Branch was auto-updated.

This commit is contained in:
Bhavin Patel
2021-10-15 09:18:36 -07:00
committed by GitHub
60 changed files with 73 additions and 10 deletions
@@ -44,6 +44,7 @@ tags:
$dest$
mitre_attack_id:
- T1560.001
- T1560
observable:
- name: dest
type: Hostname
@@ -43,6 +43,7 @@ tags:
Service (LSASS).
mitre_attack_id:
- T1003.001
- T1003
nist:
- DE.CM
observable:
@@ -47,6 +47,7 @@ tags:
message: Suspicious $process_name$ usage detected on endpoint $dest$ by user $user$.
mitre_attack_id:
- T1087.002
- T1087
observable:
- name: user
type: User
@@ -19,9 +19,9 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTim
Components*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name
Registry.registry_value_name | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)`
| `drop_dm_object_name(Registry)` | `active_setup_registry_autostart_filter`'
how_to_implement: To successfully implement this search, you must be ingesting
data that records registry activity from your hosts to populate the endpoint data
model in the registry node. This is typically populated via endpoint detection-and-response
how_to_implement: To successfully implement this search, you must be ingesting data
that records registry activity from your hosts to populate the endpoint data model
in the registry node. This is typically populated via endpoint detection-and-response
product, such as Carbon Black or endpoint data sources, such as Sysmon. The data
used for this search is typically generated via logs that report reads and writes
to the registry.
@@ -39,6 +39,7 @@ tags:
- Exploitation
mitre_attack_id:
- T1547.014
- T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -42,6 +42,7 @@ tags:
to prepare autoadminlogon
mitre_attack_id:
- T1552.002
- T1552
observable:
- name: dest
type: Endpoint
@@ -38,6 +38,7 @@ tags:
message: powershell process having commandline $Message$ for user enumeration
mitre_attack_id:
- T1087.002
- T1087
observable:
- name: ComputerName
type: Hostname
@@ -36,6 +36,7 @@ tags:
- Exploitation
mitre_attack_id:
- T1562.007
- T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -42,6 +42,7 @@ tags:
$dest$ by user $user$.
mitre_attack_id:
- T1021.001
- T1021
observable:
- name: user
type: User
@@ -38,6 +38,7 @@ tags:
user $user$.
mitre_attack_id:
- T1021.001
- T1021
observable:
- name: user
type: User
@@ -38,6 +38,7 @@ tags:
- Exploitation
mitre_attack_id:
- T1562.007
- T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -47,6 +47,7 @@ tags:
of 7zip.
mitre_attack_id:
- T1560.001
- T1560
observable:
- name: user
type: User
@@ -47,6 +47,7 @@ tags:
on endpoint $dest$ by user $user$. This behavior identifies the use of DownloadFile
within PowerShell.
mitre_attack_id:
- T1059
- T1059.001
observable:
- name: user
@@ -44,6 +44,7 @@ tags:
on endpoint $dest$ by user $user$. This behavior identifies the use of DownloadString
within PowerShell.
mitre_attack_id:
- T1059
- T1059.001
observable:
- name: user
@@ -51,8 +51,9 @@ tags:
on host $dest$ by User $user$. This process $process_name$ is known to do- $description$
mitre_attack_id:
- T1036.005
- T1595
- T1036
- T1003
- T1595
nist:
- ID.AM
- PR.DS
@@ -46,6 +46,7 @@ tags:
attempting to add a certificate to the store on endpoint $dest$ by user $user$.
mitre_attack_id:
- T1553.004
- T1553
nist:
- PR.PT
- DE.CM
@@ -49,6 +49,7 @@ tags:
attempting to disable security services on endpoint $dest$ by user $user$.
mitre_attack_id:
- T1562.001
- T1562
nist:
- PR.PT
- DE.CM
@@ -47,6 +47,7 @@ tags:
on endpoint $dest$ by user $user$ attempting to export the registry keys.
mitre_attack_id:
- T1003.002
- T1003
nist:
- DE.CM
observable:
@@ -42,6 +42,7 @@ tags:
to prepare autoadminlogon
mitre_attack_id:
- T1552.002
- T1552
observable:
- name: dest
type: Endpoint
@@ -50,6 +50,7 @@ tags:
message: A file - $file_name$ was written to system32 has occurred on endpoint $dest$
by user $user$.
