index 100fc1b120..97f7dd0d06 100644 --- a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml +++ b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml @@ -1,7 +1,7 @@ name: Suspicious Regsvr32 Register Suspicious Path id: 62732736-6250-11eb-ae93-0242ac130002 -version: 4 -date: '2024-05-29' +version: 5 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -68,11 +68,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml index 7ac0a8e5db..032ddb8847 100644 --- a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml +++ b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml @@ -1,7 +1,7 @@ name: Suspicious Rundll32 dllregisterserver id: 8c00a385-9b86-4ac0-8932-c9ec3713b159 -version: 3 -date: '2024-05-20' +version: 4 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -67,11 +67,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/uac_bypass_with_colorui_com_object.yml b/detections/endpoint/uac_bypass_with_colorui_com_object.yml index f40dff0bff..4969619c08 100644 --- a/detections/endpoint/uac_bypass_with_colorui_com_object.yml +++ b/detections/endpoint/uac_bypass_with_colorui_com_object.yml @@ -1,7 +1,7 @@ name: UAC Bypass With Colorui COM Object id: 2bcccd20-fc2b-11eb-8d22-acde48001122 -version: 2 -date: '2024-05-13' +version: 3 +date: '2024-08-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -46,7 +46,7 @@ tags: - name: ImageLoaded type: Other role: - - Other + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/wget_download_and_bash_execution.yml b/detections/endpoint/wget_download_and_bash_execution.yml index cc8783ec62..5205985b00 100644 --- a/detections/endpoint/wget_download_and_bash_execution.yml +++ b/detections/endpoint/wget_download_and_bash_execution.yml @@ -1,7 +1,7 @@ name: Wget Download and Bash Execution id: 35682718-5a85-11ec-b8f7-acde48001122 -version: 2 -date: '2024-05-12' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -63,7 +63,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_access_token_manipulation_winlogon_duplicate_token_handle.yml b/detections/endpoint/windows_access_token_manipulation_winlogon_duplicate_token_handle.yml index 3379233382..08d32a3110 100644 --- a/detections/endpoint/windows_access_token_manipulation_winlogon_duplicate_token_handle.yml +++ b/detections/endpoint/windows_access_token_manipulation_winlogon_duplicate_token_handle.yml @@ -1,7 +1,7 @@ name: Windows Access Token Manipulation Winlogon Duplicate Token Handle id: dda126d7-1d99-4f0b-b72a-4c14031f9398 -version: 2 -date: '2024-05-22' +version: 3 +date: '2024-08-15' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -48,7 +48,7 @@ tags: - name: SourceImage type: Process Name role: - - Parent Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_access_token_winlogon_duplicate_handle_in_uncommon_path.yml b/detections/endpoint/windows_access_token_winlogon_duplicate_handle_in_uncommon_path.yml index cc92288e72..3530133e93 100644 --- a/detections/endpoint/windows_access_token_winlogon_duplicate_handle_in_uncommon_path.yml +++ b/detections/endpoint/windows_access_token_winlogon_duplicate_handle_in_uncommon_path.yml @@ -1,7 +1,7 @@ name: Windows Access Token Winlogon Duplicate Handle In Uncommon Path id: b8f7ed6b-0556-4c84-bffd-839c262b0278 -version: 2 -date: '2024-05-27' +version: 3 +date: '2024-08-15' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -49,7 +49,7 @@ tags: - name: SourceImage type: Process Name role: - - Parent Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_apache_benchmark_binary.yml b/detections/endpoint/windows_apache_benchmark_binary.yml index 99ff92162d..319ee15262 100644 --- a/detections/endpoint/windows_apache_benchmark_binary.yml +++ b/detections/endpoint/windows_apache_benchmark_binary.yml @@ -1,7 +1,7 @@ name: Windows Apache Benchmark Binary id: 894f48ea-8d85-4dcd-9132-c66cdb407c9b -version: 2 -date: '2024-05-17' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Anomaly @@ -58,11 +58,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_autoit3_execution.yml b/detections/endpoint/windows_autoit3_execution.yml index 1dd127cc6e..a4f67fc31b 100644 --- a/detections/endpoint/windows_autoit3_execution.yml +++ b/detections/endpoint/windows_autoit3_execution.yml @@ -1,7 +1,7 @@ name: Windows AutoIt3 Execution id: 0ecb40d9-492b-4a57-9f87-515dd742794c -version: 2 -date: '2024-05-28' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -52,11 +52,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker - name: dest type: Hostname role: @@ -64,7 +64,7 @@ tags: - name: user type: User role: - - Other + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml b/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml index 2c897efca7..8c47e4ee19 100644 --- a/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml +++ b/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml @@ -1,7 +1,7 @@ name: Windows Binary Proxy Execution Mavinject DLL Injection id: ccf4b61b-1b26-4f2e-a089-f2009c569c57 -version: 2 -date: '2024-05-29' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -61,11 +61,11 @@ tags: - name: parent_process_name type: Process Name role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml b/detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml index 55eaacf00d..0fda311f6a 100644 --- a/detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml +++ b/detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml @@ -1,7 +1,7 @@ name: Windows COM Hijacking InprocServer32 Modification id: b7bd83c0-92b5-4fc7-b286-23eccfa2c561 -version: 2 -date: '2024-05-18' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -60,11 +60,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_credential_dumping_lsass_memory_createdump.yml b/detections/endpoint/windows_credential_dumping_lsass_memory_createdump.yml index fe68d9e5c1..e4d6f40cb9 100644 --- a/detections/endpoint/windows_credential_dumping_lsass_memory_createdump.yml +++ b/detections/endpoint/windows_credential_dumping_lsass_memory_createdump.yml @@ -1,7 +1,7 @@ name: Windows Credential Dumping LSASS Memory Createdump id: b3b7ce35-fce5-4c73-85f4-700aeada81a9 -version: 2 -date: '2024-05-26' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -59,11 +59,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_curl_download_to_suspicious_path.yml b/detections/endpoint/windows_curl_download_to_suspicious_path.yml index 9665d8ddb2..141b071dd4 100644 --- a/detections/endpoint/windows_curl_download_to_suspicious_path.yml +++ b/detections/endpoint/windows_curl_download_to_suspicious_path.yml @@ -1,7 +1,7 @@ name: Windows Curl Download to Suspicious Path id: c32f091e-30db-11ec-8738-acde48001122 -version: 2 -date: '2024-05-18' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -63,11 +63,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_curl_upload_to_remote_destination.yml b/detections/endpoint/windows_curl_upload_to_remote_destination.yml index beba138a0c..7f7b3d7d16 100644 --- a/detections/endpoint/windows_curl_upload_to_remote_destination.yml +++ b/detections/endpoint/windows_curl_upload_to_remote_destination.yml @@ -1,7 +1,7 @@ name: Windows Curl Upload to Remote Destination id: 42f8f1a2-4228-11ec-aade-acde48001122 -version: 2 -date: '2024-05-20' +version: 3 +date: '2024-08-16' author: Michael Haag, Splunk status: production type: TTP @@ -59,11 +59,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_default_group_policy_object_modified_with_gpme.yml b/detections/endpoint/windows_default_group_policy_object_modified_with_gpme.yml index 9fced33409..e97b09e011 100644 --- a/detections/endpoint/windows_default_group_policy_object_modified_with_gpme.yml +++ b/detections/endpoint/windows_default_group_policy_object_modified_with_gpme.yml @@ -1,7 +1,7 @@ name: Windows Default Group Policy Object Modified with GPME id: eaf688b3-bb8f-454d-b105-920a862cd8cb -version: 2 -date: '2024-05-24' +version: 3 +date: '2024-08-19' author: Mauricio Velazco, Splunk status: production type: TTP @@ -61,11 +61,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_defender_asr_audit_events.yml b/detections/endpoint/windows_defender_asr_audit_events.yml index ea86b39227..5548f7f00e 100644 --- a/detections/endpoint/windows_defender_asr_audit_events.yml +++ b/detections/endpoint/windows_defender_asr_audit_events.yml @@ -34,10 +34,6 @@ tags: - T1566.001 - T1566.002 observable: - - name: ASR_Rule - type: Unknown - role: - - Other - name: dest type: Endpoint role: diff --git a/detections/endpoint/windows_defender_asr_block_events.yml b/detections/endpoint/windows_defender_asr_block_events.yml index 7fefbb6800..9705f2c5af 100644 --- a/detections/endpoint/windows_defender_asr_block_events.yml +++ b/detections/endpoint/windows_defender_asr_block_events.yml @@ -1,7 +1,7 @@ name: Windows Defender ASR Block Events id: 026f5f4e-e99f-4155-9e63-911ba587300b -version: 2 -date: '2024-05-13' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: Anomaly @@ -37,7 +37,7 @@ tags: - name: ASR_Rule type: Unknown role: - - Other + - Attacker - name: dest type: Endpoint role: diff --git a/detections/endpoint/windows_defender_asr_registry_modification.yml b/detections/endpoint/windows_defender_asr_registry_modification.yml index b354f2a3a5..0b8c3221d8 100644 --- a/detections/endpoint/windows_defender_asr_registry_modification.yml +++ b/detections/endpoint/windows_defender_asr_registry_modification.yml @@ -1,7 +1,7 @@ name: Windows Defender ASR Registry Modification id: 6a1b6cbe-6612-44c3-92b9-1a1bd77412eb -version: 2 -date: '2024-05-26' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Hunting @@ -47,10 +47,6 @@ tags: mitre_attack_id: - T1112 observable: - - name: ASR_Rule - type: Unknown - role: - - Other - name: dest type: Endpoint role: diff --git a/detections/endpoint/windows_defender_asr_rule_disabled.yml b/detections/endpoint/windows_defender_asr_rule_disabled.yml index 04693b4cf6..0668079d54 100644 --- a/detections/endpoint/windows_defender_asr_rule_disabled.yml +++ b/detections/endpoint/windows_defender_asr_rule_disabled.yml @@ -1,7 +1,7 @@ name: Windows Defender ASR Rule Disabled id: 429d611b-3183-49a7-b235-fc4203c4e1cb -version: 2 -date: '2024-05-16' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -36,7 +36,7 @@ tags: - name: ASR_Rule type: Unknown role: - - Other + - Attacker - name: dest type: Endpoint role: diff --git a/detections/endpoint/windows_defender_asr_rules_stacking.yml b/detections/endpoint/windows_defender_asr_rules_stacking.yml index 9ef8f5ab7b..0ae518c4a0 100644 --- a/detections/endpoint/windows_defender_asr_rules_stacking.yml +++ b/detections/endpoint/windows_defender_asr_rules_stacking.yml @@ -1,7 +1,7 @@ name: Windows Defender ASR Rules Stacking id: 425a6657-c5e4-4cbb-909e-fc9e5d326f01 -version: 2 -date: '2024-05-21' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: Hunting @@ -61,7 +61,7 @@ tags: - name: ASR_Rule type: Unknown role: - - Other + - Attacker - name: dest type: Endpoint role: diff --git a/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml b/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml index e35d798836..daf4791997 100644 --- a/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml +++ b/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml @@ -1,7 +1,7 @@ name: Windows Disable or Modify Tools Via Taskkill id: a43ae66f-c410-4b3d-8741-9ce1ad17ddb0 -version: 2 -date: '2024-05-28' +version: 3 +date: '2024-08-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -59,7 +59,6 @@ tags: - name: parent_process_name type: Process Name role: - - Parent Process - Attacker product: - Splunk Enterprise diff --git a/detections/endpoint/windows_disable_windows_event_logging_disable_http_logging.yml b/detections/endpoint/windows_disable_windows_event_logging_disable_http_logging.yml index 930e0fffb4..ed9b58057a 100644 --- a/detections/endpoint/windows_disable_windows_event_logging_disable_http_logging.yml +++ b/detections/endpoint/windows_disable_windows_event_logging_disable_http_logging.yml @@ -1,7 +1,7 @@ name: Windows Disable Windows Event Logging Disable HTTP Logging id: 23fb6787-255f-4d5b-9a66-9fd7504032b5 -version: 2 -date: '2024-05-12' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -67,11 +67,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_diskcryptor_usage.yml b/detections/endpoint/windows_diskcryptor_usage.yml index 0a2d6aae6f..dcadcdcc98 100644 --- a/detections/endpoint/windows_diskcryptor_usage.yml +++ b/detections/endpoint/windows_diskcryptor_usage.yml @@ -1,7 +1,7 @@ name: Windows DiskCryptor Usage id: d56fe0c8-4650-11ec-a8fa-acde48001122 -version: 2 -date: '2024-05-29' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: Hunting @@ -60,11 +60,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_dism_remove_defender.yml b/detections/endpoint/windows_dism_remove_defender.yml index 7a3bf4d484..758e250e73 100644 --- a/detections/endpoint/windows_dism_remove_defender.yml +++ b/detections/endpoint/windows_dism_remove_defender.yml @@ -1,7 +1,7 @@ name: Windows DISM Remove Defender id: 8567da9e-47f0-11ec-99a9-acde48001122 -version: 2 -date: '2024-05-17' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -61,11 +61,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_dll_search_order_hijacking_with_iscsicpl.yml b/detections/endpoint/windows_dll_search_order_hijacking_with_iscsicpl.yml index 1dde696bef..b226d17b6a 100644 --- a/detections/endpoint/windows_dll_search_order_hijacking_with_iscsicpl.yml +++ b/detections/endpoint/windows_dll_search_order_hijacking_with_iscsicpl.yml @@ -1,7 +1,7 @@ name: Windows DLL Search Order Hijacking with iscsicpl id: f39ee679-3b1e-4f47-841c-5c3c580acda2 -version: 2 -date: '2024-05-11' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -60,11 +60,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml b/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml index 20c4d31540..8907b999ea 100644 --- a/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml +++ b/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml @@ -1,7 +1,7 @@ name: Windows DotNet Binary in Non Standard Path id: fddf3b56-7933-11ec-98a6-acde48001122 -version: 2 -date: '2024-05-15' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -73,11 +73,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml b/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml index bbf533cf75..e974c464d9 100644 --- a/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml +++ b/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml @@ -1,7 +1,7 @@ name: Windows Execute Arbitrary Commands with MSDT id: e1d5145f-38fe-42b9-a5d5-457796715f97 -version: 4 -date: '2024-05-19' +version: 5 +date: '2024-08-15' author: Michael Haag, Teoderick Contreras, Splunk status: production type: TTP @@ -67,11 +67,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_hunting_system_account_targeting_lsass.yml b/detections/endpoint/windows_hunting_system_account_targeting_lsass.yml index 13c7c899e9..e5cc8a7df9 100644 --- a/detections/endpoint/windows_hunting_system_account_targeting_lsass.yml +++ b/detections/endpoint/windows_hunting_system_account_targeting_lsass.yml @@ -1,7 +1,7 @@ name: Windows Hunting System Account Targeting Lsass id: 1c6abb08-73d1-11ec-9ca0-acde48001122 -version: 2 -date: '2024-05-20' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Hunting @@ -51,7 +51,7 @@ tags: - name: SourceImage type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_identify_protocol_handlers.yml b/detections/endpoint/windows_identify_protocol_handlers.yml index da2eb4eb95..0d48f21a1b 100644 --- a/detections/endpoint/windows_identify_protocol_handlers.yml +++ b/detections/endpoint/windows_identify_protocol_handlers.yml @@ -1,7 +1,7 @@ name: Windows Identify Protocol Handlers id: bd5c311e-a6ea-48ae-a289-19a3398e3648 -version: 3 -date: '2024-05-26' +version: 4 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Hunting @@ -66,11 +66,11 @@ tags: - name: parent_process_name type: Process Name role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_iis_components_add_new_module.yml b/detections/endpoint/windows_iis_components_add_new_module.yml index 679feaf087..7821c6f36a 100644 --- a/detections/endpoint/windows_iis_components_add_new_module.yml +++ b/detections/endpoint/windows_iis_components_add_new_module.yml @@ -1,7 +1,7 @@ name: Windows IIS Components Add New Module id: 38fe731c-1f13-43d4-b878-a5bbe44807e3 -version: 2 -date: '2024-05-27' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Anomaly @@ -65,11 +65,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml b/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml index a860417c29..1a08e38d1d 100644 --- a/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml +++ b/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml @@ -1,7 +1,7 @@ name: Windows Ingress Tool Transfer Using Explorer id: 76753bab-f116-4ea3-8fb9-89b638be58a9 -version: 3 -date: '2024-05-18' +version: 4 +date: '2024-08-19' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -60,11 +60,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_installutil_in_non_standard_path.yml b/detections/endpoint/windows_installutil_in_non_standard_path.yml index 9e17deb2a9..a3df44896c 100644 --- a/detections/endpoint/windows_installutil_in_non_standard_path.yml +++ b/detections/endpoint/windows_installutil_in_non_standard_path.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil in Non Standard Path id: dcf74b22-7933-11ec-857c-acde48001122 -version: 2 -date: '2024-05-22' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -72,11 +72,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_installutil_remote_network_connection.yml b/detections/endpoint/windows_installutil_remote_network_connection.yml index 3e4ded5b5b..dd895a5ad7 100644 --- a/detections/endpoint/windows_installutil_remote_network_connection.yml +++ b/detections/endpoint/windows_installutil_remote_network_connection.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil Remote Network Connection id: 4fbf9270-43da-11ec-9486-acde48001122 -version: 4 -date: '2024-05-24' +version: 5 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -63,11 +63,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_installutil_uninstall_option.yml b/detections/endpoint/windows_installutil_uninstall_option.yml index 0a704ec3ec..c3ac1b0646 100644 --- a/detections/endpoint/windows_installutil_uninstall_option.yml +++ b/detections/endpoint/windows_installutil_uninstall_option.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil Uninstall Option id: cfa7b9ac-43f0-11ec-9b48-acde48001122 -version: 3 -date: '2024-05-14' +version: 4 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -64,11 +64,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_installutil_uninstall_option_with_network.yml b/detections/endpoint/windows_installutil_uninstall_option_with_network.yml index 98edc863e1..072ce865db 100644 --- a/detections/endpoint/windows_installutil_uninstall_option_with_network.yml +++ b/detections/endpoint/windows_installutil_uninstall_option_with_network.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil Uninstall Option with Network id: 1a52c836-43ef-11ec-a36c-acde48001122 -version: 3 -date: '2024-05-25' +version: 4 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -65,11 +65,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_installutil_url_in_command_line.yml b/detections/endpoint/windows_installutil_url_in_command_line.yml index 9f30dd1f26..23f88c226c 100644 --- a/detections/endpoint/windows_installutil_url_in_command_line.yml +++ b/detections/endpoint/windows_installutil_url_in_command_line.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil URL in Command Line id: 28e06670-43df-11ec-a569-acde48001122 -version: 2 -date: '2024-05-16' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -62,11 +62,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_java_spawning_shells.yml b/detections/endpoint/windows_java_spawning_shells.yml index 268a73b7d2..69b1f0160b 100644 --- a/detections/endpoint/windows_java_spawning_shells.yml +++ b/detections/endpoint/windows_java_spawning_shells.yml @@ -1,7 +1,7 @@ name: Windows Java Spawning Shells id: 28c81306-5c47-11ec-bfea-acde48001122 -version: 3 -date: '2024-05-11' +version: 4 +date: '2024-08-15' author: Michael Haag, Splunk status: experimental type: TTP @@ -63,11 +63,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_lateral_tool_transfer_remcom.yml b/detections/endpoint/windows_lateral_tool_transfer_remcom.yml index 196699eaeb..801d049f3d 100644 --- a/detections/endpoint/windows_lateral_tool_transfer_remcom.yml +++ b/detections/endpoint/windows_lateral_tool_transfer_remcom.yml @@ -1,7 +1,7 @@ name: Windows Lateral Tool Transfer RemCom id: e373a840-5bdc-47ef-b2fd-9cc7aaf387f0 -version: 2 -date: '2024-05-15' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk type: TTP status: production @@ -59,11 +59,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_ldifde_directory_object_behavior.yml b/detections/endpoint/windows_ldifde_directory_object_behavior.yml index 6e49a95030..ff581645d5 100644 --- a/detections/endpoint/windows_ldifde_directory_object_behavior.yml +++ b/detections/endpoint/windows_ldifde_directory_object_behavior.yml @@ -1,7 +1,7 @@ name: Windows Ldifde Directory Object Behavior id: 35cd29ca-f08c-4489-8815-f715c45460d3 -version: 2 -date: '2024-05-18' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -63,11 +63,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_mimikatz_binary_execution.yml b/detections/endpoint/windows_mimikatz_binary_execution.yml index 5eed6aaa66..12474f92ad 100644 --- a/detections/endpoint/windows_mimikatz_binary_execution.yml +++ b/detections/endpoint/windows_mimikatz_binary_execution.yml @@ -1,7 +1,7 @@ name: Windows Mimikatz Binary Execution id: a9e0d6d3-9676-4e26-994d-4e0406bb4467 -version: 2 -date: '2024-05-27' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -65,11 +65,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_mof_event_triggered_execution_via_wmi.yml b/detections/endpoint/windows_mof_event_triggered_execution_via_wmi.yml index 570b766e26..c8e0c16ff1 100644 --- a/detections/endpoint/windows_mof_event_triggered_execution_via_wmi.yml +++ b/detections/endpoint/windows_mof_event_triggered_execution_via_wmi.yml @@ -1,7 +1,7 @@ name: Windows MOF Event Triggered Execution via WMI id: e59b5a73-32bf-4467-a585-452c36ae10c1 -version: 3 -date: '2024-05-24' +version: 4 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -63,11 +63,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_msiexec_dllregisterserver.yml b/detections/endpoint/windows_msiexec_dllregisterserver.yml index 25d55657ca..8a08f701ef 100644 --- a/detections/endpoint/windows_msiexec_dllregisterserver.yml +++ b/detections/endpoint/windows_msiexec_dllregisterserver.yml @@ -1,7 +1,7 @@ name: Windows MSIExec DLLRegisterServer id: fdb59aef-d88f-4909-8369-ec2afbd2c398 -version: 2 -date: '2024-05-06' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -59,11 +59,11 @@ tags: - name: parent_process_name type: Process Name role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_msiexec_remote_download.yml b/detections/endpoint/windows_msiexec_remote_download.yml index 2b7f246cee..43d1b173e6 100644 --- a/detections/endpoint/windows_msiexec_remote_download.yml +++ b/detections/endpoint/windows_msiexec_remote_download.yml @@ -1,7 +1,7 @@ name: Windows MSIExec Remote Download id: 6aa49ff2-3c92-4586-83e0-d83eb693dfda -version: 2 -date: '2024-05-08' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -58,11 +58,11 @@ tags: - name: parent_process_name type: Process Name role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_msiexec_spawn_discovery_command.yml b/detections/endpoint/windows_msiexec_spawn_discovery_command.yml index 0367683bf1..e94f334bf6 100644 --- a/detections/endpoint/windows_msiexec_spawn_discovery_command.yml +++ b/detections/endpoint/windows_msiexec_spawn_discovery_command.yml @@ -1,7 +1,7 @@ name: Windows MSIExec Spawn Discovery Command id: e9d05aa2-32f0-411b-930c-5b8ca5c4fcee -version: 2 -date: '2024-05-18' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -61,11 +61,11 @@ tags: - name: parent_process_name type: Process Name role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_msiexec_spawn_windbg.yml b/detections/endpoint/windows_msiexec_spawn_windbg.yml index 1243cdbe4e..45e68c3f07 100644 --- a/detections/endpoint/windows_msiexec_spawn_windbg.yml +++ b/detections/endpoint/windows_msiexec_spawn_windbg.yml @@ -1,7 +1,7 @@ name: Windows MSIExec Spawn WinDBG id: 9a18f7c2-1fe3-47b8-9467-8b3976770a30 -version: 2 -date: '2024-05-28' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -59,11 +59,11 @@ tags: - name: parent_process_name type: Process Name role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml b/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml index 30e7efb7dd..f1f5bee19e 100644 --- a/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml +++ b/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml @@ -1,7 +1,7 @@ name: Windows MSIExec Unregister DLLRegisterServer id: a27db3c5-1a9a-46df-a577-765d3f1a3c24 -version: 2 -date: '2024-05-10' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -59,11 +59,11 @@ tags: - name: parent_process_name type: Process Name role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_msiexec_with_network_connections.yml b/detections/endpoint/windows_msiexec_with_network_connections.yml index fde323dc9b..2163fc7787 100644 --- a/detections/endpoint/windows_msiexec_with_network_connections.yml +++ b/detections/endpoint/windows_msiexec_with_network_connections.yml @@ -1,7 +1,7 @@ name: Windows MSIExec With Network Connections id: 827409a1-5393-4d8d-8da4-bbb297c262a7 -version: 2 -date: '2024-05-14' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -59,11 +59,11 @@ tags: - name: parent_process_name type: Process Name role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_ngrok_reverse_proxy_usage.yml b/detections/endpoint/windows_ngrok_reverse_proxy_usage.yml index e0f670b1ed..8b541cebe7 100644 --- a/detections/endpoint/windows_ngrok_reverse_proxy_usage.yml +++ b/detections/endpoint/windows_ngrok_reverse_proxy_usage.yml @@ -1,7 +1,7 @@ name: Windows Ngrok Reverse Proxy Usage id: e2549f2c-0aef-408a-b0c1-e0f270623436 -version: 3 -date: '2024-05-14' +version: 4 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: Anomaly @@ -61,11 +61,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_nirsoft_advancedrun.yml b/detections/endpoint/windows_nirsoft_advancedrun.yml index 84c78b5116..46f49b6889 100644 --- a/detections/endpoint/windows_nirsoft_advancedrun.yml +++ b/detections/endpoint/windows_nirsoft_advancedrun.yml @@ -1,7 +1,7 @@ name: Windows NirSoft AdvancedRun id: bb4f3090-7ae4-11ec-897f-acde48001122 -version: 2 -date: '2024-05-14' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -63,11 +63,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_nirsoft_utilities.yml b/detections/endpoint/windows_nirsoft_utilities.yml index cae71dc40f..b2c35896a2 100644 --- a/detections/endpoint/windows_nirsoft_utilities.yml +++ b/detections/endpoint/windows_nirsoft_utilities.yml @@ -1,7 +1,7 @@ name: Windows NirSoft Utilities id: 5b2f4596-7d4c-11ec-88a7-acde48001122 -version: 2 -date: '2024-05-12' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: Hunting @@ -60,11 +60,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_non_system_account_targeting_lsass.yml b/detections/endpoint/windows_non_system_account_targeting_lsass.yml index e5df2652ed..a205a4dda6 100644 --- a/detections/endpoint/windows_non_system_account_targeting_lsass.yml +++ b/detections/endpoint/windows_non_system_account_targeting_lsass.yml @@ -1,7 +1,7 @@ name: Windows Non-System Account Targeting Lsass id: b1ce9a72-73cf-11ec-981b-acde48001122 -version: 3 -date: '2024-05-09' +version: 4 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -56,7 +56,7 @@ tags: - name: parent_process_path type: Process role: - - Parent Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_odbcconf_hunting.yml b/detections/endpoint/windows_odbcconf_hunting.yml index d0b037f761..90d0735436 100644 --- a/detections/endpoint/windows_odbcconf_hunting.yml +++ b/detections/endpoint/windows_odbcconf_hunting.yml @@ -1,7 +1,7 @@ name: Windows Odbcconf Hunting id: 0562ad4b-fdaa-4882-b12f-7b8e0034cd72 -version: 2 -date: '2024-05-20' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Hunting @@ -56,13 +56,13 @@ tags: role: - Victim - name: parent_process_name - type: Process Name - role: - - Parent Process - - name: process_name