Branch was auto-updated.

This commit is contained in:
github-actions[bot]
2021-04-23 12:24:16 +00:00
committed by GitHub
60 changed files with 77993 additions and 57558 deletions
+1
View File
@@ -56,6 +56,7 @@ def main(args):
for test in tests:
counter_tests=counter_tests+1
detection_coverage = "{:.0%}".format(counter_tests/counter_detection)
TEMPLATE_PATH = os.path.join(os.path.dirname(__file__), 'jinja2_templates')
+1 -1
View File
@@ -13,6 +13,6 @@
<rect rx="3" width="105" height="20" fill="url(#a)"/>
<g fill="#fff" text-anchor="middle" font-family="DejaVu Sans,Verdana,Geneva,sans-serif" font-size="11">
<text x="30" y="14">detections</text>
<text x="83" y="14">357</text>
<text x="83" y="14">440</text>
</g>
</svg>

Before

Width:  |  Height:  |  Size: 654 B

After

Width:  |  Height:  |  Size: 654 B

+1 -1
View File
@@ -13,6 +13,6 @@
<rect rx="3" width="100" height="20" fill="url(#a)"/>
<g fill="#fff" text-anchor="middle" font-family="DejaVu Sans,Verdana,Geneva,sans-serif" font-size="11">
<text x="30" y="14">coverage</text>
<text x="80" y="14">83%</text>
<text x="80" y="14">100%</text>
</g>
</svg>

Before

Width:  |  Height:  |  Size: 652 B

After

Width:  |  Height:  |  Size: 653 B

@@ -25,6 +25,7 @@ references:
tags:
analytic_story:
- Suspicious Cloud User Activities
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1580/aws_iam_accessdenied_discovery_events/aws_iam_accessdenied_discovery_events.json
kill_chain_phases:
@@ -44,4 +45,3 @@ tags:
- errorCode
- userIdentity.type
security_domain: access
automated_detection_testing: passed
@@ -6,8 +6,11 @@ author: Michael Haag, Splunk
type: batch
datamodel: []
description: The following detection identifies any malformed policy document exceptions
with a status of `failure`. A malformed policy document exception occurs in instances where roles are attempted to be assumed, or brute forced. In a brute force attempt, using a tool like CloudSploit or Pacu, an attempt will look like `arn:aws:iam::111111111111:role/aws-service-role/rds.amazonaws.com/AWSServiceRoleForRDS`. Meaning, when an adversary is attempting to identify
a role name, multiple failures will occur. This detection focuses on the errors of a remote attempt that is failing.
with a status of `failure`. A malformed policy document exception occurs in instances
where roles are attempted to be assumed, or brute forced. In a brute force attempt,
using a tool like CloudSploit or Pacu, an attempt will look like `arn:aws:iam::111111111111:role/aws-service-role/rds.amazonaws.com/AWSServiceRoleForRDS`. Meaning,
when an adversary is attempting to identify a role name, multiple failures will
occur. This detection focuses on the errors of a remote attempt that is failing.
search: '`cloudtrail` (errorCode=MalformedPolicyDocumentException) status=failure
(userAgent!=*.amazonaws.com) | stats count min(_time) as firstTime max(_time) as
lastTime values(requestParameters.policyName) as policy_name by src eventName eventSource
@@ -27,6 +30,7 @@ references:
tags:
analytic_story:
- AWS IAM Privilege Escalation
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1580/aws_iam_assume_role_policy_brute_force/aws_iam_assume_role_policy_brute_force.json
kill_chain_phases:
@@ -46,4 +50,3 @@ tags:
- errorCode
- requestParameters.policyName
security_domain: access
automated_detection_testing: passed
+1 -1
View File
@@ -28,6 +28,7 @@ references:
tags:
analytic_story:
- AWS IAM Privilege Escalation
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_delete_policy/aws_iam_delete_policy.json
kill_chain_phases:
@@ -46,4 +47,3 @@ tags:
- errorCode
- requestParameters.policyArn
security_domain: access
automated_detection_testing: passed
@@ -5,9 +5,9 @@ date: '2021-04-01'
author: Michael Haag, Splunk
type: batch
datamodel: []
description: This detection identifies failure attempts to delete groups. We want to identify
when a group is attempting to be deleted, but either access is denied, there is
a conflict or there is no group. This is indicative of administrators performing
description: This detection identifies failure attempts to delete groups. We want
to identify when a group is attempting to be deleted, but either access is denied,
there is a conflict or there is no group. This is indicative of administrators performing
an action, but also could be suspicious behavior occurring. Review parallel IAM
events - recently added users, new groups and so forth.
