Branch was auto-updated.

This commit is contained in:
Bhavin Patel
2021-10-15 10:33:17 -07:00
committed by GitHub
83 changed files with 107 additions and 19 deletions
@@ -47,6 +47,7 @@ tags:
in host $dest$
mitre_attack_id:
- T1546.012
- T1546
nist:
- PR.PT
- DE.CM
@@ -35,6 +35,7 @@ tags:
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1218
- T1218.010
product:
- Splunk Enterprise
@@ -50,6 +50,7 @@ tags:
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk.
mitre_attack_id:
- T1218
- T1218.011
observable:
- name: user
@@ -52,6 +52,7 @@ tags:
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk.
mitre_attack_id:
- T1218
- T1218.011
observable:
- name: user
@@ -38,6 +38,7 @@ tags:
message: rundll32 process $process_name$ having a dns query to $QueryName$ in host
$Computer$
mitre_attack_id:
- T1218
- T1218.011
observable:
- name: Computer
@@ -38,6 +38,7 @@ tags:
- Exploitation
message: process $process_name$ with cmdline $process$ in host $dest$
mitre_attack_id:
- T1218
- T1218.011
observable:
- name: dest
@@ -36,6 +36,7 @@ tags:
- Exploitation
message: rundll32 process $process_name$ drops a file $TargetFilename$ in host $dest$
mitre_attack_id:
- T1218
- T1218.011
observable:
- name: Computer
@@ -54,6 +54,7 @@ tags:
message: A rundll32 process $process_name$ with no commandline argument like this
process commandline $process$ in host $dest$
mitre_attack_id:
- T1218
- T1218.011
observable:
- name: dest
@@ -43,6 +43,7 @@ tags:
message: A rundll32 process $process_name$ with ordinal parameter like this process
commandline $process$ in host $dest$
mitre_attack_id:
- T1218
- T1218.011
nist:
- PR.PT
@@ -46,6 +46,7 @@ tags:
message: A process $process_name$ with wake on LAN commandline $process$ in host
$dest$
mitre_attack_id:
- T1059
- T1059.003
observable:
- name: dest
@@ -42,6 +42,7 @@ tags:
attempting to gain access to credentials on $dest$ by user $user$.
mitre_attack_id:
- T1003.002
- T1003
observable:
- name: user
type: User
@@ -49,6 +49,7 @@ tags:
services in host $dest$
mitre_attack_id:
- T1543.003
- T1543
nist:
- PR.IP
- PR.PT
@@ -45,6 +45,7 @@ tags:
message: process $Image$ create a file $TargetFilename$ in host $Computer$
mitre_attack_id:
- T1087.002
- T1087
observable:
- name: Computer
type: Hostname
@@ -45,6 +45,7 @@ tags:
$process$ in host $dest$
mitre_attack_id:
- T1053.005
- T1053
nist:
- PR.IP
observable:
@@ -46,6 +46,7 @@ tags:
in host $dest$
mitre_attack_id:
- T1053.005
- T1053
nist:
- PR.IP
observable:
@@ -45,6 +45,7 @@ tags:
in host $dest$
mitre_attack_id:
- T1053.005
- T1053
nist:
- PR.IP
observable:
@@ -36,6 +36,7 @@ tags:
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1546
- T1546.002
product:
- Splunk Enterprise
+1
View File
@@ -44,6 +44,7 @@ tags:
path $registry_value_name$ in $dest$
mitre_attack_id:
- T1548.002
- T1548
observable:
- name: dest
type: Hostname
@@ -42,6 +42,7 @@ tags:
to dump credentials in host $dest$
mitre_attack_id:
- T1003.003
- T1003
observable:
- name: dest
type: Hostname
@@ -46,6 +46,7 @@ tags:
message: A registry modification in $registry_path$ with reg key $registry_key_name$
and reg value $registry_value_name$ in host $dest$
mitre_attack_id:
- T1059
- T1059.001
nist:
- DE.CM
@@ -43,6 +43,7 @@ tags:
message: A process that possibly write shim database in $file_path$ in host $dest$
mitre_attack_id:
- T1546.011
- T1546
nist:
- DE.CM
observable:
@@ -44,6 +44,7 @@ tags:
$dest$
mitre_attack_id:
- T1546.011
- T1546
nist:
- DE.CM
observable:
@@ -40,6 +40,7 @@ tags:
message: A user account created or delete shortly in host $dest$
mitre_attack_id:
- T1136.001
- T1136
nist:
- PR.IP
observable:
@@ -42,6 +42,7 @@ tags:
path $registry_value_name$ in $dest$
mitre_attack_id:
- T1548.002
- T1548
observable:
- name: dest
type: Hostname
@@ -40,6 +40,7 @@ tags:
- Actions on Objectives
message: A suspicious process $process_name$ with single letter in host $dest$
mitre_attack_id:
- T1204
- T1204.002
nist:
- ID.AM
@@ -47,6 +47,7 @@ tags:
$dest$
mitre_attack_id:
- T1548.002
- T1548
observable:
- name: dest
type: Hostname
@@ -45,6 +45,7 @@ tags:
in host $dest$
mitre_attack_id:
- T1548.002
- T1548
observable:
- name: dest
type: Hostname
@@ -48,6 +48,7 @@ tags:
This behavior is suspicious and related to PrintNightmare.