type: Process role: - - Child Process + - Attacker + - name: process_name + type: Process Name + role: + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_odbcconf_load_dll.yml b/detections/endpoint/windows_odbcconf_load_dll.yml index c14bfc2a35..6f1ff3d2ce 100644 --- a/detections/endpoint/windows_odbcconf_load_dll.yml +++ b/detections/endpoint/windows_odbcconf_load_dll.yml @@ -1,7 +1,7 @@ name: Windows Odbcconf Load DLL id: 141e7fca-a9f0-40fd-a539-9aac8be41f1b -version: 2 -date: '2024-05-15' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -59,11 +59,11 @@ tags: - name: parent_process_name type: Process Name role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_odbcconf_load_response_file.yml b/detections/endpoint/windows_odbcconf_load_response_file.yml index 1067f4314a..bc17b96232 100644 --- a/detections/endpoint/windows_odbcconf_load_response_file.yml +++ b/detections/endpoint/windows_odbcconf_load_response_file.yml @@ -1,7 +1,7 @@ name: Windows Odbcconf Load Response File id: 1acafff9-1347-4b40-abae-f35aa4ba85c1 -version: 2 -date: '2024-05-15' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -59,11 +59,11 @@ tags: - name: parent_process_name type: Process Name role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_office_product_spawning_msdt.yml b/detections/endpoint/windows_office_product_spawning_msdt.yml index 4977b332f7..c4a46fe00d 100644 --- a/detections/endpoint/windows_office_product_spawning_msdt.yml +++ b/detections/endpoint/windows_office_product_spawning_msdt.yml @@ -1,7 +1,7 @@ name: Windows Office Product Spawning MSDT id: 127eba64-c981-40bf-8589-1830638864a7 -version: 5 -date: '2024-05-25' +version: 6 +date: '2024-08-14' author: Michael Haag, Teoderick Contreras, Splunk status: production type: TTP @@ -68,11 +68,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_papercut_ng_spawn_shell.yml b/detections/endpoint/windows_papercut_ng_spawn_shell.yml index 720d9addcc..0b96f3b03f 100644 --- a/detections/endpoint/windows_papercut_ng_spawn_shell.yml +++ b/detections/endpoint/windows_papercut_ng_spawn_shell.yml @@ -1,7 +1,7 @@ name: Windows PaperCut NG Spawn Shell id: a602d9a2-aaea-45f8-bf0f-d851168d61ca -version: 2 -date: '2024-05-11' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -62,7 +62,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_possible_credential_dumping.yml b/detections/endpoint/windows_possible_credential_dumping.yml index 075f0bb069..e3603fa322 100644 --- a/detections/endpoint/windows_possible_credential_dumping.yml +++ b/detections/endpoint/windows_possible_credential_dumping.yml @@ -1,7 +1,7 @@ name: Windows Possible Credential Dumping id: e4723b92-7266-11ec-af45-acde48001122 -version: 4 -date: '2024-05-31' +version: 5 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -64,7 +64,7 @@ tags: - name: SourceImage type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_privileged_group_modification.yml b/detections/endpoint/windows_privileged_group_modification.yml index d9505bdb38..5a848d9651 100644 --- a/detections/endpoint/windows_privileged_group_modification.yml +++ b/detections/endpoint/windows_privileged_group_modification.yml @@ -1,7 +1,7 @@ name: Windows Privileged Group Modification id: b8cbef2c-2cc3-4550-b0fc-9715b7852df9 -version: 1 -date: '2024-07-30' +version: 2 +date: '2024-08-15' author: Brandon Sternfield, Optiv + ClearShark data_sources: - Windows Event Log Security 4727 @@ -48,23 +48,11 @@ tags: - name: src_user type: User role: - - Attacker + - Victim - name: dest type: Hostname role: - Victim - - name: object - type: Other - role: - - Target - - name: object_category - type: Other - role: - - Other - - name: change_type - type: Other - role: - - Other product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_process_injection_into_notepad.yml b/detections/endpoint/windows_process_injection_into_notepad.yml index 5402b29917..275042523c 100644 --- a/detections/endpoint/windows_process_injection_into_notepad.yml +++ b/detections/endpoint/windows_process_injection_into_notepad.yml @@ -1,7 +1,7 @@ name: Windows Process Injection into Notepad id: b8340d0f-ba48-4391-bea7-9e793c5aae36 -version: 2 -date: '2024-05-14' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk type: Anomaly status: production @@ -49,11 +49,11 @@ tags: - name: SourceImage type: Process role: - - Parent Process + - Attacker - name: TargetImage type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_process_injection_with_public_source_path.yml b/detections/endpoint/windows_process_injection_with_public_source_path.yml index 9353d63f25..6337781de7 100644 --- a/detections/endpoint/windows_process_injection_with_public_source_path.yml +++ b/detections/endpoint/windows_process_injection_with_public_source_path.yml @@ -1,7 +1,7 @@ name: Windows Process Injection With Public Source Path id: 492f09cf-5d60-4d87-99dd-0bc325532dda -version: 2 -date: '2024-05-10' +version: 3 +date: '2024-08-14' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -51,7 +51,7 @@ tags: - name: TargetImage type: Process role: - - Target + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_protocol_tunneling_with_plink.yml b/detections/endpoint/windows_protocol_tunneling_with_plink.yml index d810345bb3..b95a79c2d1 100644 --- a/detections/endpoint/windows_protocol_tunneling_with_plink.yml +++ b/detections/endpoint/windows_protocol_tunneling_with_plink.yml @@ -1,7 +1,7 @@ name: Windows Protocol Tunneling with Plink id: 8aac5e1e-0fab-4437-af0b-c6e60af23eed -version: 3 -date: '2024-07-26' +version: 4 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -65,11 +65,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_raccine_scheduled_task_deletion.yml b/detections/endpoint/windows_raccine_scheduled_task_deletion.yml index cb5045f62c..d9bdfe14fd 100644 --- a/detections/endpoint/windows_raccine_scheduled_task_deletion.yml +++ b/detections/endpoint/windows_raccine_scheduled_task_deletion.yml @@ -1,7 +1,7 @@ name: Windows Raccine Scheduled Task Deletion id: c9f010da-57ab-11ec-82bd-acde48001122 -version: 2 -date: '2024-05-13' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -57,11 +57,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_rasautou_dll_execution.yml b/detections/endpoint/windows_rasautou_dll_execution.yml index 03d814e613..2559fa1a50 100644 --- a/detections/endpoint/windows_rasautou_dll_execution.yml +++ b/detections/endpoint/windows_rasautou_dll_execution.yml @@ -1,7 +1,7 @@ name: Windows Rasautou DLL Execution id: 6f42b8be-8e96-11ec-ad5a-acde48001122 -version: 2 -date: '2024-05-28' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -59,11 +59,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_remote_access_software_hunt.yml b/detections/endpoint/windows_remote_access_software_hunt.yml index fca384f7fa..6e947b4a52 100644 --- a/detections/endpoint/windows_remote_access_software_hunt.yml +++ b/detections/endpoint/windows_remote_access_software_hunt.yml @@ -1,7 +1,7 @@ name: Windows Remote Access Software Hunt id: 8bd22c9f-05a2-4db1-b131-29271f28cb0a -version: 2 -date: '2024-05-15' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Hunting @@ -58,7 +58,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_remote_assistance_spawning_process.yml b/detections/endpoint/windows_remote_assistance_spawning_process.yml index 8a42185fe2..7a0a45264a 100644 --- a/detections/endpoint/windows_remote_assistance_spawning_process.yml +++ b/detections/endpoint/windows_remote_assistance_spawning_process.yml @@ -1,7 +1,7 @@ name: Windows Remote Assistance Spawning Process id: ced50492-8849-11ec-9f68-acde48001122 -version: 2 -date: '2024-05-16' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -55,11 +55,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_remote_create_service.yml b/detections/endpoint/windows_remote_create_service.yml index 540a231e87..7df5ea8be0 100644 --- a/detections/endpoint/windows_remote_create_service.yml +++ b/detections/endpoint/windows_remote_create_service.yml @@ -1,7 +1,7 @@ name: Windows Remote Create Service id: 0dc44d03-8c00-482d-ba7c-796ba7ab18c9 -version: 2 -date: '2024-05-14' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: Anomaly @@ -60,11 +60,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_rundll32_webdav_request.yml b/detections/endpoint/windows_rundll32_webdav_request.yml index 162eecae41..691cb191fa 100644 --- a/detections/endpoint/windows_rundll32_webdav_request.yml +++ b/detections/endpoint/windows_rundll32_webdav_request.yml @@ -1,7 +1,7 @@ name: Windows Rundll32 WebDAV Request id: 320099b7-7eb1-4153-a2b4-decb53267de2 -version: 2 -date: '2024-05-22' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk type: TTP status: production @@ -63,11 +63,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_rundll32_webdav_with_network_connection.yml b/detections/endpoint/windows_rundll32_webdav_with_network_connection.yml index 71b1d73175..31c97f1ff0 100644 --- a/detections/endpoint/windows_rundll32_webdav_with_network_connection.yml +++ b/detections/endpoint/windows_rundll32_webdav_with_network_connection.yml @@ -1,7 +1,7 @@ name: Windows Rundll32 WebDav With Network Connection id: f03355e0-28b5-4e9b-815a-6adffc63b38c -version: 2 -date: '2024-05-11' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk type: TTP status: experimental @@ -66,11 +66,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_schtasks_create_run_as_system.yml b/detections/endpoint/windows_schtasks_create_run_as_system.yml index 4c101f1cb2..77058c44f2 100644 --- a/detections/endpoint/windows_schtasks_create_run_as_system.yml +++ b/detections/endpoint/windows_schtasks_create_run_as_system.yml @@ -1,7 +1,7 @@ name: Windows Schtasks Create Run As System id: 41a0e58e-884c-11ec-9976-acde48001122 -version: 2 -date: '2024-05-12' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -60,7 +60,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_server_software_component_gacutil_install_to_gac.yml b/detections/endpoint/windows_server_software_component_gacutil_install_to_gac.yml index be217da44e..b5170471e8 100644 --- a/detections/endpoint/windows_server_software_component_gacutil_install_to_gac.yml +++ b/detections/endpoint/windows_server_software_component_gacutil_install_to_gac.yml @@ -1,7 +1,7 @@ name: Windows Server Software Component GACUtil Install to GAC id: 7c025ef0-9e65-4c57-be39-1c13dbb1613e -version: 2 -date: '2024-05-25' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -62,11 +62,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_service_create_with_tscon.yml b/detections/endpoint/windows_service_create_with_tscon.yml index d490345a09..8e9da84759 100644 --- a/detections/endpoint/windows_service_create_with_tscon.yml +++ b/detections/endpoint/windows_service_create_with_tscon.yml @@ -1,7 +1,7 @@ name: Windows Service Create with Tscon id: c13b3d74-6b63-4db5-a841-4206f0370077 -version: 2 -date: '2024-05-30' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk type: TTP status: production @@ -70,11 +70,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_service_created_within_public_path.yml b/detections/endpoint/windows_service_created_within_public_path.yml index 6992ebaa34..f9922d09b1 100644 --- a/detections/endpoint/windows_service_created_within_public_path.yml +++ b/detections/endpoint/windows_service_created_within_public_path.yml @@ -1,7 +1,7 @@ name: Windows Service Created Within Public Path id: 3abb2eda-4bb8-11ec-9ae4-3e22fbd008af -version: 3 -date: '2024-05-15' +version: 4 +date: '2024-08-16' author: Mauricio Velazco, Splunk status: production type: TTP @@ -43,7 +43,7 @@ tags: - name: ServiceName type: Other role: - - Other + - Attacker - name: dest type: Endpoint role: diff --git a/detections/endpoint/windows_sql_spawning_certutil.yml b/detections/endpoint/windows_sql_spawning_certutil.yml index 0fc30cee1f..6af4dd15b9 100644 --- a/detections/endpoint/windows_sql_spawning_certutil.yml +++ b/detections/endpoint/windows_sql_spawning_certutil.yml @@ -1,7 +1,7 @@ name: Windows SQL Spawning CertUtil id: dfc18a5a-946e-44ee-a373-c0f60d06e676 -version: 2 -date: '2024-05-17' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: experimental type: TTP @@ -61,7 +61,7 @@ tags: - name: process_name type: Process role: - - Target + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_steal_authentication_certificates_certutil_backup.yml b/detections/endpoint/windows_steal_authentication_certificates_certutil_backup.yml index eb383c7f53..118687ddf0 100644 --- a/detections/endpoint/windows_steal_authentication_certificates_certutil_backup.yml +++ b/detections/endpoint/windows_steal_authentication_certificates_certutil_backup.yml @@ -1,7 +1,7 @@ name: Windows Steal Authentication Certificates CertUtil Backup id: bac85b56-0b65-4ce5-aad5-d94880df0967 -version: 2 -date: '2024-05-04' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Anomaly @@ -59,11 +59,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_steal_authentication_certificates_export_certificate.yml b/detections/endpoint/windows_steal_authentication_certificates_export_certificate.yml index f6707a3b2a..1a1658cfd7 100644 --- a/detections/endpoint/windows_steal_authentication_certificates_export_certificate.yml +++ b/detections/endpoint/windows_steal_authentication_certificates_export_certificate.yml @@ -1,7 +1,7 @@ name: Windows Steal Authentication Certificates Export Certificate id: e39dc429-c2a5-4f1f-9c3c-6b211af6b332 -version: 2 -date: '2024-05-10' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Anomaly @@ -59,11 +59,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_steal_authentication_certificates_export_pfxcertificate.yml b/detections/endpoint/windows_steal_authentication_certificates_export_pfxcertificate.yml index a166cbf42c..cde812b2ba 100644 --- a/detections/endpoint/windows_steal_authentication_certificates_export_pfxcertificate.yml +++ b/detections/endpoint/windows_steal_authentication_certificates_export_pfxcertificate.yml @@ -1,7 +1,7 @@ name: Windows Steal Authentication Certificates Export PfxCertificate id: 391329f3-c14b-4b8d-8b37-ac5012637360 -version: 2 -date: '2024-05-15' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Anomaly @@ -59,11 +59,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml b/detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml index b3159bdd92..88756ad625 100644 --- a/detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml +++ b/detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml @@ -1,7 +1,7 @@ name: Windows System Binary Proxy Execution Compiled HTML File Decompile id: 2acf0e19-4149-451c-a3f3-39cd3c77e37d -version: 2 -date: '2024-05-17' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -61,7 +61,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml b/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml index 125d4594ea..7e48bc0de1 100644 --- a/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml +++ b/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml @@ -1,7 +1,7 @@ name: Windows System Script Proxy Execution Syncappvpublishingserver id: 8dd73f89-682d-444c-8b41-8e679966ad3c -version: 2 -date: '2024-05-18' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -62,11 +62,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_terminating_lsass_process.yml b/detections/endpoint/windows_terminating_lsass_process.yml index fe239ff752..665870bc25 100644 --- a/detections/endpoint/windows_terminating_lsass_process.yml +++ b/detections/endpoint/windows_terminating_lsass_process.yml @@ -1,7 +1,7 @@ name: Windows Terminating Lsass Process id: 7ab3c319-a4e7-4211-9e8c-40a049d0dba6 -version: 2 -date: '2024-05-23' +version: 3 +date: '2024-08-15' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -48,7 +48,7 @@ tags: - name: TargetImage type: Process role: - - Target + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_vulnerable_3cx_software.yml b/detections/endpoint/windows_vulnerable_3cx_software.yml index 92b8990d68..7baa6e71e6 100644 --- a/detections/endpoint/windows_vulnerable_3cx_software.yml +++ b/detections/endpoint/windows_vulnerable_3cx_software.yml @@ -1,7 +1,7 @@ name: Windows Vulnerable 3CX Software id: f2cc1584-46ee-485b-b905-977c067f36de -version: 2 -date: '2024-05-18' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk type: TTP status: production @@ -52,7 +52,7 @@ tags: - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_windbg_spawning_autoit3.yml b/detections/endpoint/windows_windbg_spawning_autoit3.yml index c8bbd6fdf2..6221e937a6 100644 --- a/detections/endpoint/windows_windbg_spawning_autoit3.yml +++ b/detections/endpoint/windows_windbg_spawning_autoit3.yml @@ -1,7 +1,7 @@ name: Windows WinDBG Spawning AutoIt3 id: 7aec015b-cd69-46c3-85ed-dac152056aa4 -version: 2 -date: '2024-05-11' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -61,11 +61,11 @@ tags: - name: parent_process_name type: Process Name role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/winhlp32_spawning_a_process.yml b/detections/endpoint/winhlp32_spawning_a_process.yml index 8a548f94a9..88e88f7d07 100644 --- a/detections/endpoint/winhlp32_spawning_a_process.yml +++ b/detections/endpoint/winhlp32_spawning_a_process.yml @@ -1,7 +1,7 @@ name: Winhlp32 Spawning a Process id: d17dae9e-2618-11ec-b9f5-acde48001122 -version: 2 -date: '2024-05-16' +version: 3 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -60,11 +60,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/winrar_spawning_shell_application.yml b/detections/endpoint/winrar_spawning_shell_application.yml index 2664e41ba3..b697ecd4e7 100644 --- a/detections/endpoint/winrar_spawning_shell_application.yml +++ b/detections/endpoint/winrar_spawning_shell_application.yml @@ -1,7 +1,7 @@ name: WinRAR Spawning Shell Application id: d2f36034-37fa-4bd4-8801-26807c15540f -version: 2 -date: '2024-05-25' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -68,11 +68,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/winword_spawning_cmd.yml b/detections/endpoint/winword_spawning_cmd.yml index b556dd77a0..1ca542505a 100644 --- a/detections/endpoint/winword_spawning_cmd.yml +++ b/detections/endpoint/winword_spawning_cmd.yml @@ -1,7 +1,7 @@ name: Winword Spawning Cmd id: 6fcbaedc-a37b-11eb-956b-acde48001122 -version: 3 -date: '2024-05-29' +version: 4 +date: '2024-08-15' author: Michael Haag, Splunk status: production type: TTP @@ -61,7 +61,7 @@ tags: - name: process_name type: Process role: - - Target + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/winword_spawning_powershell.yml b/detections/endpoint/winword_spawning_powershell.yml index 8dcfca564b..afb32417bc 100644 --- a/detections/endpoint/winword_spawning_powershell.yml +++ b/detections/endpoint/winword_spawning_powershell.yml @@ -1,7 +1,7 @@ name: Winword Spawning PowerShell id: b2c950b8-9be2-11eb-8658-acde48001122 -version: 3 -date: '2024-05-10' +version: 4 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -64,7 +64,7 @@ tags: - name: process_name type: Process role: - - Target + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/winword_spawning_windows_script_host.yml b/detections/endpoint/winword_spawning_windows_script_host.yml index fe26ab1e9c..8d3c66a9c2 100644 --- a/detections/endpoint/winword_spawning_windows_script_host.yml +++ b/detections/endpoint/winword_spawning_windows_script_host.yml @@ -1,7 +1,7 @@ name: Winword Spawning Windows Script Host id: 637e1b5c-9be1-11eb-9c32-acde48001122 -version: 2 -date: '2024-05-16' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -59,7 +59,7 @@ tags: - name: process_name type: Process role: - - Target + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/wmi_temporary_event_subscription.yml b/detections/endpoint/wmi_temporary_event_subscription.yml index 8f1072481d..5a17650fa8 100644 --- a/detections/endpoint/wmi_temporary_event_subscription.yml +++ b/detections/endpoint/wmi_temporary_event_subscription.yml @@ -1,7 +1,7 @@ name: WMI Temporary Event Subscription id: 38cbd42c-1098-41bb-99cf-9d6d2b296d83 -version: 2 -date: '2024-05-12' +version: 3 +date: '2024-08-15' author: Rico Valdez, Splunk status: experimental type: TTP @@ -39,9 +39,9 @@ tags: - T1047 observable: - name: dest - type: Other + type: Hostname role: - - Other + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/wmic_noninteractive_app_uninstallation.yml b/detections/endpoint/wmic_noninteractive_app_uninstallation.yml index fb1fb67d6f..984b67f296 100644 --- a/detections/endpoint/wmic_noninteractive_app_uninstallation.yml +++ b/detections/endpoint/wmic_noninteractive_app_uninstallation.yml @@ -1,7 +1,7 @@ name: Wmic NonInteractive App Uninstallation id: bff0e7a0-317f-11ec-ab4e-acde48001122 -version: 3 -date: '2024-05-26' +version: 4 +date: '2024-08-15' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -61,7 +61,7 @@ tags: - name: process_name type: Process role: - - Target + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/wmic_xsl_execution_via_url.yml b/detections/endpoint/wmic_xsl_execution_via_url.yml index 70e85434ac..67778e2ab7 100644 --- a/detections/endpoint/wmic_xsl_execution_via_url.yml +++ b/detections/endpoint/wmic_xsl_execution_via_url.yml @@ -1,7 +1,7 @@ name: WMIC XSL Execution via URL id: 787e9dd0-4328-11ec-a029-acde48001122 -version: 2 -date: '2024-05-27' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: TTP @@ -60,11 +60,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/xsl_script_execution_with_wmic.yml