From af7ff4052e5f1f1b9d35f66696a68702573fbbc4 Mon Sep 17 00:00:00 2001 From: tccontre Date: Wed, 13 Oct 2021 11:24:10 +0200 Subject: [PATCH] CARS_UPDATE_MITRE_ID_B6 CARS_UPDATE_MITRE_ID_B3 --- .../registry_keys_used_for_privilege_escalation.yml | 1 + .../endpoint/regsvr32_silent_param_dll_loading.yml | 1 + detections/endpoint/rundll32_control_rundll_hunt.yml | 1 + ...dll32_control_rundll_world_writable_directory.yml | 1 + detections/endpoint/rundll32_dnsquery.yml | 1 + detections/endpoint/rundll32_lockworkstation.yml | 1 + .../rundll32_process_creating_exe_dll_files.yml | 1 + ...2_with_no_command_line_arguments_with_network.yml | 1 + .../endpoint/rundll_loading_dll_by_ordinal.yml | 1 + detections/endpoint/ryuk_wake_on_lan_command.yml | 1 + .../endpoint/sam_database_file_access_attempt.yml | 1 + .../sc_exe_manipulating_windows_services.yml | 1 + ..._change_by_app_connect_and_create_adsi_object.yml | 1 + .../scheduled_task_deleted_or_created_via_cmd.yml | 1 + .../schtasks_scheduling_job_on_remote_system.yml | 1 + .../endpoint/schtasks_used_for_forcing_a_reboot.yml | 1 + .../endpoint/screensaver_event_trigger_execution.yml | 1 + detections/endpoint/sdclt_uac_bypass.yml | 1 + .../secretdumps_offline_ntds_dumping_tool.yml | 1 + ...ll_execution_policy_to_unrestricted_or_bypass.yml | 1 + detections/endpoint/shim_database_file_creation.yml | 1 + ...abase_installation_with_suspicious_parameters.yml | 1 + detections/endpoint/short_lived_windows_accounts.yml | 1 + detections/endpoint/silentcleanup_uac_bypass.yml | 1 + .../endpoint/single_letter_process_on_endpoint.yml | 1 + detections/endpoint/slui_runas_elevated.yml | 1 + detections/endpoint/slui_spawning_a_process.yml | 1 + detections/endpoint/spoolsv_spawning_rundll32.yml | 1 + .../endpoint/spoolsv_suspicious_loaded_modules.yml | 1 + detections/endpoint/spoolsv_writing_a_dll.yml | 1 + .../endpoint/spoolsv_writing_a_dll___sysmon.yml | 1 + .../ssa___detect_dump_lsass_memory_using_comsvcs.yml | 1 + detections/endpoint/ssa___detect_kerberoasting.yml | 1 + detections/endpoint/ssa___detect_pass_hash.yml | 1 + .../endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml | 1 + .../ssa___ptt_pth_kerb_ntlm_origin_device.yml | 1 + ...ating_system_elements_via_powersploit_modules.yml | 11 ++++++----- ...a___recon_and_use_shares_via_mimikatz_modules.yml | 5 +++-- ..._recon_and_use_shares_via_powersploit_modules.yml | 5 +++-- ...___recon_connectivity_via_powersploit_modules.yml | 5 +++-- ...tial_stores_and_services_via_mimikatz_modules.yml | 12 +++++++----- ...recon_defensive_tools_via_powersploit_modules.yml | 4 +++- .../endpoint/ssa___wevtutil_usage_to_clear_logs.yml | 1 + .../ssa___wevtutil_usage_to_disable_logs.yml | 1 + .../endpoint/start_up_during_safe_mode_boot.yml | 1 + .../endpoint/suspicious_driver_loaded_path.yml | 1 + .../suspicious_event_log_service_behavior.yml | 1 + .../endpoint/suspicious_icedid_regsvr32_cmdline.yml | 1 + .../endpoint/suspicious_icedid_rundll32_cmdline.yml | 1 + ...suspicious_microsoft_workflow_compiler_rename.yml | 1 + detections/endpoint/suspicious_msbuild_path.yml | 4 +++- detections/endpoint/suspicious_msbuild_rename.yml | 4 +++- detections/endpoint/suspicious_msbuild_spawn.yml | 1 + .../endpoint/suspicious_mshta_child_process.yml | 1 + detections/endpoint/suspicious_mshta_spawn.yml | 1 + .../suspicious_regsvr32_register_suspicious_path.yml | 1 + .../suspicious_rundll32_dllregisterserver.yml | 1 + .../endpoint/suspicious_rundll32_plugininit.yml | 1 + detections/endpoint/suspicious_rundll32_rename.yml | 2 ++ detections/endpoint/suspicious_rundll32_startw.yml | 1 + ...cious_rundll32_with_no_command_line_arguments.yml | 1 + ...spicious_scheduled_task_from_public_directory.yml | 1 + ...ystem_processes_run_from_unexpected_locations.yml | 1 + .../endpoint/time_provider_persistence_registry.yml | 1 + .../endpoint/uac_bypass_mmc_load_unsigned_dll.yml | 1 + .../endpoint/uac_bypass_with_colorui_com_object.yml | 1 + detections/endpoint/uninstall_app_using_msiexec.yml | 1 + detections/endpoint/unload_sysmon_filter_driver.yml | 1 + detections/endpoint/w3wp_spawning_shell.yml | 1 + .../endpoint/wbemprox_com_object_execution.yml | 1 + ...r_process_connecting_to_ip_check_web_services.yml | 1 + .../endpoint/windows_disableantispyware_reg.yml | 1 + detections/endpoint/windows_event_log_cleared.yml | 1 + ...inevent_scheduled_task_created_to_spawn_shell.yml | 1 + ...ent_scheduled_task_created_within_public_path.yml | 1 + detections/endpoint/winword_spawning_cmd.yml | 1 + detections/endpoint/winword_spawning_powershell.yml | 1 + .../winword_spawning_windows_script_host.yml | 1 + .../wmi_permanent_event_subscription___sysmon.yml | 1 + detections/endpoint/wmic_group_discovery.yml | 1 + .../endpoint/write_executable_in_smb_share.yml | 1 + detections/endpoint/wsreset_uac_bypass.yml | 1 + detections/endpoint/xmrig_driver_loaded.yml | 1 + 83 files changed, 107 insertions(+), 19 deletions(-) diff --git a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml index e91f558ec6..111952d065 100644 --- a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml +++ b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml @@ -47,6 +47,7 @@ tags: in host $dest$ mitre_attack_id: - T1546.012 + - T1546 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/regsvr32_silent_param_dll_loading.yml b/detections/endpoint/regsvr32_silent_param_dll_loading.yml index d27c7425aa..0c3663c46e 100644 --- a/detections/endpoint/regsvr32_silent_param_dll_loading.yml +++ b/detections/endpoint/regsvr32_silent_param_dll_loading.yml @@ -35,6 +35,7 @@ tags: kill_chain_phases: - Exploitation mitre_attack_id: + - T1218 - T1218.010 product: - Splunk Enterprise diff --git a/detections/endpoint/rundll32_control_rundll_hunt.yml b/detections/endpoint/rundll32_control_rundll_hunt.yml index c9a4f1b93d..0007a75412 100644 --- a/detections/endpoint/rundll32_control_rundll_hunt.yml +++ b/detections/endpoint/rundll32_control_rundll_hunt.yml @@ -50,6 +50,7 @@ tags: message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk. mitre_attack_id: + - T1218 - T1218.011 observable: - name: user diff --git a/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml b/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml index b0f3f201d7..3acd837f63 100644 --- a/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml +++ b/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml @@ -52,6 +52,7 @@ tags: message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk. mitre_attack_id: + - T1218 - T1218.011 observable: - name: user diff --git a/detections/endpoint/rundll32_dnsquery.yml b/detections/endpoint/rundll32_dnsquery.yml index ca03bace5f..d542ef031f 100644 --- a/detections/endpoint/rundll32_dnsquery.yml +++ b/detections/endpoint/rundll32_dnsquery.yml @@ -38,6 +38,7 @@ tags: message: rundll32 process $process_name$ having a dns query to $QueryName$ in host $Computer$ mitre_attack_id: + - T1218 - T1218.011 observable: - name: Computer diff --git a/detections/endpoint/rundll32_lockworkstation.yml b/detections/endpoint/rundll32_lockworkstation.yml index e98876a8ed..f20d95d919 100644 --- a/detections/endpoint/rundll32_lockworkstation.yml +++ b/detections/endpoint/rundll32_lockworkstation.yml @@ -38,6 +38,7 @@ tags: - Exploitation message: process $process_name$ with cmdline $process$ in host $dest$ mitre_attack_id: + - T1218 - T1218.011 observable: - name: dest diff --git a/detections/endpoint/rundll32_process_creating_exe_dll_files.yml b/detections/endpoint/rundll32_process_creating_exe_dll_files.yml index 1a596c34d7..b23c0499f3 100644 --- a/detections/endpoint/rundll32_process_creating_exe_dll_files.yml +++ b/detections/endpoint/rundll32_process_creating_exe_dll_files.yml @@ -36,6 +36,7 @@ tags: - Exploitation message: rundll32 process $process_name$ drops a file $TargetFilename$ in host $dest$ mitre_attack_id: + - T1218 - T1218.011 observable: - name: Computer diff --git a/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml b/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml index e753e33958..e513b27287 100644 --- a/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml +++ b/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml @@ -54,6 +54,7 @@ tags: message: A rundll32 process $process_name$ with no commandline argument like this process commandline $process$ in host $dest$ mitre_attack_id: + - T1218 - T1218.011 observable: - name: dest diff --git a/detections/endpoint/rundll_loading_dll_by_ordinal.yml b/detections/endpoint/rundll_loading_dll_by_ordinal.yml index f60585c5a5..1a42db412b 100644 --- a/detections/endpoint/rundll_loading_dll_by_ordinal.yml +++ b/detections/endpoint/rundll_loading_dll_by_ordinal.yml @@ -43,6 +43,7 @@ tags: message: A rundll32 process $process_name$ with ordinal parameter like this process commandline $process$ in host $dest$ mitre_attack_id: + - T1218 - T1218.011 nist: - PR.PT diff --git a/detections/endpoint/ryuk_wake_on_lan_command.yml b/detections/endpoint/ryuk_wake_on_lan_command.yml index 63b690b819..3785dc0563 100644 --- a/detections/endpoint/ryuk_wake_on_lan_command.yml +++ b/detections/endpoint/ryuk_wake_on_lan_command.yml @@ -46,6 +46,7 @@ tags: message: A process $process_name$ with wake on LAN commandline $process$ in host $dest$ mitre_attack_id: + - T1059 - T1059.003 observable: - name: dest diff --git a/detections/endpoint/sam_database_file_access_attempt.yml b/detections/endpoint/sam_database_file_access_attempt.yml index fb1765f6ee..a082dff66f 100644 --- a/detections/endpoint/sam_database_file_access_attempt.yml +++ b/detections/endpoint/sam_database_file_access_attempt.yml @@ -42,6 +42,7 @@ tags: attempting to gain access to credentials on $dest$ by user $user$. mitre_attack_id: - T1003.002 + - T1003 observable: - name: user type: User diff --git a/detections/endpoint/sc_exe_manipulating_windows_services.yml b/detections/endpoint/sc_exe_manipulating_windows_services.yml index 85aa89544f..fe0205380e 100644 --- a/detections/endpoint/sc_exe_manipulating_windows_services.yml +++ b/detections/endpoint/sc_exe_manipulating_windows_services.yml @@ -49,6 +49,7 @@ tags: services in host $dest$ mitre_attack_id: - T1543.003 + - T1543 nist: - PR.IP - PR.PT diff --git