search: '`cloudtrail` eventSource=iam.amazonaws.com eventName=DeleteGroup errorCode
@@ -28,6 +28,7 @@ references:
tags:
analytic_story:
- AWS IAM Privilege Escalation
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_failure_group_deletion/aws_iam_failure_group_deletion.json
kill_chain_phases:
@@ -46,4 +47,3 @@ tags:
- errorCode
- requestParameters.groupName
security_domain: identity
automated_detection_testing: passed
@@ -26,6 +26,7 @@ references:
tags:
analytic_story:
- AWS IAM Privilege Escalation
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_successful_group_deletion/aws_iam_successful_group_deletion.json
kill_chain_phases:
@@ -45,4 +46,3 @@ tags:
- errorCode
- requestParameters.groupName
security_domain: identity
automated_detection_testing: passed
@@ -32,6 +32,7 @@ references:
tags:
analytic_story:
- Cobalt Strike
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon_dllhost.log
kill_chain_phases:
@@ -51,4 +52,3 @@ tags:
- dest_port
- process_path
security_domain: endpoint
automated_detection_testing: passed
@@ -30,6 +30,7 @@ references:
tags:
analytic_story:
- Spearphishing Attachments
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log
kill_chain_phases:
@@ -49,4 +50,3 @@ tags:
- user
- parent_process_id
security_domain: endpoint
automated_detection_testing: passed
@@ -34,6 +34,7 @@ references:
tags:
analytic_story:
- Spearphishing Attachments
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log
kill_chain_phases:
@@ -53,4 +54,3 @@ tags:
- user
- parent_process_id
security_domain: endpoint
automated_detection_testing: passed
@@ -20,8 +20,8 @@ search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint
| regex process="(gpupdate\.exe.{0,4}$)" | join process_id [| tstats `security_content_summariesonly`
count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_id
Ports.dest Ports.dest_port| `drop_dm_object_name(Ports)` | rename dest as connection_to_CNC]
| table _time dest parent_process_name process_name process_path process process_id connection_to_CNC
dest_port | `gpupdate_with_no_command_line_arguments_with_network_filter`'
| table _time dest parent_process_name process_name process_path process process_id
connection_to_CNC dest_port | `gpupdate_with_no_command_line_arguments_with_network_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node.
@@ -33,6 +33,7 @@ references:
tags:
analytic_story:
- Cobalt Strike
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log
kill_chain_phases:
@@ -52,4 +53,3 @@ tags:
- dest_port
- process_path
security_domain: endpoint
automated_detection_testing: passed
@@ -29,6 +29,9 @@ references:
tags:
analytic_story:
- Spearphishing Attachments
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log
kill_chain_phases:
- Exploitation
mitre_attack_id:
@@ -46,6 +49,3 @@ tags:
- Processes.user
- Processes.process_id
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log
@@ -35,6 +35,9 @@ references:
tags:
analytic_story:
- Spearphishing Attachments
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log
kill_chain_phases:
- Exploitation
mitre_attack_id:
@@ -54,6 +57,3 @@ tags:
- ProcessGuid
- _time
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log
@@ -28,6 +28,9 @@ references:
tags:
analytic_story:
- Spearphishing Attachments
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log
kill_chain_phases:
- Exploitation
mitre_attack_id:
@@ -47,6 +50,3 @@ tags:
- ProcessGuid
- _time
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log
@@ -27,6 +27,9 @@ references:
tags:
analytic_story:
- Spearphishing Attachments
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets2/windows-sysmon.log
kill_chain_phases:
- Exploitation
mitre_attack_id:
@@ -47,6 +50,3 @@ tags:
- Computer
- EventCode
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets2/windows-sysmon.log
@@ -35,6 +35,7 @@ references:
tags:
analytic_story:
- Spearphishing Attachments
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_icedid.log
kill_chain_phases:
@@ -54,4 +55,3 @@ tags:
- user
- parent_process_id
security_domain: endpoint
automated_detection_testing: passed
@@ -20,8 +20,8 @@ search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint
| regex process="(rundll32\.exe.{0,4}$)" | join process_id [| tstats `security_content_summariesonly`
count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_id
Ports.dest Ports.dest_port| `drop_dm_object_name(Ports)` | rename dest as connection_to_CNC]
| table _time dest parent_process_name process_name process_path process process_id connection_to_CNC
dest_port | `rundll32_with_no_command_line_arguments_with_network_filter`'
| table _time dest parent_process_name process_name process_path process process_id
connection_to_CNC dest_port | `rundll32_with_no_command_line_arguments_with_network_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` and `port` node.