mitre_attack_id:
- T1204
- T1204.002
nist:
- PR.PT
@@ -36,6 +36,7 @@ tags:
- Exploitation
mitre_attack_id:
- T1546.001
- T1546
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -40,6 +40,7 @@ tags:
of a specific disk.
mitre_attack_id:
- T1070.004
- T1070
observable:
- name: user
type: User
@@ -44,8 +44,10 @@ tags:
on endpoint $dest$ by user $user$ potentially performing privilege escalation
using named pipes related to Cobalt Strike and other frameworks.
mitre_attack_id:
- T1059
- T1059.003
- T1543.003
- T1543
observable:
- name: user
type: User
@@ -44,6 +44,7 @@ tags:
message: parent process name $parent_process_name$ with child process $process_name$
to execute commandline tool in $dest$
mitre_attack_id:
- T1059
- T1059.007
observable:
- name: dest
@@ -38,6 +38,7 @@ tags:
message: The following module $ImageLoaded$ was loaded by a non-standard application
on endpoint $Computer$ by user $user$.
mitre_attack_id:
- T1218
- T1218.003
observable:
- name: user
@@ -47,6 +47,7 @@ tags:
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk.
mitre_attack_id:
- T1218
- T1218.002
observable:
- name: user
@@ -46,6 +46,7 @@ tags:
group.
mitre_attack_id:
- T1136.001
- T1136
nist:
- PR.PT
- DE.CM
@@ -42,6 +42,7 @@ tags:
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ enumerating Windows file shares.
mitre_attack_id:
- T1070
- T1070.005
nist:
- PR.PT
@@ -41,6 +41,7 @@ tags:
behavior is indicative of credential dumping and should be investigated.
mitre_attack_id:
- T1003.001
- T1003
nist:
- DE.CM
observable:
@@ -36,6 +36,7 @@ tags:
message: A service $Service_File_Name$ was created from a non-standard path using
$Service_Name$, potentially leading to a privilege escalation.
mitre_attack_id:
- T1569
- T1569.002
observable:
- name: Service_File_Name
@@ -47,6 +47,7 @@ tags:
to disk. This behavior is related to dumping credentials via Task Manager.
mitre_attack_id:
- T1003.001
- T1003
nist:
- DE.CM
observable:
@@ -45,6 +45,7 @@ tags:
offline password cracking.
mitre_attack_id:
- T1003.003
- T1003
nist:
- DE.CM
observable:
@@ -43,6 +43,7 @@ tags:
offline password cracking.
mitre_attack_id:
- T1003.003
- T1003
nist:
- DE.CM
observable:
@@ -45,6 +45,7 @@ tags:
password cracking.
mitre_attack_id:
- T1003.003
- T1003
nist:
- DE.CM
observable:
@@ -43,6 +43,7 @@ tags:
to grab credentials.
mitre_attack_id:
- T1003.003
- T1003
nist:
- DE.CM
observable:
@@ -38,6 +38,7 @@ tags:
message: The following $EventCode$ occurred on $dest$ by $user$ with Logon Type
3, which may be indicative of the pass the hash technique.
mitre_attack_id:
- T1550
- T1550.002
nist:
- PR.PT
@@ -42,10 +42,12 @@ tags:
on endpoint $dest$ by user $user$ using AzureHound to enumerate AzureAD.
mitre_attack_id:
- T1087.002
- T1087.001
- T1482
- T1069.002
- T1069.001
- T1482
- T1087.001
- T1087
- T1069.002
- T1069
observable:
- name: user
type: User
@@ -45,10 +45,12 @@ tags:
a AzureAD enumeration utility, has occurred on endpoint $dest$ by user $user$.
mitre_attack_id:
- T1087.002
- T1087.001
- T1482
- T1069.002
- T1069.001
- T1482
- T1087.001
- T1087
- T1069.002
- T1069
observable:
- name: user
type: User
@@ -49,6 +49,7 @@ tags:
$ComputerName$ by user $user$.
mitre_attack_id:
- T1003.002
- T1003
observable:
- name: user
type: User
@@ -47,6 +47,7 @@ tags:
investigated.
mitre_attack_id:
- T1003.001
- T1003
nist:
- PR.IP
- PR.AC
@@ -51,6 +51,7 @@ tags:
message: The following behavior was identified and typically related to PowerShell-Empire
on $ComputerName$ by $User$.