mitre_attack_id:
- T1547.012
- T1547
observable:
- name: dest
type: Endpoint
@@ -39,6 +39,7 @@ tags:
on endpoint $Computer$. This behavior is suspicious and related to PrintNightmare.
mitre_attack_id:
- T1547.012
- T1547
observable:
- name: Computer
type: Endpoint
@@ -49,6 +49,7 @@ tags:
$dest$. This behavior is suspicious and related to PrintNightmare.
mitre_attack_id:
- T1547.012
- T1547
observable:
- name: dest
type: Endpoint
@@ -45,6 +45,7 @@ tags:
$dest$. This behavior is suspicious and related to PrintNightmare.
mitre_attack_id:
- T1547.012
- T1547
observable:
- name: dest
type: Endpoint
@@ -45,6 +45,7 @@ tags:
via command $cmd_line$
mitre_attack_id:
- T1003.003
- T1003
nist:
- DE.CM
observable:
@@ -47,6 +47,7 @@ tags:
command $cmd_line$
mitre_attack_id:
- T1558.003
- T1558
nist:
- DE.CM
observable:
@@ -47,6 +47,7 @@ tags:
Operation is performed at the device $dest_device_id$, by the account $dest_user_id$
via command $cmd_line$
mitre_attack_id:
- T1550
- T1550.002
nist:
- PR.PT
@@ -63,6 +63,7 @@ tags:
Pass the Hash techniques. Operation is performed via credentials of the account
$dest_user_id$ and observed by the destination device $dest_device_id$
mitre_attack_id:
- T1550
- T1550.002
nist:
- PR.PT
@@ -65,6 +65,7 @@ tags:
Pass the Hash techniques. Operation is performed via credentials of the account
$dest_user_id$ and observed by the logging device $origin_device_id$
mitre_attack_id:
- T1550
- T1550.002
nist:
- PR.PT
@@ -51,14 +51,15 @@ tags:
mounted drives or other operating system elements. Operation is performed at the
device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
mitre_attack_id:
- T1007
- T1012
- T1046
- T1047
- T1057
- T1083
- T1518
- T1592.002
- T1046
- T1012
- T1007
- T1047
- T1592
- T1518
nist:
- PR.AC
- PR.IP
@@ -44,9 +44,10 @@ tags:
is performed at the device $dest_device_id$, by the account $dest_user_id$ via
command $cmd_line$
mitre_attack_id:
- T1021.002
- T1135
- T1021
- T1039
- T1135
- T1021.002
nist:
- PR.AC
- PR.IP
@@ -48,9 +48,10 @@ tags:
is performed at the device $dest_device_id$, by the account $dest_user_id$ via
command $cmd_line$
mitre_attack_id:
- T1021.002
- T1135
- T1021
- T1039
- T1135
- T1021.002
nist:
- PR.AC
- PR.IP
@@ -48,9 +48,10 @@ tags:
details such as DNS data, proxies, or ongoing RDP connections. Operation is performed
at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
mitre_attack_id:
- T1021.002
- T1135
- T1021
- T1039
- T1135
- T1021.002
nist:
- PR.AC
- PR.IP
@@ -45,12 +45,14 @@ tags:
is performed at the device $dest_device_id$, by the account $dest_user_id$ via
command $cmd_line$
mitre_attack_id:
- T1589.001
- T1590.001
- T1590.003
- T1068
- T1078
- T1098
- T1590.001
- T1078
- T1589.001
- T1590
- T1068
- T1589
- T1590.003
nist:
- PR.AC
- PR.IP
@@ -42,8 +42,10 @@ tags:
is performed at the device $dest_device_id$, by the account $dest_user_id$ via
command $cmd_line$
mitre_attack_id:
- T1595.002
- T1592.002
- T1595.002
- T1592
- T1595
nist:
- PR.AC
- PR.IP
@@ -49,6 +49,7 @@ tags:
message: A wevtutil process $process_name$ with commandline $cmd_line$ to clear
event logs in host $dest_device_id$
mitre_attack_id:
- T1070
- T1070.001
observable:
- name: dest_device_id
@@ -45,6 +45,7 @@ tags:
message: A wevtutil process $process_name$ with commandline $cmd_line$ to disable
event logs in host $dest_device_id$
mitre_attack_id:
- T1070
- T1070.001
observable:
- name: dest_device_id
@@ -41,6 +41,7 @@ tags:
$registry_value_name$ on $dest$
mitre_attack_id:
- T1547.001
- T1547
observable:
- name: dest