@@ -36,6 +36,7 @@ tags:
analytic_story:
- Suspicious Rundll32 Activity
- Cobalt Strike
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log
kill_chain_phases:
@@ -55,4 +56,3 @@ tags:
- dest_port
- process_path
security_domain: endpoint
automated_detection_testing: passed
@@ -32,6 +32,7 @@ references:
tags:
analytic_story:
- Cobalt Strike
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon_searchprotocolhost.log
kill_chain_phases:
@@ -50,4 +51,3 @@ tags:
- dest_port
- process_path
security_domain: endpoint
automated_detection_testing: passed
@@ -33,6 +33,9 @@ references:
tags:
analytic_story:
- Windows Persistence Techniques
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/tasksched/windows-security.log
kill_chain_phases:
- Exploitation
mitre_attack_id:
@@ -51,6 +54,3 @@ tags:
- Hidden
- Arguments
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/tasksched/windows-security.log
@@ -46,6 +46,7 @@ tags:
- Windows Persistence Techniques
- Ransomware
- Ryuk Ransomware
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-security.log
kill_chain_phases:
@@ -63,4 +64,3 @@ tags:
- Description
- Command
security_domain: endpoint
automated_detection_testing: passed
@@ -46,6 +46,7 @@ tags:
- Windows Persistence Techniques
- Ransomware
- Ryuk Ransomware
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/taskschedule/windows-security.log
kill_chain_phases:
@@ -63,4 +64,3 @@ tags:
- Description
- Command
security_domain: endpoint
automated_detection_testing: passed
+1 -1
View File
@@ -30,6 +30,7 @@ references:
tags:
analytic_story:
- Spearphishing Attachments
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log
kill_chain_phases:
@@ -49,4 +50,3 @@ tags:
- user
- parent_process_id
security_domain: endpoint
automated_detection_testing: passed
@@ -32,6 +32,7 @@ references:
tags:
analytic_story:
- Spearphishing Attachments
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log
kill_chain_phases:
@@ -51,4 +52,3 @@ tags:
- user
- parent_process_id
security_domain: endpoint
automated_detection_testing: passed
@@ -32,6 +32,7 @@ references:
tags:
analytic_story:
- Spearphishing Attachment
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_wsh.log
kill_chain_phases:
@@ -51,4 +52,3 @@ tags:
- user
- parent_process_id
security_domain: endpoint
automated_detection_testing: passed
+1 -1
View File
@@ -5,7 +5,7 @@
"id": {
"group": null,
"name": "DA-ESS-ContentUpdate",
"version": "3.18.0"
"version": "3.19.0"
},
"author": [
{
+109 -109
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-04-14T19:13:35 UTC
# On Date: 2021-04-22T21:35:40 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -35,8 +35,8 @@ version = 1
reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"]
detection_searches = ["ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule", "ESCU - Abnormally High AWS Instances Launched by User - Rule", "ESCU - EC2 Instance Started In Previously Unseen Region - Rule", "ESCU - EC2 Instance Started With Previously Unseen AMI - Rule", "ESCU - EC2 Instance Started With Previously Unseen Instance Type - Rule", "ESCU - EC2 Instance Started With Previously Unseen User - Rule"]
mappings = {"cis20": ["CIS 1", "CIS 12", "CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004", "T1535"], "nist": ["DE.AE", "DE.DP", "ID.AM"]}
investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task"]
support_searches = ["ESCU - Previously Seen EC2 Instance Types", "ESCU - Previously Seen EC2 AMIs", "ESCU - Baseline of Excessive AWS Instances Launched by User - MLTK", "ESCU - Previously Seen EC2 Launches By User", "ESCU - Previously Seen AWS Regions"]
investigative_searches = ["ESCU - Get Notable History - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task"]
support_searches = ["ESCU - Previously Seen EC2 AMIs", "ESCU - Baseline of Excessive AWS Instances Launched by User - MLTK", "ESCU - Previously Seen EC2 Instance Types", "ESCU - Previously Seen EC2 Launches By User", "ESCU - Previously Seen AWS Regions"]
data_models = []
providing_technologies = none
description = Monitor your AWS EC2 instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or EC2 instances started by previously unseen users are just a few examples of potentially malicious behavior.
@@ -53,8 +53,8 @@ modification_date = 2021-03-08
id = ced74200-8465-4bc3-bd2c-22782eec6750
version = 1
reference = ["https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/", "https://www.cyberark.com/resources/threat-research-blog/the-cloud-shadow-admin-threat-10-permissions-to-protect", "https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws"]
detection_searches = ["ESCU - AWS Create Policy Version to allow all resources - Rule", "ESCU - AWS CreateAccessKey - Rule", "ESCU - AWS CreateLoginProfile - Rule", "ESCU - AWS SetDefaultPolicyVersion - Rule", "ESCU - AWS UpdateLoginProfile - Rule"]
mappings = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004", "T1136.003"], "nist": ["DE.CM", "PR.AC", "PR.DS"]}
detection_searches = ["ESCU - AWS Create Policy Version to allow all resources - Rule", "ESCU - AWS CreateAccessKey - Rule", "ESCU - AWS CreateLoginProfile - Rule", "ESCU - AWS IAM Assume Role Policy Brute Force - Rule", "ESCU - AWS IAM Delete Policy - Rule", "ESCU - AWS IAM Failure Group Deletion - Rule", "ESCU - AWS IAM Successful Group Deletion - Rule", "ESCU - AWS SetDefaultPolicyVersion - Rule", "ESCU - AWS UpdateLoginProfile - Rule"]
mappings = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives", "Reconnaissance"], "mitre_attack": ["T1069.003", "T1078.004", "T1098", "T1110", "T1136.003", "T1580"], "nist": ["DE.CM", "PR.AC", "PR.DS"]}
investigative_searches = []
support_searches = []
data_models = []
@@ -73,7 +73,7 @@ version = 2
reference = ["https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_Appendix_NACLs.html", "https://aws.amazon.com/blogs/security/how-to-help-prepare-for-ddos-attacks-by-reducing-your-attack-surface/"]
detection_searches = ["ESCU - AWS Network Access Control List Created with All Open Ports - Rule", "ESCU - AWS Network Access Control List Deleted - Rule", "ESCU - Detect Spike in Network ACL Activity - Rule", "ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule"]
mappings = {"cis20": ["CIS 11", "CIS 12"], "kill_chain_phases": ["Actions on Objectives", "Command and Control"], "mitre_attack": ["T1562.007"], "nist": ["DE.AE", "DE.CM", "DE.DP", "PR.AC"]}
investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task"]
investigative_searches = ["ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Info - Response Task"]
support_searches = ["ESCU - Baseline of blocked outbound traffic from AWS", "ESCU - Baseline of Network ACL Activity by ARN"]
data_models = []
providing_technologies = none
@@ -107,7 +107,7 @@ version = 1
reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"]
detection_searches = ["ESCU - AWS Cloud Provisioning From Previously Unseen City - Rule", "ESCU - AWS Cloud Provisioning From Previously Unseen Country - Rule", "ESCU - AWS Cloud Provisioning From Previously Unseen IP Address - Rule", "ESCU - AWS Cloud Provisioning From Previously Unseen Region - Rule"]
mappings = {"cis20": ["CIS 1"], "mitre_attack": ["T1535"], "nist": ["ID.AM"]}
investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get All AWS Activity From City - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get All AWS Activity From Country - Response Task", "ESCU - Get All AWS Activity From Region - Response Task"]
investigative_searches = ["ESCU - Get All AWS Activity From City - Response Task", "ESCU - Get All AWS Activity From Country - Response Task", "ESCU - Get All AWS Activity From Region - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task"]
support_searches = ["ESCU - Previously Seen AWS Provisioning Activity Sources"]
data_models = []
providing_technologies = none
@@ -126,7 +126,7 @@ reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.p
detection_searches = ["ESCU - AWS Excessive Security Scanning - Rule", "ESCU - Detect API activity from users without MFA - Rule", "ESCU - Detect AWS API Activities From Unapproved Accounts - Rule", "ESCU - Detect Spike in AWS API Activity - Rule", "ESCU - Detect Spike in Security Group Activity - Rule", "ESCU - Detect new API calls from user roles - Rule"]
mappings = {"cis20": ["CIS 1", "CIS 13", "CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004", "T1526"], "nist": ["DE.CM", "DE.DP", "ID.AM", "PR.AC", "PR.DS"]}
investigative_searches = ["ESCU - Investigate AWS User Activities by user field - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = ["ESCU - Baseline of API Calls per User ARN", "ESCU - Create a list of approved AWS service accounts", "ESCU - Baseline of Security Group Activity by ARN", "ESCU - Previously seen API call per user roles in CloudTrail"]
support_searches = ["ESCU - Previously seen API call per user roles in CloudTrail", "ESCU - Baseline of API Calls per User ARN", "ESCU - Baseline of Security Group Activity by ARN", "ESCU - Create a list of approved AWS service accounts"]
data_models = []
providing_technologies = none
description = Detect and investigate dormant user accounts for your AWS environment that have become active again. Because inactive and ad-hoc accounts are common attack targets, it's critical to enable governance within your environment.
@@ -145,7 +145,7 @@ version = 1
reference = ["https://github.com/SpiderLabs/owasp-modsecurity-crs/blob/v3.2/dev/rules/REQUEST-944-APPLICATION-ATTACK-JAVA.conf"]
detection_searches = ["ESCU - Suspicious Java Classes - Rule", "ESCU - Unusually Long Content-Type Length - Rule", "ESCU - Web Servers Executing Suspicious Processes - Rule"]
mappings = {"cis20": ["CIS 12", "CIS 18", "CIS 3", "CIS 4", "CIS 7"], "kill_chain_phases": ["Actions on Objectives", "Delivery", "Exploitation"], "mitre_attack": ["T1082"], "nist": ["DE.AE", "DE.CM", "ID.RA", "PR.IP", "PR.MA", "PR.PT", "RS.MI"]}
investigative_searches = ["ESCU - Investigate Web POSTs From src - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Investigate Suspicious Strings in HTTP Header - Response Task"]
investigative_searches = ["ESCU - Investigate Suspicious Strings in HTTP Header - Response Task", "ESCU - Investigate Web POSTs From src - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = []
data_models = ["Endpoint"]
providing_technologies = none
@@ -226,7 +226,7 @@ version = 1
reference = ["https://www.zerofox.com/blog/what-is-digital-risk-monitoring/", "https://securingtomorrow.mcafee.com/consumer/family-safety/what-is-typosquatting/", "https://blog.malwarebytes.com/cybercrime/2016/06/explained-typosquatting/"]
detection_searches = ["ESCU - Monitor DNS For Brand Abuse - Rule", "ESCU - Monitor Email For Brand Abuse - Rule", "ESCU - Monitor Web Traffic For Brand Abuse - Rule"]
mappings = {"cis20": ["CIS 7"], "kill_chain_phases": ["Actions on Objectives", "Delivery"], "nist": ["PR.IP"]}
investigative_searches = ["ESCU - Get Notable History - Response Task", "ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Email Info - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"]
investigative_searches = ["ESCU - Get Email Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"]
support_searches = ["ESCU - DNSTwist Domain Names"]
data_models = ["Email", "Network_Resolution", "Web"]
providing_technologies = none
@@ -262,8 +262,8 @@ version = 1
reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"]
detection_searches = ["ESCU - Abnormally High Number Of Cloud Instances Launched - Rule", "ESCU - Cloud Compute Instance Created By Previously Unseen User - Rule", "ESCU - Cloud Compute Instance Created In Previously Unused Region - Rule", "ESCU - Cloud Compute Instance Created With Previously Unseen Image - Rule", "ESCU - Cloud Compute Instance Created With Previously Unseen Instance Type - Rule"]
mappings = {"cis20": ["CIS 1", "CIS 12", "CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004", "T1535"], "nist": ["DE.AE", "DE.DP", "ID.AM"]}
investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task"]
support_searches = ["ESCU - Previously Seen Cloud Regions - Update", "ESCU - Previously Seen Cloud Compute Instance Types - Initial", "ESCU - Baseline Of Cloud Instances Launched", "ESCU - Previously Seen Cloud Compute Images - Update", "ESCU - Previously Seen Cloud Compute Instance Types - Update", "ESCU - Baseline Of Cloud Instances Destroyed", "ESCU - Previously Seen Cloud Regions - Initial", "ESCU - Previously Seen Cloud Compute Creations By User - Update", "ESCU - Previously Seen Cloud Compute Creations By User - Initial", "ESCU - Previously Seen Cloud Compute Images - Initial"]
investigative_searches = ["ESCU - Get Notable History - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task"]
support_searches = ["ESCU - Previously Seen Cloud Compute Creations By User - Initial", "ESCU - Previously Seen Cloud Compute Instance Types - Initial", "ESCU - Previously Seen Cloud Compute Creations By User - Update", "ESCU - Previously Seen Cloud Compute Instance Types - Update", "ESCU - Baseline Of Cloud Instances Launched", "ESCU - Previously Seen Cloud Regions - Initial", "ESCU - Previously Seen Cloud Compute Images - Update", "ESCU - Previously Seen Cloud Compute Images - Initial", "ESCU - Previously Seen Cloud Regions - Update", "ESCU - Baseline Of Cloud Instances Destroyed"]
data_models = ["Change"]
providing_technologies = none
description = Monitor your cloud compute instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or compute instances started by previously unseen users are just a few examples of potentially malicious behavior.
@@ -297,7 +297,7 @@ modification_date = 2021-02-16
id = bcfd17e8-5461-400a-80a2-3b7d1459220c
version = 1
reference = ["https://www.cobaltstrike.com/", "https://www.infocyte.com/blog/2020/09/02/cobalt-strike-the-new-favorite-among-thieves/", "https://bluescreenofjeff.com/2017-01-24-how-to-write-malleable-c2-profiles-for-cobalt-strike/", "https://blog.talosintelligence.com/2020/09/coverage-strikes-back-cobalt-strike-paper.html", "https://www.fireeye.com/blog/threat-research/2020/12/unauthorized-access-of-fireeye-red-team-tools.html", "https://github.com/MichaelKoczwara/Awesome-CobaltStrike-Defence", "https://github.com/zer0yu/Awesome-CobaltStrike"]
detection_searches = ["ESCU - Cobalt Strike Named Pipes - Rule", "ESCU - Detect Regsvr32 Application Control Bypass - Rule", "ESCU - Suspicious DLLHost no Command Line Arguments - Rule", "ESCU - Suspicious GPUpdate no Command Line Arguments - Rule", "ESCU - Suspicious MSBuild Rename - Rule", "ESCU - Suspicious Rundll32 StartW - Rule", "ESCU - Suspicious Rundll32 no Command Line Arguments - Rule", "ESCU - Suspicious SearchProtocolHost no Command Line Arguments - Rule", "ESCU - Suspicious microsoft workflow compiler rename - Rule", "ESCU - Suspicious msbuild path - Rule"]
