mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -47,6 +47,7 @@ tags:
|
||||
in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1546.012
|
||||
- T1546
|
||||
nist:
|
||||
- PR.PT
|
||||
- DE.CM
|
||||
|
||||
@@ -35,6 +35,7 @@ tags:
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.010
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -50,6 +50,7 @@ tags:
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.011
|
||||
observable:
|
||||
- name: user
|
||||
|
||||
@@ -52,6 +52,7 @@ tags:
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.011
|
||||
observable:
|
||||
- name: user
|
||||
|
||||
@@ -38,6 +38,7 @@ tags:
|
||||
message: rundll32 process $process_name$ having a dns query to $QueryName$ in host
|
||||
$Computer$
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.011
|
||||
observable:
|
||||
- name: Computer
|
||||
|
||||
@@ -38,6 +38,7 @@ tags:
|
||||
- Exploitation
|
||||
message: process $process_name$ with cmdline $process$ in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.011
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -36,6 +36,7 @@ tags:
|
||||
- Exploitation
|
||||
message: rundll32 process $process_name$ drops a file $TargetFilename$ in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.011
|
||||
observable:
|
||||
- name: Computer
|
||||
|
||||
@@ -54,6 +54,7 @@ tags:
|
||||
message: A rundll32 process $process_name$ with no commandline argument like this
|
||||
process commandline $process$ in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.011
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -43,6 +43,7 @@ tags:
|
||||
message: A rundll32 process $process_name$ with ordinal parameter like this process
|
||||
commandline $process$ in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.011
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -46,6 +46,7 @@ tags:
|
||||
message: A process $process_name$ with wake on LAN commandline $process$ in host
|
||||
$dest$
|
||||
mitre_attack_id:
|
||||
- T1059
|
||||
- T1059.003
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -42,6 +42,7 @@ tags:
|
||||
attempting to gain access to credentials on $dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1003.002
|
||||
- T1003
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -49,6 +49,7 @@ tags:
|
||||
services in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1543.003
|
||||
- T1543
|
||||
nist:
|
||||
- PR.IP
|
||||
- PR.PT
|
||||
|
||||
@@ -45,6 +45,7 @@ tags:
|
||||
message: process $Image$ create a file $TargetFilename$ in host $Computer$
|
||||
mitre_attack_id:
|
||||
- T1087.002
|
||||
- T1087
|
||||
observable:
|
||||
- name: Computer
|
||||
type: Hostname
|
||||
|
||||
@@ -45,6 +45,7 @@ tags:
|
||||
$process$ in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1053.005
|
||||
- T1053
|
||||
nist:
|
||||
- PR.IP
|
||||
observable:
|
||||
|
||||
@@ -46,6 +46,7 @@ tags:
|
||||
in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1053.005
|
||||
- T1053
|
||||
nist:
|
||||
- PR.IP
|
||||
observable:
|
||||
|
||||
@@ -45,6 +45,7 @@ tags:
|
||||
in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1053.005
|
||||
- T1053
|
||||
nist:
|
||||
- PR.IP
|
||||
observable:
|
||||
|
||||
@@ -36,6 +36,7 @@ tags:
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
- T1546
|
||||
- T1546.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -44,6 +44,7 @@ tags:
|
||||
path $registry_value_name$ in $dest$
|
||||
mitre_attack_id:
|
||||
- T1548.002
|
||||
- T1548
|
||||
observable:
|
||||
- name: dest
|
||||
type: Hostname
|
||||
|
||||
@@ -42,6 +42,7 @@ tags:
|
||||
to dump credentials in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1003.003
|
||||
- T1003
|
||||
observable:
|
||||
- name: dest
|
||||
type: Hostname
|
||||
|
||||
+1
@@ -46,6 +46,7 @@ tags:
|
||||
message: A registry modification in $registry_path$ with reg key $registry_key_name$
|
||||
and reg value $registry_value_name$ in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1059
|
||||
- T1059.001
|
||||
nist:
|
||||
- DE.CM
|
||||
|
||||
@@ -43,6 +43,7 @@ tags:
|
||||
message: A process that possibly write shim database in $file_path$ in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1546.011
|
||||
- T1546
|
||||
nist:
|
||||
- DE.CM
|
||||
observable:
|
||||
|
||||
@@ -44,6 +44,7 @@ tags:
|
||||
$dest$
|
||||
mitre_attack_id:
|
||||
- T1546.011
|
||||
- T1546
|
||||
nist:
|
||||
- DE.CM
|
||||
observable:
|
||||
|
||||
@@ -40,6 +40,7 @@ tags:
|
||||
message: A user account created or delete shortly in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1136.001
|
||||
- T1136
|
||||
nist:
|
||||
- PR.IP
|
||||
observable:
|
||||
|
||||
@@ -42,6 +42,7 @@ tags:
|
||||
path $registry_value_name$ in $dest$
|
||||
mitre_attack_id:
|
||||
- T1548.002
|
||||
- T1548
|
||||
observable:
|
||||
- name: dest
|
||||
type: Hostname
|
||||
|
||||
@@ -40,6 +40,7 @@ tags:
|
||||
- Actions on Objectives
|
||||
message: A suspicious process $process_name$ with single letter in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1204
|
||||
- T1204.002
|
||||
nist:
|
||||
- ID.AM
|
||||
|
||||
@@ -47,6 +47,7 @@ tags:
|
||||
$dest$
|
||||
mitre_attack_id:
|
||||
- T1548.002
|
||||
- T1548
|
||||
observable:
|
||||
- name: dest
|
||||
type: Hostname
|
||||
|
||||
@@ -45,6 +45,7 @@ tags:
|
||||
in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1548.002
|
||||
- T1548
|
||||
observable:
|
||||
- name: dest
|
||||
type: Hostname
|
||||
|
||||
@@ -48,6 +48,7 @@ tags:
|
||||
This behavior is suspicious and related to PrintNightmare.
|
||||
mitre_attack_id:
|
||||
- T1547.012
|
||||
- T1547
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
|
||||
@@ -39,6 +39,7 @@ tags:
|
||||
on endpoint $Computer$. This behavior is suspicious and related to PrintNightmare.
|
||||
mitre_attack_id:
|
||||
- T1547.012
|
||||
- T1547
|
||||
observable:
|
||||
- name: Computer
|
||||
type: Endpoint
|
||||
|
||||
@@ -49,6 +49,7 @@ tags:
|
||||
$dest$. This behavior is suspicious and related to PrintNightmare.
|
||||
mitre_attack_id:
|
||||
- T1547.012
|
||||
- T1547
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
|
||||
@@ -45,6 +45,7 @@ tags:
|
||||
$dest$. This behavior is suspicious and related to PrintNightmare.
|
||||
mitre_attack_id:
|
||||
- T1547.012
|
||||
- T1547
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
|
||||
@@ -45,6 +45,7 @@ tags:
|
||||
via command $cmd_line$
|
||||
mitre_attack_id:
|
||||
- T1003.003
|
||||
- T1003
|
||||
nist:
|
||||
- DE.CM
|
||||
observable:
|
||||
|
||||
@@ -47,6 +47,7 @@ tags:
|
||||
command $cmd_line$
|
||||
mitre_attack_id:
|
||||
- T1558.003
|
||||
- T1558
|
||||
nist:
|
||||
- DE.CM
|
||||
observable:
|
||||
|
||||
@@ -47,6 +47,7 @@ tags:
|
||||
Operation is performed at the device $dest_device_id$, by the account $dest_user_id$
|
||||
via command $cmd_line$
|
||||
mitre_attack_id:
|
||||
- T1550
|
||||
- T1550.002
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -63,6 +63,7 @@ tags:
|
||||
Pass the Hash techniques. Operation is performed via credentials of the account
|
||||
$dest_user_id$ and observed by the destination device $dest_device_id$
|
||||
mitre_attack_id:
|
||||
- T1550
|
||||
- T1550.002
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -65,6 +65,7 @@ tags:
|
||||
Pass the Hash techniques. Operation is performed via credentials of the account
|
||||
$dest_user_id$ and observed by the logging device $origin_device_id$
|
||||
mitre_attack_id:
|
||||
- T1550
|
||||
- T1550.002
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
+6
-5
@@ -51,14 +51,15 @@ tags:
|
||||
mounted drives or other operating system elements. Operation is performed at the
|
||||
device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
|
||||
mitre_attack_id:
|
||||
- T1007
|
||||
- T1012
|
||||
- T1046
|
||||
- T1047
|
||||
- T1057
|
||||
- T1083
|
||||
- T1518
|
||||
- T1592.002
|
||||
- T1046
|
||||
- T1012
|
||||
- T1007
|
||||
- T1047
|
||||
- T1592
|
||||
- T1518
|
||||
nist:
|
||||
- PR.AC
|
||||
- PR.IP
|
||||
|
||||
@@ -44,9 +44,10 @@ tags:
|
||||
is performed at the device $dest_device_id$, by the account $dest_user_id$ via
|
||||
command $cmd_line$
|
||||
mitre_attack_id:
|
||||
- T1021.002
|
||||
- T1135
|
||||
- T1021
|
||||
- T1039
|
||||
- T1135
|
||||
- T1021.002
|
||||
nist:
|
||||
- PR.AC
|
||||
- PR.IP
|
||||
|
||||
@@ -48,9 +48,10 @@ tags:
|
||||
is performed at the device $dest_device_id$, by the account $dest_user_id$ via
|
||||
command $cmd_line$
|
||||
mitre_attack_id:
|
||||
- T1021.002
|
||||
- T1135
|
||||
- T1021
|
||||
- T1039
|
||||
- T1135
|
||||
- T1021.002
|
||||
nist:
|
||||
- PR.AC
|
||||
- PR.IP
|
||||
|
||||
@@ -48,9 +48,10 @@ tags:
|
||||
details such as DNS data, proxies, or ongoing RDP connections. Operation is performed
|
||||
at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
|
||||
mitre_attack_id:
|
||||
- T1021.002
|
||||
- T1135
|
||||
- T1021
|
||||
- T1039
|
||||
- T1135
|
||||
- T1021.002
|
||||
nist:
|
||||
- PR.AC
|
||||
- PR.IP
|
||||
|
||||
+7
-5
@@ -45,12 +45,14 @@ tags:
|
||||
is performed at the device $dest_device_id$, by the account $dest_user_id$ via
|
||||
command $cmd_line$
|
||||
mitre_attack_id:
|
||||
- T1589.001
|
||||
- T1590.001
|
||||
- T1590.003
|
||||
- T1068
|
||||
- T1078
|
||||
- T1098
|
||||
- T1590.001
|
||||
- T1078
|
||||
- T1589.001
|
||||
- T1590
|
||||
- T1068
|
||||
- T1589
|
||||
- T1590.003
|
||||
nist:
|
||||
- PR.AC
|
||||
- PR.IP
|
||||
|
||||
@@ -42,8 +42,10 @@ tags:
|
||||
is performed at the device $dest_device_id$, by the account $dest_user_id$ via
|
||||
command $cmd_line$
|
||||
mitre_attack_id:
|
||||
- T1595.002
|
||||
- T1592.002
|
||||
- T1595.002
|
||||
- T1592
|
||||
- T1595
|
||||
nist:
|
||||
- PR.AC
|
||||
- PR.IP
|
||||
|
||||
@@ -49,6 +49,7 @@ tags:
|
||||
message: A wevtutil process $process_name$ with commandline $cmd_line$ to clear
|
||||
event logs in host $dest_device_id$
|
||||
mitre_attack_id:
|
||||
- T1070
|
||||
- T1070.001
|
||||
observable:
|
||||
- name: dest_device_id
|
||||
|
||||
@@ -45,6 +45,7 @@ tags:
|
||||
message: A wevtutil process $process_name$ with commandline $cmd_line$ to disable
|
||||
event logs in host $dest_device_id$
|
||||
mitre_attack_id:
|
||||
- T1070
|
||||
- T1070.001
|
||||
observable:
|
||||
- name: dest_device_id
|
||||
|
||||
@@ -41,6 +41,7 @@ tags:
|
||||
$registry_value_name$ on $dest$
|
||||
mitre_attack_id:
|
||||
- T1547.001
|
||||
- T1547
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
|
||||
@@ -44,6 +44,7 @@ tags:
|
||||
message: Suspicious driver $ImageLoaded$ on $Computer$
|
||||
mitre_attack_id:
|
||||
- T1543.003
|
||||
- T1543
|
||||
observable:
|
||||
- name: Computer
|
||||
type: Endpoint
|
||||
|
||||
@@ -46,6 +46,7 @@ tags:
|
||||
- Actions on Objectives
|
||||
message: The Windows Event Log Service shutdown on $ComputerName$
|
||||
mitre_attack_id:
|
||||
- T1070
|
||||
- T1070.001
|
||||
nist:
|
||||
- DE.DP
|
||||
|
||||
@@ -40,6 +40,7 @@ tags:
|
||||
- Exploitation
|
||||
message: regsvr32 process $process_name$ with commandline $process$ in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.010
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -39,6 +39,7 @@ tags:
|
||||
- Exploitation
|
||||
message: rundll32 process $process_name$ with commandline $process$ in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.011
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -51,6 +51,7 @@ tags:
|
||||
message: Suspicious renamed microsoft.workflow.compiler.exe binary ran on $dest$
|
||||
by $user$
|
||||
mitre_attack_id:
|
||||
- T1036
|
||||
- T1127
|
||||
- T1036.003
|
||||
nist:
|
||||
|
||||
@@ -51,8 +51,10 @@ tags:
|
||||
- Exploitation
|
||||
message: Msbuild.exe ran from an uncommon path on $dest$ execyted by $user$
|
||||
mitre_attack_id:
|
||||
- T1127.001
|
||||
- T1036
|
||||
- T1127
|
||||
- T1036.003
|
||||
- T1127.001
|
||||
nist:
|
||||
- PR.PT
|
||||
- DE.CM
|
||||
|
||||
@@ -49,8 +49,10 @@ tags:
|
||||
- Exploitation
|
||||
message: Suspicious renamed msbuild.exe binary ran on $dest$ by $user$
|
||||
mitre_attack_id:
|
||||
- T1127.001
|
||||
- T1036
|
||||
- T1127
|
||||
- T1036.003
|
||||
- T1127.001
|
||||
nist:
|
||||
- PR.PT
|
||||
- DE.CM
|
||||
|
||||
@@ -48,6 +48,7 @@ tags:
|
||||
- Exploitation
|
||||
message: Suspicious msbuild.exe process executed on $dest$ by $user$
|
||||
mitre_attack_id:
|
||||
- T1127
|
||||
- T1127.001
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -47,6 +47,7 @@ tags:
|
||||
- Exploitation
|
||||
message: suspicious mshta child process detected on host $dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.005
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -46,6 +46,7 @@ tags:
|
||||
- Exploitation
|
||||
message: mshta.exe spawned by wmiprvse.exe on $dest$
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.005
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -56,6 +56,7 @@ tags:
|
||||
message: Suspicious $Processes.process_path.file_path$ process potentially loading
|
||||
malicious code
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.010
|
||||
nist:
|
||||
- DE.CM
|
||||
|
||||
@@ -55,6 +55,7 @@ tags:
|
||||
message: $Processes.process_path.file_path$ process potentially loading malicious
|
||||
code
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.011
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -39,6 +39,7 @@ tags:
|
||||
- Exploitation
|
||||
message: rundll32 process $process_name$ with commandline $process$ in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.011
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -50,6 +50,8 @@ tags:
|
||||
- Actions on Objectives
|
||||
message: Suspicious renamed rundll32.exe binary ran on $dest$ by $user$
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1036
|
||||
- T1218.011
|
||||
- T1036.003
|
||||
nist:
|
||||
|
||||
@@ -56,6 +56,7 @@ tags:
|
||||
- Actions on Objectives
|
||||
message: rundll32.exe running with suspicious parameters on $dest$
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.011
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -52,6 +52,7 @@ tags:
|
||||
message: Suspicious rundll32.exe process with no command line arguments executed
|
||||
on $dest$ by $user$
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.011
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -47,6 +47,7 @@ tags:
|
||||
message: Suspicious scheduled task registered on $dest$
|
||||
mitre_attack_id:
|
||||
- T1053.005
|
||||
- T1053
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
|
||||
@@ -53,6 +53,7 @@ tags:
|
||||
- Actions on Objectives
|
||||
message: System process running from unexpected location on $dest$
|
||||
mitre_attack_id:
|
||||
- T1036
|
||||
- T1036.003
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -37,6 +37,7 @@ tags:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
- T1547.003
|
||||
- T1547
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -42,6 +42,7 @@ tags:
|
||||
with EventCode $EventCode$
|
||||
mitre_attack_id:
|
||||
- T1548.002
|
||||
- T1548
|
||||
observable:
|
||||
- name: Computer
|
||||
type: Hostname
|
||||
|
||||
@@ -37,6 +37,7 @@ tags:
|
||||
message: The following module $ImageLoaded$ was loaded by a non-standard application
|
||||
on endpoint $Computer$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.003
|
||||
observable:
|
||||
- name: user
|
||||
|
||||
@@ -39,6 +39,7 @@ tags:
|
||||
message: process $process_name$ with a cmdline $process$ in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1218.007
|
||||
- T1218
|
||||
observable:
|
||||
- name: dest
|
||||
type: Hostname
|
||||
|
||||
@@ -43,6 +43,7 @@ tags:
|
||||
message: Possible Sysmon filter driver unloading on $dest$
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
nist:
|
||||
- DE.CM
|
||||
observable:
|
||||
|
||||
@@ -50,6 +50,7 @@ tags:
|
||||
- Exploitation
|
||||
message: Possible Web Shell execution on $dest$
|
||||
mitre_attack_id:
|
||||
- T1505
|
||||
- T1505.003
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -38,6 +38,7 @@ tags:
|
||||
- Exploitation
|
||||
message: Suspicious COM Object Execution on $Computer$
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.003
|
||||
observable:
|
||||
- name: Computer
|
||||
|
||||
@@ -44,6 +44,7 @@ tags:
|
||||
- Exploitation
|
||||
message: Wermgr.exe process connecting IP location web services on $ComputerName$
|
||||
mitre_attack_id:
|
||||
- T1590
|
||||
- T1590.005
|
||||
observable:
|
||||
- name: ComputerName
|
||||
|
||||
@@ -46,6 +46,7 @@ tags:
|
||||
message: Windows DisableAntiSpyware registry key set to 'disabled' on $dest$
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
nist:
|
||||
- PR.PT
|
||||
- DE.CM
|
||||
|
||||
@@ -46,6 +46,7 @@ tags:
|
||||
- Actions on Objectives
|
||||
message: Windows event logs cleared on $dest$ via EventCode $EventCode$
|
||||
mitre_attack_id:
|
||||
- T1070
|
||||
- T1070.001
|
||||
nist:
|
||||
- DE.DP
|
||||
|
||||
@@ -62,6 +62,7 @@ tags:
|
||||
by the following command: $Command$'
|
||||
mitre_attack_id:
|
||||
- T1053.005
|
||||
- T1053
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
|
||||
@@ -63,6 +63,7 @@ tags:
|
||||
by the following command: $Command$'
|
||||
mitre_attack_id:
|
||||
- T1053.005
|
||||
- T1053
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
|
||||
@@ -45,6 +45,7 @@ tags:
|
||||
message: '$parent_process_name$ on $dest$ by $user$ launched command: $process_name$
|
||||
which is very common in spearphishing attacks.'
|
||||
mitre_attack_id:
|
||||
- T1566
|
||||
- T1566.001
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -47,6 +47,7 @@ tags:
|
||||
message: '$parent_process_name$ on $dest$ by $user$ launched the following powershell
|
||||
process: $process_name$ which is very common in spearphishing attacks'
|
||||
mitre_attack_id:
|
||||
- T1566
|
||||
- T1566.001
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -44,6 +44,7 @@ tags:
|
||||
- Exploitation
|
||||
message: User $user$ on $dest$ spawned Windows Script Host from Winword.exe
|
||||
mitre_attack_id:
|
||||
- T1566
|
||||
- T1566.001
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -61,6 +61,7 @@ tags:
|
||||
$filter$. Consumer: $Consumer$. EventCode: $EventCode$'
|
||||
mitre_attack_id:
|
||||
- T1546.003
|
||||
- T1546
|
||||
nist:
|
||||
- PR.PT
|
||||
- PR.AT
|
||||
|
||||
@@ -44,6 +44,7 @@ tags:
|
||||
- Reconnaissance
|
||||
message: Local group discovery on $dest$ by $user$.
|
||||
mitre_attack_id:
|
||||
- T1069
|
||||
- T1069.001
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -38,6 +38,7 @@ tags:
|
||||
message: $user$ dropped or created an executable file in known sensitive SMB share. Share
|
||||
name=$Share_Name$, Target name=$Relative_Target_Name$, and Access mask=$Access_Mask$
|
||||
mitre_attack_id:
|
||||
- T1021
|
||||
- T1021.002
|
||||
observable:
|
||||
- name: user
|
||||
|
||||
@@ -43,6 +43,7 @@ tags:
|
||||
path $registry_value_name$ in $dest$
|
||||
mitre_attack_id:
|
||||
- T1548.002
|
||||
- T1548
|
||||
observable:
|
||||
- name: dest
|
||||
type: Hostname
|
||||
|
||||
@@ -36,6 +36,7 @@ tags:
|
||||
message: A driver $ImageLoaded$ related to xmrig crytominer loaded in host $Computer$
|
||||
mitre_attack_id:
|
||||
- T1543.003
|
||||
- T1543
|
||||
observable:
|
||||
- name: Computer
|
||||
type: Hostname
|
||||
|
||||
Reference in New Issue
Block a user