mitre_attack_id:
- T1059
- T1059.001
observable:
- name: User
@@ -49,6 +49,7 @@ tags:
message: Multiple accounts have been locked out. Review $dest$ and results related
to $user$.
mitre_attack_id:
- T1078
- T1078.002
nist:
- PR.IP
@@ -38,6 +38,7 @@ tags:
message: Multiple accounts have been locked out. Review $nodename$ and $result$
related to $user$.
mitre_attack_id:
- T1078
- T1078.003
nist:
- PR.IP
@@ -65,6 +65,7 @@ tags:
previously performed by HAFNIUM. Review further file modifications on endpoint
$dest$ by user $user$.
mitre_attack_id:
- T1505
- T1505.003
observable:
- name: user
@@ -53,6 +53,7 @@ tags:
message: The following $process_name$ has been identified as renamed, spawning from
$parent_process_name$.
mitre_attack_id:
- T1218
- T1218.001
nist:
- PR.PT
@@ -53,6 +53,7 @@ tags:
on endpoint $dest$ by user $user$ spawning a child process, typically not normal
behavior.
mitre_attack_id:
- T1218
- T1218.001
nist:
- PR.PT
@@ -57,6 +57,7 @@ tags:
on endpoint $dest$ by user $user$ contacting a remote destination to potentally
download a malicious payload.
mitre_attack_id:
- T1218
- T1218.001
nist:
- PR.PT
@@ -58,6 +58,7 @@ tags:
message: $process_name$ has been identified using Infotech Storage Handlers to load
a specific file within a CHM on $dest$ under user $user$.
mitre_attack_id:
- T1218
- T1218.001
nist:
- PR.PT
@@ -48,6 +48,7 @@ tags:
to credential dumping on $Computer$. Review for further details.
mitre_attack_id:
- T1003.001
- T1003
nist:
- DE.AE
- DE.CM
@@ -49,6 +49,7 @@ tags:
on endpoint $dest$ by user $user$ executing with inline HTA, indicative of defense
evasion.
mitre_attack_id:
- T1218
- T1218.005
nist:
- PR.PT
@@ -46,6 +46,7 @@ tags:
message: The following $process_name$ has been identified as renamed, spawning from
$parent_process_name$.
mitre_attack_id:
- T1218
- T1218.005
nist:
- PR.PT
@@ -50,6 +50,7 @@ tags:
on endpoint $est$ by user $user$ attempting to access a remote destination to
download an additional payload.
mitre_attack_id:
- T1218
- T1218.005
nist:
- PR.PT
@@ -42,6 +42,7 @@ tags:
behavior or not.
mitre_attack_id:
- T1136.001
- T1136
nist:
- PR.AC
- DE.CM
@@ -45,6 +45,7 @@ tags:
using unquoted service paths.
mitre_attack_id:
- T1574.009
- T1574
nist:
- PR.PT
- DE.CM
@@ -48,6 +48,7 @@ tags:
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ running prohibited applications.
mitre_attack_id:
- T1059
- T1059.003
nist:
- PR.PT
@@ -53,6 +53,7 @@ tags:
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ running the utility for possibly the first time.
mitre_attack_id:
- T1021
- T1021.002
nist:
- PR.PT
@@ -50,6 +50,7 @@ tags:
on endpoint $dest$ by user $user$ spawning a child process, typically not normal
behavior for $parent_process_name$.
mitre_attack_id:
- T1218
- T1218.009
nist:
- PR.PT
@@ -49,6 +49,7 @@ tags:
message: An instance of $process_name$ contacting a remote destination was identified
on endpoint $Computer$ by user $user$. This behavior is not normal for $process_name$.
mitre_attack_id:
- T1218
- T1218.009
nist:
- PR.PT
@@ -48,6 +48,7 @@ tags:
message: The process $process_name$ was spawned by $parent_process_name$ without
any command-line arguments on $dest$ by $user$.
mitre_attack_id:
- T1218
- T1218.009
nist:
- PR.PT
@@ -48,6 +48,7 @@ tags:
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ typically not normal for this process.
mitre_attack_id:
- T1218
- T1218.009
nist:
- PR.PT
@@ -49,6 +49,7 @@ tags:
message: An instance of $process_name$ contacting a remote destination was identified
on endpoint $Computer$ by user $user$. This behavior is not normal for $process_name$.
mitre_attack_id:
- T1218
- T1218.009
nist:
- PR.PT