diff --git a/detections/attrib_to_hide_files.yml b/detections/attrib_to_hide_files.yml index 68ab374d86..099387ec43 100644 --- a/detections/attrib_to_hide_files.yml +++ b/detections/attrib_to_hide_files.yml @@ -95,7 +95,7 @@ mappings: - Persistence nist: - DE.CM -modification_date: '2018-11-15' +modification_date: '2020-03-16' name: Hiding Files And Directories With Attrib.exe original_authors: - company: Splunk @@ -105,4 +105,4 @@ references: [] security_domain: endpoint spec_version: 2 type: splunk -version: '2.0' +version: '3.0' diff --git a/detections/change_file_association.yml b/detections/change_file_association.yml index 396277b2fa..79c4e289d8 100644 --- a/detections/change_file_association.yml +++ b/detections/change_file_association.yml @@ -108,7 +108,7 @@ mappings: - DE.CM - PR.PT - PR.IP -modification_date: '2018-01-26' +modification_date: '2020-03-16' name: Suspicious Changes to File Associations original_authors: - company: Splunk @@ -118,4 +118,4 @@ references: [] security_domain: endpoint spec_version: 2 type: splunk -version: '2.0' +version: '3.0' diff --git a/detections/children_of_spoolsv.yml b/detections/children_of_spoolsv.yml index 4acb01ea67..71eaef8c88 100644 --- a/detections/children_of_spoolsv.yml +++ b/detections/children_of_spoolsv.yml @@ -99,7 +99,7 @@ mappings: - PR.AC - PR.PT - DE.CM -modification_date: '2020-07-03' +modification_date: '2020-03-16' name: Child Processes of Spoolsv.exe original_authors: - company: Splunk @@ -109,4 +109,4 @@ references: [] security_domain: endpoint spec_version: 2 type: splunk -version: '2.0' +version: '3.0' diff --git a/detections/common_ransomware_extensions.yml b/detections/common_ransomware_extensions.yml index eaf7f66351..f276171835 100644 --- a/detections/common_ransomware_extensions.yml +++ b/detections/common_ransomware_extensions.yml @@ -110,7 +110,7 @@ mappings: nist: - PR.PT - DE.CM -modification_date: '2018-11-15' +modification_date: '2020-03-16' name: Common Ransomware Extensions original_authors: - company: Splunk @@ -120,4 +120,4 @@ references: [] security_domain: endpoint spec_version: 2 type: splunk -version: '2.0' +version: '3.0' diff --git a/detections/common_ransomware_notes.yml b/detections/common_ransomware_notes.yml index 15f3137b52..6f21591ee3 100644 --- a/detections/common_ransomware_notes.yml +++ b/detections/common_ransomware_notes.yml @@ -98,7 +98,7 @@ mappings: nist: - PR.PT - DE.CM -modification_date: '2018-11-15' +modification_date: '2020-03-16' name: Common Ransomware Notes original_authors: - company: Splunk @@ -108,4 +108,4 @@ references: [] security_domain: endpoint spec_version: 2 type: splunk -version: '2.0' +version: '3.0' diff --git a/detections/create_local_admin_via_net.yml b/detections/create_local_admin_via_net.yml index c9cef4d0f5..6cc228236c 100644 --- a/detections/create_local_admin_via_net.yml +++ b/detections/create_local_admin_via_net.yml @@ -98,7 +98,7 @@ mappings: nist: - PR.PT - DE.CM -modification_date: '2018-11-15' +modification_date: '2020-03-16' name: Create local admin accounts using net.exe original_authors: - company: Splunk @@ -108,4 +108,4 @@ references: [] security_domain: endpoint spec_version: 2 type: splunk -version: '2.0' +version: '3.0' diff --git a/detections/dragonfly_schtasks.yml b/detections/dragonfly_schtasks.yml index 85aee43bdd..fdff4b89a9 100644 --- a/detections/dragonfly_schtasks.yml +++ b/detections/dragonfly_schtasks.yml @@ -96,7 +96,7 @@ mappings: - Scheduled Task nist: - PR.IP -modification_date: '2018-12-03' +modification_date: '2020-03-16' name: Scheduled Task Name Used by Dragonfly Threat Actors original_authors: - company: Splunk @@ -106,4 +106,4 @@ references: [] security_domain: endpoint spec_version: 2 type: splunk -version: '2.0' +version: '3.0' diff --git a/detections/file_write_spikes.yml b/detections/file_write_spikes.yml index bce910283f..cdb8d28712 100644 --- a/detections/file_write_spikes.yml +++ b/detections/file_write_spikes.yml @@ -96,7 +96,7 @@ mappings: - Execution nist: - DE.CM -modification_date: '2018-12-03' +modification_date: '2020-03-16' name: Spike in File Writes original_authors: - company: Splunk @@ -106,4 +106,4 @@ references: [] security_domain: endpoint spec_version: 2 type: splunk -version: '2.0' +version: '3.0' diff --git a/detections/lnk_executing_a_process.yml b/detections/lnk_executing_a_process.yml index a10a666df6..5288ef531c 100644 --- a/detections/lnk_executing_a_process.yml +++ b/detections/lnk_executing_a_process.yml @@ -81,7 +81,7 @@ mappings: nist: - ID.AM - PR.DS -modification_date: '2019-04-29' +modification_date: '2020-03-16' name: Suspicious LNK file launching a process original_authors: - company: Splunk @@ -91,4 +91,4 @@ responses: [] security_domain: network spec_version: 2 type: splunk -version: '1.0' +version: '2.0' diff --git a/detections/outlook_writing_zip.yml b/detections/outlook_writing_zip.yml index 55fa6ae78b..fa463ab8ef 100644 --- a/detections/outlook_writing_zip.yml +++ b/detections/outlook_writing_zip.yml @@ -89,7 +89,7 @@ mappings: nist: - ID.AM - PR.DS -modification_date: '2019-04-29' +modification_date: '2020-03-16' name: Detect Oulook.exe writing a .zip file original_authors: - company: Splunk @@ -99,4 +99,4 @@ responses: [] security_domain: network spec_version: 2 type: splunk -version: '1.0' +version: '2.0' diff --git a/detections/rare_executables_on_endpoint.yml b/detections/rare_executables_on_endpoint.yml index 541d99d101..82ce6103d9 100644 --- a/detections/rare_executables_on_endpoint.yml +++ b/detections/rare_executables_on_endpoint.yml @@ -111,7 +111,7 @@ mappings: - PR.PT - PR.DS - DE.CM -modification_date: '2018-10-30' +modification_date: '2020-03-16' name: Detect Rare Executables original_authors: - company: Splunk @@ -121,4 +121,4 @@ references: [] security_domain: endpoint spec_version: 2 type: splunk -version: '4.0' +version: '5.0' diff --git a/detections/suspicious_reg_process.yml b/detections/suspicious_reg_process.yml index 7d0c80da4b..3d511293b6 100644 --- a/detections/suspicious_reg_process.yml +++ b/detections/suspicious_reg_process.yml @@ -104,7 +104,7 @@ mappings: - Disabling Security Tools nist: - DE.CM -modification_date: '2019-03-01' +modification_date: '2020-03-16' name: Suspicious Reg.exe Process original_authors: - company: Splunk @@ -115,4 +115,4 @@ references: security_domain: endpoint spec_version: 2 type: splunk -version: '2.0' +version: '3.0' diff --git a/detections/uncommon_processes.yml b/detections/uncommon_processes.yml index 5fc33b44ca..5b3232f774 100644 --- a/detections/uncommon_processes.yml +++ b/detections/uncommon_processes.yml @@ -99,7 +99,7 @@ mappings: nist: - ID.AM - PR.DS -modification_date: '2019-04-01' +modification_date: '2020-03-16' name: Uncommon Processes On Endpoint original_authors: - company: Splunk @@ -109,4 +109,4 @@ references: [] security_domain: endpoint spec_version: 2 type: splunk -version: '2.0' +version: '3.0' diff --git a/detections/unusually_long_commandlines.yml b/detections/unusually_long_commandlines.yml index 4a91ce70a9..cbebca5e07 100644 --- a/detections/unusually_long_commandlines.yml +++ b/detections/unusually_long_commandlines.yml @@ -99,7 +99,7 @@ mappings: nist: - PR.PT - DE.CM -modification_date: '2019-02-28' +modification_date: '2020-03-16' name: Unusually Long Command Line original_authors: - company: Splunk @@ -109,4 +109,4 @@ references: [] security_domain: endpoint spec_version: 2 type: splunk -version: '3.0' +version: '4.0' diff --git a/detections/wmi_process_launch.yml b/detections/wmi_process_launch.yml index d710abde5f..91f82dea31 100644 --- a/detections/wmi_process_launch.yml +++ b/detections/wmi_process_launch.yml @@ -96,7 +96,7 @@ mappings: - PR.AT - PR.AC - PR.IP -modification_date: '2019-02-28' +modification_date: '2020-03-16' name: Process Execution via WMI original_authors: - company: Splunk @@ -106,4 +106,4 @@ references: [] security_domain: endpoint spec_version: 2 type: splunk -version: '2.0' +version: '3.0' diff --git a/detections/wmi_script_execution.yml b/detections/wmi_script_execution.yml index 25a855643f..6af5245b33 100644 --- a/detections/wmi_script_execution.yml +++ b/detections/wmi_script_execution.yml @@ -96,7 +96,7 @@ mappings: - PR.AT - PR.AC - PR.IP -modification_date: '2019-03-01' +modification_date: '2020-03-16' name: Script Execution via WMI original_authors: - company: Splunk @@ -106,4 +106,4 @@ references: [] security_domain: endpoint spec_version: 2 type: splunk -version: '2.0' +version: '3.0'