type: Endpoint
@@ -44,6 +44,7 @@ tags:
message: Suspicious driver $ImageLoaded$ on $Computer$
mitre_attack_id:
- T1543.003
- T1543
observable:
- name: Computer
type: Endpoint
@@ -46,6 +46,7 @@ tags:
- Actions on Objectives
message: The Windows Event Log Service shutdown on $ComputerName$
mitre_attack_id:
- T1070
- T1070.001
nist:
- DE.DP
@@ -40,6 +40,7 @@ tags:
- Exploitation
message: regsvr32 process $process_name$ with commandline $process$ in host $dest$
mitre_attack_id:
- T1218
- T1218.010
observable:
- name: dest
@@ -39,6 +39,7 @@ tags:
- Exploitation
message: rundll32 process $process_name$ with commandline $process$ in host $dest$
mitre_attack_id:
- T1218
- T1218.011
observable:
- name: dest
@@ -51,6 +51,7 @@ tags:
message: Suspicious renamed microsoft.workflow.compiler.exe binary ran on $dest$
by $user$
mitre_attack_id:
- T1036
- T1127
- T1036.003
nist:
@@ -51,8 +51,10 @@ tags:
- Exploitation
message: Msbuild.exe ran from an uncommon path on $dest$ execyted by $user$
mitre_attack_id:
- T1127.001
- T1036
- T1127
- T1036.003
- T1127.001
nist:
- PR.PT
- DE.CM
@@ -49,8 +49,10 @@ tags:
- Exploitation
message: Suspicious renamed msbuild.exe binary ran on $dest$ by $user$
mitre_attack_id:
- T1127.001
- T1036
- T1127
- T1036.003
- T1127.001
nist:
- PR.PT
- DE.CM
@@ -48,6 +48,7 @@ tags:
- Exploitation
message: Suspicious msbuild.exe process executed on $dest$ by $user$
mitre_attack_id:
- T1127
- T1127.001
nist:
- PR.PT
@@ -47,6 +47,7 @@ tags:
- Exploitation
message: suspicious mshta child process detected on host $dest$ by user $user$.
mitre_attack_id:
- T1218
- T1218.005
nist:
- PR.PT
@@ -46,6 +46,7 @@ tags:
- Exploitation
message: mshta.exe spawned by wmiprvse.exe on $dest$
mitre_attack_id:
- T1218
- T1218.005
nist:
- PR.PT
@@ -56,6 +56,7 @@ tags:
message: Suspicious $Processes.process_path.file_path$ process potentially loading
malicious code
mitre_attack_id:
- T1218
- T1218.010
nist:
- DE.CM
@@ -55,6 +55,7 @@ tags:
message: $Processes.process_path.file_path$ process potentially loading malicious
code
mitre_attack_id:
- T1218
- T1218.011
nist:
- PR.PT
@@ -39,6 +39,7 @@ tags:
- Exploitation
message: rundll32 process $process_name$ with commandline $process$ in host $dest$
mitre_attack_id:
- T1218
- T1218.011
observable:
- name: dest
@@ -50,6 +50,8 @@ tags:
- Actions on Objectives
message: Suspicious renamed rundll32.exe binary ran on $dest$ by $user$
mitre_attack_id:
- T1218
- T1036
- T1218.011
- T1036.003
nist:
@@ -56,6 +56,7 @@ tags:
- Actions on Objectives
message: rundll32.exe running with suspicious parameters on $dest$
mitre_attack_id:
- T1218
- T1218.011
nist:
- PR.PT
@@ -52,6 +52,7 @@ tags:
message: Suspicious rundll32.exe process with no command line arguments executed
on $dest$ by $user$
mitre_attack_id:
- T1218
- T1218.011
nist:
- PR.PT
@@ -47,6 +47,7 @@ tags:
message: Suspicious scheduled task registered on $dest$
mitre_attack_id:
- T1053.005
- T1053
observable:
- name: dest
type: Endpoint
@@ -53,6 +53,7 @@ tags:
- Actions on Objectives
message: System process running from unexpected location on $dest$
mitre_attack_id:
- T1036
- T1036.003
nist:
- PR.PT
@@ -37,6 +37,7 @@ tags:
- Exploitation
mitre_attack_id:
- T1547.003
- T1547
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -42,6 +42,7 @@ tags:
with EventCode $EventCode$
mitre_attack_id:
- T1548.002
- T1548
observable:
- name: Computer
type: Hostname
@@ -37,6 +37,7 @@ tags:
message: The following module $ImageLoaded$ was loaded by a non-standard application
on endpoint $Computer$ by user $user$.