b/detections/endpoint/xsl_script_execution_with_wmic.yml index b06116aa92..7a322158db 100644 --- a/detections/endpoint/xsl_script_execution_with_wmic.yml +++ b/detections/endpoint/xsl_script_execution_with_wmic.yml @@ -1,7 +1,7 @@ name: XSL Script Execution With WMIC id: 004e32e2-146d-11ec-a83f-acde48001122 -version: 2 -date: '2024-05-13' +version: 3 +date: '2024-08-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,11 +61,11 @@ tags: - name: parent_process_name type: Process role: - - Parent Process + - Attacker - name: process_name type: Process role: - - Child Process + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/detect_arp_poisoning.yml b/detections/network/detect_arp_poisoning.yml index 2dae82e3f5..38f16d21b7 100644 --- a/detections/network/detect_arp_poisoning.yml +++ b/detections/network/detect_arp_poisoning.yml @@ -1,7 +1,7 @@ name: Detect ARP Poisoning id: b44bebd6-bd39-467b-9321-73971bcd1aac -version: 2 -date: '2024-05-12' +version: 3 +date: '2024-08-14' author: Mikael Bjerkeland, Splunk status: experimental type: TTP @@ -46,7 +46,7 @@ tags: - name: dest type: Other role: - - Other + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/detect_port_security_violation.yml b/detections/network/detect_port_security_violation.yml index 3df84d3efe..7899791e48 100644 --- a/detections/network/detect_port_security_violation.yml +++ b/detections/network/detect_port_security_violation.yml @@ -1,7 +1,7 @@ name: Detect Port Security Violation id: 2de3d5b8-a4fa-45c5-8540-6d071c194d24 -version: 2 -date: '2024-05-13' +version: 3 +date: '2024-08-16' author: Mikael Bjerkeland, Splunk status: experimental type: TTP @@ -46,7 +46,7 @@ tags: - name: dest type: Other role: - - Other + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/detect_rogue_dhcp_server.yml b/detections/network/detect_rogue_dhcp_server.yml index a9254f53b9..c89cfe41fe 100644 --- a/detections/network/detect_rogue_dhcp_server.yml +++ b/detections/network/detect_rogue_dhcp_server.yml @@ -1,7 +1,7 @@ name: Detect Rogue DHCP Server id: 6e1ada88-7a0d-4ac1-92c6-03d354686079 -version: 2 -date: '2024-05-28' +version: 3 +date: '2024-08-14' author: Mikael Bjerkeland, Splunk status: experimental type: TTP @@ -42,7 +42,7 @@ tags: - name: dest type: Other role: - - Other + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/detect_traffic_mirroring.yml b/detections/network/detect_traffic_mirroring.yml index 6905c3e69a..2b83def6ef 100644 --- a/detections/network/detect_traffic_mirroring.yml +++ b/detections/network/detect_traffic_mirroring.yml @@ -1,7 +1,7 @@ name: Detect Traffic Mirroring id: 42b3b753-5925-49c5-9742-36fa40a73990 -version: 2 -date: '2024-05-09' +version: 3 +date: '2024-08-14' author: Mikael Bjerkeland, Splunk status: experimental type: TTP @@ -45,7 +45,7 @@ tags: - name: dest type: Other role: - - Other + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/detect_windows_dns_sigred_via_splunk_stream.yml b/detections/network/detect_windows_dns_sigred_via_splunk_stream.yml index 6dc617e251..2a0c5b23b1 100644 --- a/detections/network/detect_windows_dns_sigred_via_splunk_stream.yml +++ b/detections/network/detect_windows_dns_sigred_via_splunk_stream.yml @@ -1,7 +1,7 @@ name: Detect Windows DNS SIGRed via Splunk Stream id: babd8d10-d073-11ea-87d0-0242ac130003 -version: 2 -date: '2024-05-28' +version: 3 +date: '2024-08-14' author: Shannon Davis, Splunk status: experimental type: TTP @@ -36,10 +36,10 @@ tags: mitre_attack_id: - T1203 observable: - - name: dest + - name: flow_id type: Other role: - - Other + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/detect_windows_dns_sigred_via_zeek.yml b/detections/network/detect_windows_dns_sigred_via_zeek.yml index 6cffde76c0..1290d1c7be 100644 --- a/detections/network/detect_windows_dns_sigred_via_zeek.yml +++ b/detections/network/detect_windows_dns_sigred_via_zeek.yml @@ -1,7 +1,7 @@ name: Detect Windows DNS SIGRed via Zeek id: c5c622e4-d073-11ea-87d0-0242ac130003 -version: 2 -date: '2024-05-23' +version: 3 +date: '2024-08-19' author: Shannon Davis, Splunk status: experimental type: TTP @@ -32,10 +32,10 @@ tags: mitre_attack_id: - T1203 observable: - - name: dest + - name: flow_id type: Other role: - - Other + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/web/detect_f5_tmui_rce_cve_2020_5902.yml b/detections/web/detect_f5_tmui_rce_cve_2020_5902.yml index 568b19452a..4c23f542fd 100644 --- a/detections/web/detect_f5_tmui_rce_cve_2020_5902.yml +++ b/detections/web/detect_f5_tmui_rce_cve_2020_5902.yml @@ -1,7 +1,7 @@ name: Detect F5 TMUI RCE CVE-2020-5902 id: 810e4dbc-d46e-11ea-87d0-0242ac130003 -version: 2 -date: '2024-05-22' +version: 3 +date: '2024-08-16' author: Shannon Davis, Splunk status: experimental type: TTP @@ -39,9 +39,9 @@ tags: - T1190 observable: - name: dest - type: Other + type: IP Address role: - - Other + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/web/hunting_for_log4shell.yml b/detections/web/hunting_for_log4shell.yml index d5aa4dc7ba..fa2b09881d 100644 --- a/detections/web/hunting_for_log4shell.yml +++ b/detections/web/hunting_for_log4shell.yml @@ -1,7 +1,7 @@ name: Hunting for Log4Shell id: 158b68fa-5d1a-11ec-aac8-acde48001122 -version: 2 -date: '2024-05-26' +version: 3 +date: '2024-08-14' author: Michael Haag, Splunk status: production type: Hunting @@ -61,14 +61,10 @@ tags: type: Hostname role: - Victim - - name: http_method - type: Other - role: - - Other - name: src - type: Other + type: IP Address role: - - Other + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/web/detections/web/ivanti_epm_sql_injection_remote_code_execution.yml b/detections/web/ivanti_epm_sql_injection_remote_code_execution.yml similarity index 100% rename from detections/web/detections/web/ivanti_epm_sql_injection_remote_code_execution.yml rename to detections/web/ivanti_epm_sql_injection_remote_code_execution.yml diff --git a/detections/web/jetbrains_teamcity_rce_attempt.yml b/detections/web/jetbrains_teamcity_rce_attempt.yml index abca1f2fc1..e525d10bca 100644 --- a/detections/web/jetbrains_teamcity_rce_attempt.yml +++ b/detections/web/jetbrains_teamcity_rce_attempt.yml @@ -1,7 +1,7 @@ name: JetBrains TeamCity RCE Attempt id: 89a58e5f-1365-4793-b45c-770abbb32b6c -version: 2 -date: '2024-05-23' +version: 3 +date: '2024-08-16' author: Michael Haag, Splunk status: production type: TTP @@ -49,10 +49,6 @@ tags: type: Hostname role: - Victim - - name: url - type: URL String - role: - - Other - name: src type: IP Address role: diff --git a/detections/web/ws_ftp_remote_code_execution.yml b/detections/web/ws_ftp_remote_code_execution.yml index 12d1f3d7d0..178af37f1b 100644 --- a/detections/web/ws_ftp_remote_code_execution.yml +++ b/detections/web/ws_ftp_remote_code_execution.yml @@ -1,7 +1,7 @@ name: WS FTP Remote Code Execution id: b84e8f39-4e7b-4d4f-9e7c-fcd29a227845 -version: 2 -date: '2024-05-11' +version: 3 +date: '2024-08-16' author: Michael Haag, Splunk status: production type: TTP @@ -43,10 +43,6 @@ tags: mitre_attack_id: - T1190 observable: - - name: url - type: URL String - role: - - Other - name: dest type: Hostname role: