Branch was auto-updated.

This commit is contained in:
srv-rr-gh-researchbt
2022-12-13 10:18:01 -08:00
committed by GitHub
5 changed files with 965 additions and 0 deletions
@@ -0,0 +1,157 @@
{
"version": "4.3",
"name": "AgentTesla Detection Coverage",
"description": "security_content detection coverage for AgentTesla",
"domain": "mitre-enterprise",
"techniques": [
{
"techniqueID": "T1562.001",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml"
},
{
"techniqueID": "T1562",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml"
},
{
"techniqueID": "T1566.001",
"score": 7,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml"
},
{
"techniqueID": "T1566",
"score": 7,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml"
},
{
"techniqueID": "T1204.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml"
},
{
"techniqueID": "T1204",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml"
},
{
"techniqueID": "T1071.003",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_file_transfer_protocol_in_non_common_process_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multi_hop_proxy_tor_website_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_mail_protocol_in_non_common_process_path.yml"
},
{
"techniqueID": "T1071",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_file_transfer_protocol_in_non_common_process_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multi_hop_proxy_tor_website_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_mail_protocol_in_non_common_process_path.yml"
},
{
"techniqueID": "T1014",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_drivers_loaded_by_signature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_driver_load_non_standard_path.yml"
},
{
"techniqueID": "T1068",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_drivers_loaded_by_signature.yml"
},
{
"techniqueID": "T1059",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml"
},
{
"techniqueID": "T1059.001",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml"
},
{
"techniqueID": "T1548.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml"
},
{
"techniqueID": "T1548",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml"
},
{
"techniqueID": "T1543.003",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml"
},
{
"techniqueID": "T1543",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_file_path.yml"
},
{
"techniqueID": "T1555",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml"
},
{
"techniqueID": "T1555.003",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml"
},
{
"techniqueID": "T1053.005",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml"
},
{
"techniqueID": "T1053",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml"
},
{
"techniqueID": "T1218",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml"
},
{
"techniqueID": "T1218.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml"
},
{
"techniqueID": "T1036",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml"
}
],
"gradient": {
"colors": [
"#ffffff",
"#66b1ff",
"#096ed7"
],
"minValue": 0,
"maxValue": 5
},
"filters": {
"platforms": [
"Windows",
"Linux",
"macOS",
"AWS",
"GCP",
"Azure",
"Office 365",
"SaaS"
]
},
"legendItems": [
{
"label": "NO available detections",
"color": "#ffffff"
},
{
"label": "Some detections available",
"color": "#66b1ff"
}
],
"showTacticRowBackground": true,
"tacticRowBackground": "#dddddd",
"sorting": 3
}
@@ -0,0 +1,247 @@
{
"version": "4.3",
"name": "Azorult Detection Coverage",
"description": "security_content detection coverage for Azorult",
"domain": "mitre-enterprise",
"techniques": [
{
"techniqueID": "T1021.001",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_allow_remote_assistance.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_rdp_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml"
},
{
"techniqueID": "T1021",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_allow_remote_assistance.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_rdp_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml"
},
{
"techniqueID": "T1489",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_service_stop_by_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_valid_account_with_never_expires_password.yml"
},
{
"techniqueID": "T1219",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_access_software_rms_registry.yml"
},
{
"techniqueID": "T1566.001",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml"
},
{
"techniqueID": "T1566",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml"
},
{
"techniqueID": "T1204.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml"
},
{
"techniqueID": "T1204",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml"
},
{
"techniqueID": "T1562.001",
"score": 14,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml"
},
{
"techniqueID": "T1562",
"score": 16,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml"
},
{
"techniqueID": "T1562.004",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml"
},
{
"techniqueID": "T1222",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml"
},
{
"techniqueID": "T1548",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_operation_with_consent_admin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml"
},
{
"techniqueID": "T1112",
"score": 7,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_regedit_silent_reg_import.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disable_win_defender_raw_write_notif.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disallow_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_suppress_win_defender_notif.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disable_windows_security_center_notif.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disable_toast_notifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disabling_wer_settings.yml"
},
{
"techniqueID": "T1053.005",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml"
},
{
"techniqueID": "T1053",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml"
},
{
"techniqueID": "T1136.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml"
},
{
"techniqueID": "T1136",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml"
},
{
"techniqueID": "T1059.003",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml"
},
{
"techniqueID": "T1059",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml"
},
{
"techniqueID": "T1531",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_net_app.yml"
},
{
"techniqueID": "T1548.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml"
},
{
"techniqueID": "T1049",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml"
},
{
"techniqueID": "T1543.003",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml"
},
{
"techniqueID": "T1543",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml"
},
{
"techniqueID": "T1555",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml"
},
{
"techniqueID": "T1555.003",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml"
},
{
"techniqueID": "T1590.005",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_gather_victim_network_info_through_ip_check_web_services.yml"
},
{
"techniqueID": "T1590",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_gather_victim_network_info_through_ip_check_web_services.yml"
},
{
"techniqueID": "T1569",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml"
},
{
"techniqueID": "T1569.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml"
},
{
"techniqueID": "T1059.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_import_applocker_policy.yml"
},
{
"techniqueID": "T1564.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml"
},
{
"techniqueID": "T1564",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml"
},
{
"techniqueID": "T1036",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml"
},
{
"techniqueID": "T1071",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_application_layer_protocol_rms_radmin_tool_namedpipe.yml"
},
{
"techniqueID": "T1222.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml"
},
{
"techniqueID": "T1069",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml"
},
{
"techniqueID": "T1069.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml"
},
{
"techniqueID": "T1547.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml"
},
{
"techniqueID": "T1547",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml"
}
],
"gradient": {
"colors": [
"#ffffff",
"#66b1ff",
"#096ed7"
],
"minValue": 0,
"maxValue": 5
},
"filters": {
"platforms": [
"Windows",
"Linux",
"macOS",
"AWS",
"GCP",
"Azure",
"Office 365",
"SaaS"
]
},
"legendItems": [
{
"label": "NO available detections",
"color": "#ffffff"
},
{
"label": "Some detections available",
"color": "#66b1ff"
}
],
"showTacticRowBackground": true,
"tacticRowBackground": "#dddddd",
"sorting": 3
}
@@ -0,0 +1,237 @@
{
"version": "4.3",
"name": "Qakbot Detection Coverage",
"description": "security_content detection coverage for Qakbot",
"domain": "mitre-enterprise",
"techniques": [
{
"techniqueID": "T1055",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_remote_thread.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_shell_fetch_env_variables.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_wermgr_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml"
},
{
"techniqueID": "T1055.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_remote_thread.yml"
},
{
"techniqueID": "T1033",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_discovery_using_qwinsta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_discovery_using_ldap_nslookup.yml"
},
{
"techniqueID": "T1566.001",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml"
},
{
"techniqueID": "T1566",
"score": 6,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml"
},
{
"techniqueID": "T1204.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml"
},
{
"techniqueID": "T1204",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml"
},
{
"techniqueID": "T1059",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml"
},
{
"techniqueID": "T1049",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml"
},
{
"techniqueID": "T1059.007",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml"
},
{
"techniqueID": "T1047",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_wmi_process_call_create.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_wmi_impersonate_token.yml"
},
{
"techniqueID": "T1218",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_regsvr32_renamed_binary.yml"
},
{
"techniqueID": "T1218.010",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_regsvr32_renamed_binary.yml"
},
{
"techniqueID": "T1574.002",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_masquerading_explorer_as_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_side_loading_in_calc.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml"
},
{
"techniqueID": "T1574",
"score": 4,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_masquerading_explorer_as_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_side_loading_in_calc.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml"
},
{
"techniqueID": "T1053",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_run_task_on_demand.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_schtasks_create_run_as_system.yml"
},
{
"techniqueID": "T1016",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_discovery_using_route_windows_app.yml"
},
{
"techniqueID": "T1016.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_discovery_using_route_windows_app.yml"
},
{
"techniqueID": "T1027",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml"
},
{
"techniqueID": "T1592",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recon_using_wmi_class.yml"
},
{
"techniqueID": "T1562.001",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml"
},
{
"techniqueID": "T1562",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml"
},
{
"techniqueID": "T1059.003",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml"
},
{
"techniqueID": "T1059.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recon_using_wmi_class.yml"
},
{
"techniqueID": "T1071",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_app_layer_protocol_qakbot_namedpipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_app_layer_protocol_wermgr_connect_to_namedpipe.yml"
},
{
"techniqueID": "T1569",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_service_created_with_suspicious_service_path.yml"
},
{
"techniqueID": "T1569.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_service_created_with_suspicious_service_path.yml"
},
{
"techniqueID": "T1036",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_copy_on_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml"
},
{
"techniqueID": "T1036.003",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_copy_on_system32.yml"
},
{
"techniqueID": "T1543",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/services_exe_lolbas_execution_process_spawn.yml"
},
{
"techniqueID": "T1543.003",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/services_exe_lolbas_execution_process_spawn.yml"
},
{
"techniqueID": "T1053.005",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_windows_task_scheduler_event_action_started.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_schtasks_create_run_as_system.yml"
},
{
"techniqueID": "T1055.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml"
},
{
"techniqueID": "T1566.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml"
},
{
"techniqueID": "T1482",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml"
},
{
"techniqueID": "T1112",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_qakbot_binary_data_registry.yml"
},
{
"techniqueID": "T1574.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml"
},
{
"techniqueID": "T1547.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml"
},
{
"techniqueID": "T1547",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml"
}
],
"gradient": {
"colors": [
"#ffffff",
"#66b1ff",
"#096ed7"
],
"minValue": 0,
"maxValue": 5
},
"filters": {
"platforms": [
"Windows",
"Linux",
"macOS",
"AWS",
"GCP",
"Azure",
"Office 365",
"SaaS"
]
},
"legendItems": [
{
"label": "NO available detections",
"color": "#ffffff"
},
{
"label": "Some detections available",
"color": "#66b1ff"
}
],
"showTacticRowBackground": true,
"tacticRowBackground": "#dddddd",
"sorting": 3
}
@@ -0,0 +1,182 @@
{
"version": "4.3",
"name": "Remcos Detection Coverage",
"description": "security_content detection coverage for Remcos",
"domain": "mitre-enterprise",
"techniques": [
{
"techniqueID": "T1562.001",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml"
},
{
"techniqueID": "T1562",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml"
},
{
"techniqueID": "T1059.005",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml"
},
{
"techniqueID": "T1059",
"score": 4,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml"
},
{
"techniqueID": "T1566.001",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml"
},
{
"techniqueID": "T1566",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml"
},
{
"techniqueID": "T1204.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml"
},
{
"techniqueID": "T1204",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml"
},
{
"techniqueID": "T1113",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml"
},
{
"techniqueID": "T1218",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml"
},
{
"techniqueID": "T1218.010",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_inprocserver32_modification.yml"
},
{
"techniqueID": "T1055",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/loading_of_dynwrapx_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winhlp32_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"
},
{
"techniqueID": "T1055.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/loading_of_dynwrapx_module.yml"
},
{
"techniqueID": "T1555.003",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_browser_pass_view_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml"
},
{
"techniqueID": "T1555",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_browser_pass_view_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml"
},
{
"techniqueID": "T1112",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_client_registry_install_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_inprocserver32_modification.yml"
},
{
"techniqueID": "T1070",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml"
},
{
"techniqueID": "T1548.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml"
},
{
"techniqueID": "T1548",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml"
},
{
"techniqueID": "T1543",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"
},
{
"techniqueID": "T1059.007",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml"
},
{
"techniqueID": "T1592",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_info_gathering_using_dxdiag_application.yml"
},
{
"techniqueID": "T1559.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml"
},
{
"techniqueID": "T1036",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml"
},
{
"techniqueID": "T1134.004",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"
},
{
"techniqueID": "T1134",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"
},
{
"techniqueID": "T1547.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml"
},
{
"techniqueID": "T1547",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml"
}
],
"gradient": {
"colors": [
"#ffffff",
"#66b1ff",
"#096ed7"
],
"minValue": 0,
"maxValue": 5
},
"filters": {
"platforms": [
"Windows",
"Linux",
"macOS",
"AWS",
"GCP",
"Azure",
"Office 365",
"SaaS"
]
},
"legendItems": [
{
"label": "NO available detections",
"color": "#ffffff"
},
{
"label": "Some detections available",
"color": "#66b1ff"
}
],
"showTacticRowBackground": true,
"tacticRowBackground": "#dddddd",
"sorting": 3
}
@@ -0,0 +1,142 @@
{
"version": "4.3",
"name": "Trickbot Detection Coverage",
"description": "security_content detection coverage for Trickbot",
"domain": "mitre-enterprise",
"techniques": [
{
"techniqueID": "T1027",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml"
},
{
"techniqueID": "T1059",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml"
},
{
"techniqueID": "T1590",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml"
},
{
"techniqueID": "T1590.005",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml"
},
{
"techniqueID": "T1218",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml"
},
{
"techniqueID": "T1218.005",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml"
},
{
"techniqueID": "T1566",
"score": 4,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml"
},
{
"techniqueID": "T1566.001",
"score": 4,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml"
},
{
"techniqueID": "T1055",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml"
},
{
"techniqueID": "T1543",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_file_path.yml"
},
{
"techniqueID": "T1053",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/schedule_task_with_rundll32_command_trigger.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml"
},
{
"techniqueID": "T1562.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml"
},
{
"techniqueID": "T1562",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml"
},
{
"techniqueID": "T1053.005",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml"
},
{
"techniqueID": "T1087.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml"
},
{
"techniqueID": "T1087",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml"
},
{
"techniqueID": "T1218.011",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml"
},
{
"techniqueID": "T1021",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/executable_file_written_in_administrative_smb_share.yml"
},
{
"techniqueID": "T1021.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/executable_file_written_in_administrative_smb_share.yml"
},
{
"techniqueID": "T1036",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml"
}
],
"gradient": {
"colors": [
"#ffffff",
"#66b1ff",
"#096ed7"
],
"minValue": 0,
"maxValue": 5
},
"filters": {
"platforms": [
"Windows",
"Linux",
"macOS",
"AWS",
"GCP",
"Azure",
"Office 365",
"SaaS"
]
},
"legendItems": [
{
"label": "NO available detections",
"color": "#ffffff"
},
{
"label": "Some detections available",
"color": "#66b1ff"
}
],
"showTacticRowBackground": true,
"tacticRowBackground": "#dddddd",
"sorting": 3
}