a/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml b/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml index 808d5a3886..d627f66d3c 100644 --- a/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml +++ b/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml @@ -45,6 +45,7 @@ tags: message: process $Image$ create a file $TargetFilename$ in host $Computer$ mitre_attack_id: - T1087.002 + - T1087 observable: - name: Computer type: Hostname diff --git a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml index 44fa29fd2d..96a6b392d3 100644 --- a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml +++ b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml @@ -45,6 +45,7 @@ tags: $process$ in host $dest$ mitre_attack_id: - T1053.005 + - T1053 nist: - PR.IP observable: diff --git a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml index 11bbb12a20..11496da387 100644 --- a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml +++ b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml @@ -46,6 +46,7 @@ tags: in host $dest$ mitre_attack_id: - T1053.005 + - T1053 nist: - PR.IP observable: diff --git a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml index 8ee09e559f..c6fd3a72f5 100644 --- a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml +++ b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml @@ -45,6 +45,7 @@ tags: in host $dest$ mitre_attack_id: - T1053.005 + - T1053 nist: - PR.IP observable: diff --git a/detections/endpoint/screensaver_event_trigger_execution.yml b/detections/endpoint/screensaver_event_trigger_execution.yml index 00b8914da3..bc498612dd 100644 --- a/detections/endpoint/screensaver_event_trigger_execution.yml +++ b/detections/endpoint/screensaver_event_trigger_execution.yml @@ -36,6 +36,7 @@ tags: kill_chain_phases: - Exploitation mitre_attack_id: + - T1546 - T1546.002 product: - Splunk Enterprise diff --git a/detections/endpoint/sdclt_uac_bypass.yml b/detections/endpoint/sdclt_uac_bypass.yml index 45477c7d1c..db3b46956c 100644 --- a/detections/endpoint/sdclt_uac_bypass.yml +++ b/detections/endpoint/sdclt_uac_bypass.yml @@ -44,6 +44,7 @@ tags: path $registry_value_name$ in $dest$ mitre_attack_id: - T1548.002 + - T1548 observable: - name: dest type: Hostname diff --git a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml index 1c6c8d605f..e404794b9e 100644 --- a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml +++ b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml @@ -42,6 +42,7 @@ tags: to dump credentials in host $dest$ mitre_attack_id: - T1003.003 + - T1003 observable: - name: dest type: Hostname diff --git a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml index 4a007740e3..61f741ddab 100644 --- a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml +++ b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml @@ -46,6 +46,7 @@ tags: message: A registry modification in $registry_path$ with reg key $registry_key_name$ and reg value $registry_value_name$ in host $dest$ mitre_attack_id: + - T1059 - T1059.001 nist: - DE.CM diff --git a/detections/endpoint/shim_database_file_creation.yml b/detections/endpoint/shim_database_file_creation.yml index e59f84bc50..a29923fe90 100644 --- a/detections/endpoint/shim_database_file_creation.yml +++ b/detections/endpoint/shim_database_file_creation.yml @@ -43,6 +43,7 @@ tags: message: A process that possibly write shim database in $file_path$ in host $dest$ mitre_attack_id: - T1546.011 + - T1546 nist: - DE.CM observable: diff --git a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml index c2e6feecfd..6ac4dc6618 100644 --- a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml +++ b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml @@ -44,6 +44,7 @@ tags: $dest$ mitre_attack_id: - T1546.011 + - T1546 nist: - DE.CM observable: diff --git a/detections/endpoint/short_lived_windows_accounts.yml b/detections/endpoint/short_lived_windows_accounts.yml index bc0dfe52d2..41eaafaaab 100644 --- a/detections/endpoint/short_lived_windows_accounts.yml +++ b/detections/endpoint/short_lived_windows_accounts.yml @@ -40,6 +40,7 @@ tags: message: A user account created or delete shortly in host $dest$ mitre_attack_id: - T1136.001 + - T1136 nist: - PR.IP observable: diff --git a/detections/endpoint/silentcleanup_uac_bypass.yml b/detections/endpoint/silentcleanup_uac_bypass.yml index 61b5025568..bbd46535fb 100644 --- a/detections/endpoint/silentcleanup_uac_bypass.yml +++ b/detections/endpoint/silentcleanup_uac_bypass.yml @@ -42,6 +42,7 @@ tags: path $registry_value_name$ in $dest$ mitre_attack_id: - T1548.002 + - T1548 observable: - name: dest type: Hostname diff --git a/detections/endpoint/single_letter_process_on_endpoint.yml b/detections/endpoint/single_letter_process_on_endpoint.yml index f09df3de5b..48f1c3eba6 100644 --- a/detections/endpoint/single_letter_process_on_endpoint.yml +++ b/detections/endpoint/single_letter_process_on_endpoint.yml @@ -40,6 +40,7 @@ tags: - Actions on Objectives message: A suspicious process $process_name$ with single letter in host $dest$ mitre_attack_id: + - T1204 - T1204.002 