version and date update

This commit is contained in:
bpatel
2020-03-16 12:56:56 -07:00
parent 7ee8310efb
commit d7828c2c0d
16 changed files with 32 additions and 32 deletions
+2 -2
View File
@@ -95,7 +95,7 @@ mappings:
- Persistence
nist:
- DE.CM
modification_date: '2018-11-15'
modification_date: '2020-03-16'
name: Hiding Files And Directories With Attrib.exe
original_authors:
- company: Splunk
@@ -105,4 +105,4 @@ references: []
security_domain: endpoint
spec_version: 2
type: splunk
version: '2.0'
version: '3.0'
+2 -2
View File
@@ -108,7 +108,7 @@ mappings:
- DE.CM
- PR.PT
- PR.IP
modification_date: '2018-01-26'
modification_date: '2020-03-16'
name: Suspicious Changes to File Associations
original_authors:
- company: Splunk
@@ -118,4 +118,4 @@ references: []
security_domain: endpoint
spec_version: 2
type: splunk
version: '2.0'
version: '3.0'
+2 -2
View File
@@ -99,7 +99,7 @@ mappings:
- PR.AC
- PR.PT
- DE.CM
modification_date: '2020-07-03'
modification_date: '2020-03-16'
name: Child Processes of Spoolsv.exe
original_authors:
- company: Splunk
@@ -109,4 +109,4 @@ references: []
security_domain: endpoint
spec_version: 2
type: splunk
version: '2.0'
version: '3.0'
+2 -2
View File
@@ -110,7 +110,7 @@ mappings:
nist:
- PR.PT
- DE.CM
modification_date: '2018-11-15'
modification_date: '2020-03-16'
name: Common Ransomware Extensions
original_authors:
- company: Splunk
@@ -120,4 +120,4 @@ references: []
security_domain: endpoint
spec_version: 2
type: splunk
version: '2.0'
version: '3.0'
+2 -2
View File
@@ -98,7 +98,7 @@ mappings:
nist:
- PR.PT
- DE.CM
modification_date: '2018-11-15'
modification_date: '2020-03-16'
name: Common Ransomware Notes
original_authors:
- company: Splunk
@@ -108,4 +108,4 @@ references: []
security_domain: endpoint
spec_version: 2
type: splunk
version: '2.0'
version: '3.0'
+2 -2
View File
@@ -98,7 +98,7 @@ mappings:
nist:
- PR.PT
- DE.CM
modification_date: '2018-11-15'
modification_date: '2020-03-16'
name: Create local admin accounts using net.exe
original_authors:
- company: Splunk
@@ -108,4 +108,4 @@ references: []
security_domain: endpoint
spec_version: 2
type: splunk
version: '2.0'
version: '3.0'
+2 -2
View File
@@ -96,7 +96,7 @@ mappings:
- Scheduled Task
nist:
- PR.IP
modification_date: '2018-12-03'
modification_date: '2020-03-16'
name: Scheduled Task Name Used by Dragonfly Threat Actors
original_authors:
- company: Splunk
@@ -106,4 +106,4 @@ references: []
security_domain: endpoint
spec_version: 2
type: splunk
version: '2.0'
version: '3.0'
+2 -2
View File
@@ -96,7 +96,7 @@ mappings:
- Execution
nist:
- DE.CM
modification_date: '2018-12-03'
modification_date: '2020-03-16'
name: Spike in File Writes
original_authors:
- company: Splunk
@@ -106,4 +106,4 @@ references: []
security_domain: endpoint
spec_version: 2
type: splunk
version: '2.0'
version: '3.0'
+2 -2
View File
@@ -81,7 +81,7 @@ mappings:
nist:
- ID.AM
- PR.DS
modification_date: '2019-04-29'
modification_date: '2020-03-16'
name: Suspicious LNK file launching a process
original_authors:
- company: Splunk
@@ -91,4 +91,4 @@ responses: []
security_domain: network
spec_version: 2
type: splunk
version: '1.0'
version: '2.0'
+2 -2
View File
@@ -89,7 +89,7 @@ mappings:
nist:
- ID.AM
- PR.DS
modification_date: '2019-04-29'
modification_date: '2020-03-16'
name: Detect Oulook.exe writing a .zip file
original_authors:
- company: Splunk
@@ -99,4 +99,4 @@ responses: []
security_domain: network
spec_version: 2
type: splunk
version: '1.0'
version: '2.0'
+2 -2
View File
@@ -111,7 +111,7 @@ mappings:
- PR.PT
- PR.DS
- DE.CM
modification_date: '2018-10-30'
modification_date: '2020-03-16'
name: Detect Rare Executables
original_authors:
- company: Splunk
@@ -121,4 +121,4 @@ references: []
security_domain: endpoint
spec_version: 2
type: splunk
version: '4.0'
version: '5.0'
+2 -2
View File
@@ -104,7 +104,7 @@ mappings:
- Disabling Security Tools
nist:
- DE.CM
modification_date: '2019-03-01'
modification_date: '2020-03-16'
name: Suspicious Reg.exe Process
original_authors:
- company: Splunk
@@ -115,4 +115,4 @@ references:
security_domain: endpoint
spec_version: 2
type: splunk
version: '2.0'
version: '3.0'
+2 -2
View File
@@ -99,7 +99,7 @@ mappings:
nist:
- ID.AM
- PR.DS
modification_date: '2019-04-01'
modification_date: '2020-03-16'
name: Uncommon Processes On Endpoint
original_authors:
- company: Splunk
@@ -109,4 +109,4 @@ references: []
security_domain: endpoint
spec_version: 2
type: splunk
version: '2.0'
version: '3.0'
+2 -2
View File
@@ -99,7 +99,7 @@ mappings:
nist:
- PR.PT
- DE.CM
modification_date: '2019-02-28'
modification_date: '2020-03-16'
name: Unusually Long Command Line
original_authors:
- company: Splunk
@@ -109,4 +109,4 @@ references: []
security_domain: endpoint
spec_version: 2
type: splunk
version: '3.0'
version: '4.0'
+2 -2
View File
@@ -96,7 +96,7 @@ mappings:
- PR.AT
- PR.AC
- PR.IP
modification_date: '2019-02-28'
modification_date: '2020-03-16'
name: Process Execution via WMI
original_authors:
- company: Splunk
@@ -106,4 +106,4 @@ references: []
security_domain: endpoint
spec_version: 2
type: splunk
version: '2.0'
version: '3.0'
+2 -2
View File
@@ -96,7 +96,7 @@ mappings:
- PR.AT
- PR.AC
- PR.IP
modification_date: '2019-03-01'
modification_date: '2020-03-16'
name: Script Execution via WMI
original_authors:
- company: Splunk
@@ -106,4 +106,4 @@ references: []
security_domain: endpoint
spec_version: 2
type: splunk
version: '2.0'
version: '3.0'