mitre_attack_id:
- T1218
- T1218.003
observable:
- name: user
@@ -39,6 +39,7 @@ tags:
message: process $process_name$ with a cmdline $process$ in host $dest$
mitre_attack_id:
- T1218.007
- T1218
observable:
- name: dest
type: Hostname
@@ -43,6 +43,7 @@ tags:
message: Possible Sysmon filter driver unloading on $dest$
mitre_attack_id:
- T1562.001
- T1562
nist:
- DE.CM
observable:
@@ -50,6 +50,7 @@ tags:
- Exploitation
message: Possible Web Shell execution on $dest$
mitre_attack_id:
- T1505
- T1505.003
observable:
- name: dest
@@ -38,6 +38,7 @@ tags:
- Exploitation
message: Suspicious COM Object Execution on $Computer$
mitre_attack_id:
- T1218
- T1218.003
observable:
- name: Computer
@@ -44,6 +44,7 @@ tags:
- Exploitation
message: Wermgr.exe process connecting IP location web services on $ComputerName$
mitre_attack_id:
- T1590
- T1590.005
observable:
- name: ComputerName
@@ -46,6 +46,7 @@ tags:
message: Windows DisableAntiSpyware registry key set to 'disabled' on $dest$
mitre_attack_id:
- T1562.001
- T1562
nist:
- PR.PT
- DE.CM
@@ -46,6 +46,7 @@ tags:
- Actions on Objectives
message: Windows event logs cleared on $dest$ via EventCode $EventCode$
mitre_attack_id:
- T1070
- T1070.001
nist:
- DE.DP
@@ -62,6 +62,7 @@ tags:
by the following command: $Command$'
mitre_attack_id:
- T1053.005
- T1053
observable:
- name: dest
type: Endpoint
@@ -63,6 +63,7 @@ tags:
by the following command: $Command$'
mitre_attack_id:
- T1053.005
- T1053
observable:
- name: dest
type: Endpoint
@@ -45,6 +45,7 @@ tags:
message: '$parent_process_name$ on $dest$ by $user$ launched command: $process_name$
which is very common in spearphishing attacks.'
mitre_attack_id:
- T1566
- T1566.001
observable:
- name: dest
@@ -47,6 +47,7 @@ tags:
message: '$parent_process_name$ on $dest$ by $user$ launched the following powershell
process: $process_name$ which is very common in spearphishing attacks'
mitre_attack_id:
- T1566
- T1566.001
observable:
- name: dest
@@ -44,6 +44,7 @@ tags:
- Exploitation
message: User $user$ on $dest$ spawned Windows Script Host from Winword.exe
mitre_attack_id:
- T1566
- T1566.001
observable:
- name: dest
@@ -61,6 +61,7 @@ tags:
$filter$. Consumer: $Consumer$. EventCode: $EventCode$'
mitre_attack_id:
- T1546.003
- T1546
nist:
- PR.PT
- PR.AT
@@ -44,6 +44,7 @@ tags:
- Reconnaissance
message: Local group discovery on $dest$ by $user$.
mitre_attack_id:
- T1069
- T1069.001
observable:
- name: dest
@@ -38,6 +38,7 @@ tags:
message: $user$ dropped or created an executable file in known sensitive SMB share. Share
name=$Share_Name$, Target name=$Relative_Target_Name$, and Access mask=$Access_Mask$
mitre_attack_id:
- T1021
- T1021.002
observable:
- name: user
@@ -43,6 +43,7 @@ tags:
path $registry_value_name$ in $dest$
mitre_attack_id:
- T1548.002
- T1548
observable:
- name: dest
type: Hostname
@@ -36,6 +36,7 @@ tags:
message: A driver $ImageLoaded$ related to xmrig crytominer loaded in host $Computer$
mitre_attack_id:
- T1543.003
- T1543
observable:
- name: Computer
type: Hostname