nist: - ID.AM diff --git a/detections/endpoint/slui_runas_elevated.yml b/detections/endpoint/slui_runas_elevated.yml index 38830bc4cd..214b13ac1c 100644 --- a/detections/endpoint/slui_runas_elevated.yml +++ b/detections/endpoint/slui_runas_elevated.yml @@ -47,6 +47,7 @@ tags: $dest$ mitre_attack_id: - T1548.002 + - T1548 observable: - name: dest type: Hostname diff --git a/detections/endpoint/slui_spawning_a_process.yml b/detections/endpoint/slui_spawning_a_process.yml index 579685a0e7..da332eedf0 100644 --- a/detections/endpoint/slui_spawning_a_process.yml +++ b/detections/endpoint/slui_spawning_a_process.yml @@ -45,6 +45,7 @@ tags: in host $dest$ mitre_attack_id: - T1548.002 + - T1548 observable: - name: dest type: Hostname diff --git a/detections/endpoint/spoolsv_spawning_rundll32.yml b/detections/endpoint/spoolsv_spawning_rundll32.yml index 9fadebeb10..d60fa4a4f2 100644 --- a/detections/endpoint/spoolsv_spawning_rundll32.yml +++ b/detections/endpoint/spoolsv_spawning_rundll32.yml @@ -48,6 +48,7 @@ tags: This behavior is suspicious and related to PrintNightmare. mitre_attack_id: - T1547.012 + - T1547 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/spoolsv_suspicious_loaded_modules.yml b/detections/endpoint/spoolsv_suspicious_loaded_modules.yml index 0836ae7c82..85a54dbaed 100644 --- a/detections/endpoint/spoolsv_suspicious_loaded_modules.yml +++ b/detections/endpoint/spoolsv_suspicious_loaded_modules.yml @@ -39,6 +39,7 @@ tags: on endpoint $Computer$. This behavior is suspicious and related to PrintNightmare. mitre_attack_id: - T1547.012 + - T1547 observable: - name: Computer type: Endpoint diff --git a/detections/endpoint/spoolsv_writing_a_dll.yml b/detections/endpoint/spoolsv_writing_a_dll.yml index afc4984e1c..cf7150056b 100644 --- a/detections/endpoint/spoolsv_writing_a_dll.yml +++ b/detections/endpoint/spoolsv_writing_a_dll.yml @@ -49,6 +49,7 @@ tags: $dest$. This behavior is suspicious and related to PrintNightmare. mitre_attack_id: - T1547.012 + - T1547 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml b/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml index a46a5d2e9f..540559a44a 100644 --- a/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml +++ b/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml @@ -45,6 +45,7 @@ tags: $dest$. This behavior is suspicious and related to PrintNightmare. mitre_attack_id: - T1547.012 + - T1547 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml b/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml index 8a6d6373f9..9d797b74ee 100644 --- a/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml +++ b/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml @@ -45,6 +45,7 @@ tags: via command $cmd_line$ mitre_attack_id: - T1003.003 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/ssa___detect_kerberoasting.yml b/detections/endpoint/ssa___detect_kerberoasting.yml index 63b1c8a188..79d5759281 100644 --- a/detections/endpoint/ssa___detect_kerberoasting.yml +++ b/detections/endpoint/ssa___detect_kerberoasting.yml @@ -47,6 +47,7 @@ tags: command $cmd_line$ mitre_attack_id: - T1558.003 + - T1558 nist: - DE.CM observable: diff --git a/detections/endpoint/ssa___detect_pass_hash.yml b/detections/endpoint/ssa___detect_pass_hash.yml index 2267f6ffcd..49ae7ca771 100644 --- a/detections/endpoint/ssa___detect_pass_hash.yml +++ b/detections/endpoint/ssa___detect_pass_hash.yml @@ -47,6 +47,7 @@ tags: Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ mitre_attack_id: + - T1550 - T1550.002 nist: - PR.PT diff --git a/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml b/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml index ab890a2895..f65c51a9d1 100644 --- a/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml +++ b/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml @@ -63,6 +63,7 @@ tags: Pass the Hash techniques. Operation is performed via credentials of the account $dest_user_id$ and observed by the destination device $dest_device_id$ mitre_attack_id: + - T1550 - T1550.002 nist: - PR.PT diff --git a/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml b/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml index 82a5385966..1c6f185310 100644 --- a/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml +++ b/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml @@ -65,6 +65,7 @@ tags: Pass the Hash techniques. Operation is performed via credentials of the account $dest_user_id$ and observed by the logging device $origin_device_id$ mitre_attack_id: + - T1550 - T1550.002 nist: - PR.PT diff --git a/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml b/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml index 0aa1b3fb6a..a63cfbbb23 100644 --- a/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml @@ -51,14 +51,15 @@ tags: mounted drives or other operating system elements. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ mitre_attack_id: - - T1007 - - T1012 - - T1046 - - T1047 - T1057 - T1083 - - T1518 - T1592.002 + - T1046 + - T1012 + - T1007 + - T1047 + - T1592 + - T1518 nist: - PR.AC - PR.IP diff --git a/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml b/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml index 702f66a066..66d177f48b 100644 --- a/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml +++ b/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml @@ -44,9 +44,10 @@ tags: is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ mitre_attack_id: - - T1021.002 - - T1135 + - T1021 - T1039 + - T1135 + - T1021.002 nist: - PR.AC - PR.IP diff --git a/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml b/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml index 4d72993fc4..c98b38ae46 100644 --- a/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml @@ -48,9 +48,10 @@ tags: is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ mitre_attack_id: - - T1021.002 - - T1135 + - T1021 - T1039 + - T1135 + - T1021.002 nist: - PR.AC - PR.IP diff --git a/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml b/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml index 085c118f58..8fe5b4980a 100644 --- a/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml @@ -48,9 +48,10 @@ tags: details such as DNS data, proxies, or ongoing RDP connections. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ mitre_attack_id: - - T1021.002 - - T1135 + - T1021 - T1039 + - T1135 + - T1021.002 nist: - PR.AC - PR.IP diff --git a/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml b/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml index 5ab92c7f7a..84eef9576b 100644 --- a/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml +++ b/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml @@ -45,12 +45,14 @@ tags: is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ mitre_attack_id: - - T1589.001 - - T1590.001 - - T1590.003 - - T1068 - - T1078 - T1098 + - T1590.001 + - T1078 + - T1589.001 + - T1590 + - T1068 + - T1589 + - T1590.003 nist: - PR.AC - PR.IP diff --git a/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml b/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml index 130cb2e20b..511a1cb7c0 100644 --- a/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml @@ -42,8 +42,10 @@ tags: is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ mitre_attack_id: - - T1595.002 - T1592.002 + - T1595.002 + - T1592 + - T1595 nist: - PR.AC - PR.IP diff --git a/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml b/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml index cc9ace99c4..73a7fbd8bf 100644 --- a/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml +++ b/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml @@ -49,6 +49,7 @@ tags: message: A wevtutil process $process_name$ with commandline $cmd_line$ to clear event logs in host $dest_device_id$ mitre_attack_id: + - T1070 - T1070.001 observable: - name: dest_device_id diff --git a/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml b/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml index 24431d68eb..69d1c02046 100644 --- a/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml +++ b/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml @@ -45,6 +45,7 @@ tags: message: A wevtutil process $process_name$ with commandline $cmd_line$ to disable event logs in host $dest_device_id$ mitre_attack_id: + - T1070 - T1070.001 observable: - name: dest_device_id diff --git a/detections/endpoint/start_up_during_safe_mode_boot.yml b/detections/endpoint/start_up_during_safe_mode_boot.yml index 5f2664d98f..b4f49a32f1 100644 --- a/detections/endpoint/start_up_during_safe_mode_boot.yml +++ b/detections/endpoint/start_up_during_safe_mode_boot.yml @@ -41,6 +41,7 @@ tags: $registry_value_name$ on $dest$ mitre_attack_id: - T1547.001 + - T1547 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/suspicious_driver_loaded_path.yml b/detections/endpoint/suspicious_driver_loaded_path.yml index e9e8c99c7e..10a0bada0e 100644 --- a/detections/endpoint/suspicious_driver_loaded_path.yml +++ b/detections/endpoint/suspicious_driver_loaded_path.yml @@ -44,6 +44,7 @@ tags: message: Suspicious driver $ImageLoaded$ on $Computer$ mitre_attack_id: - T1543.003 + - T1543 observable: - name: Computer type: Endpoint diff --git a/detections/endpoint/suspicious_event_log_service_behavior.yml b/detections/endpoint/suspicious_event_log_service_behavior.yml index 4b2706e518..3e5b4f7ce8 100644 --- a/detections/endpoint/suspicious_event_log_service_behavior.yml +++ b/detections/endpoint/suspicious_event_log_service_behavior.yml @@ -46,6 +46,7 @@ tags: - Actions on Objectives message: The Windows Event Log Service shutdown on $ComputerName$ mitre_attack_id: + - T1070 - T1070.001 nist: - DE.DP diff --git a/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml b/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml index 198e2d21ea..2e9fe3108a 100644 --- a/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml +++ b/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml @@ -40,6 +40,7 @@ tags: - Exploitation message: regsvr32 process $process_name$ with commandline $process$ in host $dest$ mitre_attack_id: + - T1218 - T1218.010 observable: - name: dest diff --git a/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml b/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml index fa8eb14e8d..2c5ba047e9 100644 --- a/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml +++ b/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml @@ -39,6 +39,7 @@ tags: - Exploitation message: rundll32 process $process_name$ with commandline $process$ in host $dest$ mitre_attack_id: + - T1218 - T1218.011 observable: - name: dest diff --git a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml index c1b68d43d2..94eaa1d5b8 100644 --- a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml +++ b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml @@ -51,6 +51,7 @@ tags: message: Suspicious renamed microsoft.workflow.compiler.exe binary ran on $dest$ by $user$ mitre_attack_id: + - T1036 - T1127 - T1036.003 nist: diff --git a/detections/endpoint/suspicious_msbuild_path.yml b/detections/endpoint/suspicious_msbuild_path.yml index ee399b0b5d..54626c3ca3 100644 --- a/detections/endpoint/suspicious_msbuild_path.yml +++ b/detections/endpoint/suspicious_msbuild_path.yml @@ -51,8 +51,10 @@ tags: - Exploitation message: Msbuild.exe ran from an uncommon path on $dest$ execyted by $user$ mitre_attack_id: - - T1127.001 + - T1036 + - T1127 - T1036.003 + - T1127.001 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/suspicious_msbuild_rename.yml b/detections/endpoint/suspicious_msbuild_rename.yml index 973dbdaa07..b95320d0c2 100644 --- a/detections/endpoint/suspicious_msbuild_rename.yml +++ b/detections/endpoint/suspicious_msbuild_rename.yml @@ -49,8 +49,10 @@ tags: - Exploitation message: Suspicious renamed msbuild.exe binary ran on $dest$ by $user$ mitre_attack_id: - - T1127.001 + - T1036 + - T1127 - T1036.003 + - T1127.001 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/suspicious_msbuild_spawn.yml b/detections/endpoint/suspicious_msbuild_spawn.yml index c27f2512a0..5446e67271 100644 --- a/detections/endpoint/suspicious_msbuild_spawn.yml +++ b/detections/endpoint/suspicious_msbuild_spawn.yml @@ -48,6 +48,7 @@ tags: - Exploitation message: Suspicious msbuild.exe process executed on $dest$ by $user$ mitre_attack_id: + - T1127 - T1127.001 nist: - PR.PT diff --git a/detections/endpoint/suspicious_mshta_child_process.yml b/detections/endpoint/suspicious_mshta_child_process.yml index 3c4d2ba9f1..76e082bafe 100644 --- a/detections/endpoint/suspicious_mshta_child_process.yml +++ b/detections/endpoint/suspicious_mshta_child_process.yml @@ -47,6 +47,7 @@ tags: - Exploitation message: suspicious mshta child process detected on host $dest$ by user $user$. mitre_attack_id: + - T1218 - T1218.005 nist: - PR.PT diff --git a/detections/endpoint/suspicious_mshta_spawn.yml b/detections/endpoint/suspicious_mshta_spawn.yml index 28fbd4aa7d..c90b293976 100644 --- a/detections/endpoint/suspicious_mshta_spawn.yml +++ b/detections/endpoint/suspicious_mshta_spawn.yml @@ -46,6 +46,7 @@ tags: - Exploitation message: mshta.exe spawned by wmiprvse.exe on $dest$ mitre_attack_id: + - T1218 - T1218.005 nist: - PR.PT diff --git a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml index 6327c94cab..6884c73b1f 100644 --- a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml +++ b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml @@ -56,6 +56,7 @@ tags: message: Suspicious $Processes.process_path.file_path$ process potentially loading malicious code mitre_attack_id: + - T1218 - T1218.010 nist: - DE.CM diff --git a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml index 7116e1e610..25aadbe349 100644 --- a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml +++ b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml @@ -55,6 +55,7 @@ tags: message: $Processes.process_path.file_path$ process potentially loading malicious code mitre_attack_id: + - T1218 - T1218.011 nist: - PR.PT diff --git a/detections/endpoint/suspicious_rundll32_plugininit.yml b/detections/endpoint/suspicious_rundll32_plugininit.yml index 1f38049a11..838bd7e76f 100644 --- a/detections/endpoint/suspicious_rundll32_plugininit.yml +++ b/detections/endpoint/suspicious_rundll32_plugininit.yml @@ -39,6 +39,7 @@ tags: - Exploitation message: rundll32 process $process_name$ with commandline $process$ in host $dest$ mitre_attack_id: + - T1218 - T1218.011 observable: - name: dest diff --git a/detections/endpoint/suspicious_rundll32_rename.yml b/detections/endpoint/suspicious_rundll32_rename.yml index 07c01a5c50..459457a7d6 100644 --- a/detections/endpoint/suspicious_rundll32_rename.yml +++ b/detections/endpoint/suspicious_rundll32_rename.yml @@ -50,6 +50,8 @@ tags: - Actions on Objectives message: Suspicious renamed rundll32.exe binary ran on $dest$ by $user$ mitre_attack_id: + - T1218 + - T1036 - T1218.011 - T1036.003 nist: diff --git a/detections/endpoint/suspicious_rundll32_startw.yml b/detections/endpoint/suspicious_rundll32_startw.yml index 48a3a1d075..222729300e 100644 --- a/detections/endpoint/suspicious_rundll32_startw.yml +++ b/detections/endpoint/suspicious_rundll32_startw.yml @@ -56,6 +56,7 @@ tags: - Actions on Objectives message: rundll32.exe running with suspicious parameters on $dest$ mitre_attack_id: + - T1218 - T1218.011 nist: - PR.PT diff --git a/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml b/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml index ab6536acaf..683ac299ac 100644 --- a/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml @@ -52,6 +52,7 @@ tags: message: Suspicious rundll32.exe process with no command line arguments executed on $dest$ by $user$ mitre_attack_id: + - T1218 - T1218.011 nist: - PR.PT diff --git a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml index efedc0b128..f27fec7309 100644 --- a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml +++ b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml @@ -47,6 +47,7 @@ tags: message: Suspicious scheduled task registered on $dest$ mitre_attack_id: - T1053.005 + - T1053 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/system_processes_run_from_unexpected_locations.yml b/detections/endpoint/system_processes_run_from_unexpected_locations.yml index b85a4a6084..559d66164c 100644 --- a/detections/endpoint/system_processes_run_from_unexpected_locations.yml +++ b/detections/endpoint/system_processes_run_from_unexpected_locations.yml @@ -53,6 +53,7 @@ tags: - Actions on Objectives message: System process running from unexpected location on $dest$ mitre_attack_id: + - T1036 - T1036.003 nist: - PR.PT diff --git a/detections/endpoint/time_provider_persistence_registry.yml b/detections/endpoint/time_provider_persistence_registry.yml index fcf99f419e..12ad4308ff 100644 --- a/detections/endpoint/time_provider_persistence_registry.yml +++ b/detections/endpoint/time_provider_persistence_registry.yml @@ -37,6 +37,7 @@ tags: - Exploitation mitre_attack_id: - T1547.003 + - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml b/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml index 1532a647be..6949009607 100644 --- a/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml +++ b/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml @@ -42,6 +42,7 @@ tags: with EventCode $EventCode$ mitre_attack_id: - T1548.002 + - T1548 observable: - name: Computer type: Hostname diff --git a/detections/endpoint/uac_bypass_with_colorui_com_object.yml b/detections/endpoint/uac_bypass_with_colorui_com_object.yml index 84ce9eb604..965e53bb2e 100644 --- a/detections/endpoint/uac_bypass_with_colorui_com_object.yml +++ b/detections/endpoint/uac_bypass_with_colorui_com_object.yml @@ -37,6 +37,7 @@ tags: message: The following module $ImageLoaded$ was loaded by a non-standard application on endpoint $Computer$ by user $user$. mitre_attack_id: + - T1218 - T1218.003 observable: - name: user diff --git a/detections/endpoint/uninstall_app_using_msiexec.yml b/detections/endpoint/uninstall_app_using_msiexec.yml index e3305b5e7e..fc2c1b0fec 100644 --- a/detections/endpoint/uninstall_app_using_msiexec.yml +++ b/detections/endpoint/uninstall_app_using_msiexec.yml @@ -39,6 +39,7 @@ tags: message: process $process_name$ with a cmdline $process$ in host $dest$ mitre_attack_id: - T1218.007 + - T1218 observable: - name: dest type: Hostname diff --git a/detections/endpoint/unload_sysmon_filter_driver.yml b/detections/endpoint/unload_sysmon_filter_driver.yml index 10c7e25200..a22640a966 100644 --- a/detections/endpoint/unload_sysmon_filter_driver.yml +++ b/detections/endpoint/unload_sysmon_filter_driver.yml @@ -43,6 +43,7 @@ tags: message: Possible Sysmon filter driver unloading on $dest$ mitre_attack_id: - T1562.001 + - T1562 nist: - DE.CM observable: diff --git a/detections/endpoint/w3wp_spawning_shell.yml b/detections/endpoint/w3wp_spawning_shell.yml index ce8dcabe42..726c79d82d 100644 --- a/detections/endpoint/w3wp_spawning_shell.yml +++ b/detections/endpoint/w3wp_spawning_shell.yml @@ -50,6 +50,7 @@ tags: - Exploitation message: Possible Web Shell execution on $dest$ mitre_attack_id: + - T1505 - T1505.003 observable: - name: dest diff --git a/detections/endpoint/wbemprox_com_object_execution.yml b/detections/endpoint/wbemprox_com_object_execution.yml index bfbff429fa..91f61b3952 100644 --- a/detections/endpoint/wbemprox_com_object_execution.yml +++ b/detections/endpoint/wbemprox_com_object_execution.yml @@ -38,6 +38,7 @@ tags: - Exploitation message: Suspicious COM Object Execution on $Computer$ mitre_attack_id: + - T1218 - T1218.003 observable: - name: Computer diff --git a/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml b/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml index c93c9ea6e6..4bd094af25 100644 --- a/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml +++ b/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml @@ -44,6 +44,7 @@ tags: - Exploitation message: Wermgr.exe process connecting IP location web services on $ComputerName$ mitre_attack_id: + - T1590 - T1590.005 observable: - name: ComputerName diff --git a/detections/endpoint/windows_disableantispyware_reg.yml b/detections/endpoint/windows_disableantispyware_reg.yml index 3388fb9e89..bb539c4ea0 100644 --- a/detections/endpoint/windows_disableantispyware_reg.yml +++ b/detections/endpoint/windows_disableantispyware_reg.yml @@ -46,6 +46,7 @@ tags: message: Windows DisableAntiSpyware registry key set to 'disabled' on $dest$ mitre_attack_id: - T1562.001 + - T1562 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/windows_event_log_cleared.yml b/detections/endpoint/windows_event_log_cleared.yml index b185e92dbd..7d11c1f611 100644 --- a/detections/endpoint/windows_event_log_cleared.yml +++ b/detections/endpoint/windows_event_log_cleared.yml @@ -46,6 +46,7 @@ tags: - Actions on Objectives message: Windows event logs cleared on $dest$ via EventCode $EventCode$ mitre_attack_id: + - T1070 - T1070.001 nist: - DE.DP diff --git a/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml b/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml index e8d0ac5da9..3f135b0e36 100644 --- a/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml +++ b/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml @@ -62,6 +62,7 @@ tags: by the following command: $Command$' mitre_attack_id: - T1053.005 + - T1053 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml b/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml index c9f8a80525..b34070f242 100644 --- a/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml +++ b/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml @@ -63,6 +63,7 @@ tags: by the following command: $Command$' mitre_attack_id: - T1053.005 + - T1053 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/winword_spawning_cmd.yml b/detections/endpoint/winword_spawning_cmd.yml index 3be1953d5f..79ab9fdff3 100644 --- a/detections/endpoint/winword_spawning_cmd.yml +++ b/detections/endpoint/winword_spawning_cmd.yml @@ -45,6 +45,7 @@ tags: message: '$parent_process_name$ on $dest$ by $user$ launched command: $process_name$ which is very common in spearphishing attacks.' mitre_attack_id: + - T1566 - T1566.001 observable: - name: dest diff --git a/detections/endpoint/winword_spawning_powershell.yml b/detections/endpoint/winword_spawning_powershell.yml index 1ba0b16446..27bf1fe98d 100644 --- a/detections/endpoint/winword_spawning_powershell.yml +++ b/detections/endpoint/winword_spawning_powershell.yml @@ -47,6 +47,7 @@ tags: message: '$parent_process_name$ on $dest$ by $user$ launched the following powershell process: $process_name$ which is very common in spearphishing attacks' mitre_attack_id: + - T1566 - T1566.001 observable: - name: dest diff --git a/detections/endpoint/winword_spawning_windows_script_host.yml b/detections/endpoint/winword_spawning_windows_script_host.yml index 22493feea3..005936b001 100644 --- a/detections/endpoint/winword_spawning_windows_script_host.yml +++ b/detections/endpoint/winword_spawning_windows_script_host.yml @@ -44,6 +44,7 @@ tags: - Exploitation message: User $user$ on $dest$ spawned Windows Script Host from Winword.exe mitre_attack_id: + - T1566 - T1566.001 observable: - name: dest diff --git a/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml b/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml index 968baa4806..953a5e1593 100644 --- a/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml +++ b/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml @@ -61,6 +61,7 @@ tags: $filter$. Consumer: $Consumer$. EventCode: $EventCode$' mitre_attack_id: - T1546.003 + - T1546 nist: - PR.PT - PR.AT diff --git a/detections/endpoint/wmic_group_discovery.yml b/detections/endpoint/wmic_group_discovery.yml index ade199fd96..67ccbb4fcb 100644 --- a/detections/endpoint/wmic_group_discovery.yml +++ b/detections/endpoint/wmic_group_discovery.yml @@ -44,6 +44,7 @@ tags: - Reconnaissance message: Local group discovery on $dest$ by $user$. mitre_attack_id: + - T1069 - T1069.001 observable: - name: dest diff --git a/detections/endpoint/write_executable_in_smb_share.yml b/detections/endpoint/write_executable_in_smb_share.yml index 0465108fa9..16363956c9 100644 --- a/detections/endpoint/write_executable_in_smb_share.yml +++ b/detections/endpoint/write_executable_in_smb_share.yml @@ -38,6 +38,7 @@ tags: message: $user$ dropped or created an executable file in known sensitive SMB share. Share name=$Share_Name$, Target name=$Relative_Target_Name$, and Access mask=$Access_Mask$ mitre_attack_id: + - T1021 - T1021.002 observable: - name: user diff --git a/detections/endpoint/wsreset_uac_bypass.yml b/detections/endpoint/wsreset_uac_bypass.yml index 5d2ab46587..6b4a5762ea 100644 --- a/detections/endpoint/wsreset_uac_bypass.yml +++ b/detections/endpoint/wsreset_uac_bypass.yml @@ -43,6 +43,7 @@ tags: path $registry_value_name$ in $dest$ mitre_attack_id: - T1548.002 + - T1548 observable: - name: dest type: Hostname diff --git a/detections/endpoint/xmrig_driver_loaded.yml b/detections/endpoint/xmrig_driver_loaded.yml index c3c9d278af..acadcdf186 100644 --- a/detections/endpoint/xmrig_driver_loaded.yml +++ b/detections/endpoint/xmrig_driver_loaded.yml @@ -36,6 +36,7 @@ tags: message: A driver $ImageLoaded$ related to xmrig crytominer loaded in host $Computer$ mitre_attack_id: - T1543.003 + - T1543 observable: - name: Computer type: Hostname