detection_searches = ["ESCU - Cobalt Strike Named Pipes - Rule", "ESCU - DLLHost with no Command Line Arguments with Network - Rule", "ESCU - Detect Regsvr32 Application Control Bypass - Rule", "ESCU - GPUpdate with no Command Line Arguments with Network - Rule", "ESCU - Rundll32 with no Command Line Arguments with Network - Rule", "ESCU - SearchProtocolHost with no Command Line with Network - Rule", "ESCU - Suspicious DLLHost no Command Line Arguments - Rule", "ESCU - Suspicious GPUpdate no Command Line Arguments - Rule", "ESCU - Suspicious MSBuild Rename - Rule", "ESCU - Suspicious Rundll32 StartW - Rule", "ESCU - Suspicious Rundll32 no Command Line Arguments - Rule", "ESCU - Suspicious SearchProtocolHost no Command Line Arguments - Rule", "ESCU - Suspicious microsoft workflow compiler rename - Rule", "ESCU - Suspicious msbuild path - Rule"]
mappings = {"cis20": ["CIS 16", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Exploitation"], "mitre_attack": ["T1036.003", "T1055", "T1127", "T1127.001", "T1218.010", "T1218.011"], "nist": ["DE.CM", "PR.PT"]}
investigative_searches = []
support_searches = []
@@ -325,7 +325,7 @@ version = 1
reference = ["https://www.intego.com/mac-security-blog/osxcoldroot-and-the-rat-invasion/", "https://objective-see.com/blog/blog_0x2A.html", "https://www.bleepingcomputer.com/news/security/coldroot-rat-still-undetectable-despite-being-uploaded-on-github-two-years-ago/"]
detection_searches = ["ESCU - Osquery pack - ColdRoot detection - Rule", "ESCU - Processes Tapping Keyboard Events - Rule"]
mappings = {"cis20": ["CIS 4", "CIS 8"], "kill_chain_phases": ["Command and Control", "Installation"], "nist": ["DE.CM", "DE.DP", "PR.PT"]}
investigative_searches = ["ESCU - Get Notable History - Response Task", "ESCU - Investigate Network Traffic From src ip - Response Task"]
investigative_searches = ["ESCU - Investigate Network Traffic From src ip - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = []
data_models = []
providing_technologies = none
@@ -344,7 +344,7 @@ version = 1
reference = ["https://attack.mitre.org/wiki/Collection", "https://attack.mitre.org/wiki/Technique/T1074"]
detection_searches = ["ESCU - Email files written outside of the Outlook directory - Rule", "ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Hosts receiving high volume of network traffic from email server - Rule", "ESCU - Suspicious writes to System Volume Information - Rule", "ESCU - Suspicious writes to windows Recycle Bin - Rule"]
mappings = {"cis20": ["CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1036", "T1114.001", "T1114.002"], "nist": ["DE.AE", "DE.CM", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = []
data_models = ["Endpoint", "Network_Traffic"]
providing_technologies = none
@@ -363,8 +363,8 @@ version = 1
reference = ["https://attack.mitre.org/wiki/Command_and_Control", "https://searchsecurity.techtarget.com/feature/Command-and-control-servers-The-puppet-masters-that-govern-malware"]
detection_searches = ["ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Detect Large Outbound ICMP Packets - Rule", "ESCU - Detect Long DNS TXT Record Response - Rule", "ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Detection of DNS Tunnels - Rule", "ESCU - Excessive DNS Failures - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - TOR Traffic - Rule"]
mappings = {"cis20": ["CIS 1", "CIS 11", "CIS 12", "CIS 13", "CIS 3", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Delivery"], "mitre_attack": ["T1048", "T1048.003", "T1071.001", "T1071.004", "T1095", "T1189"], "nist": ["DE.AE", "DE.CM", "ID.AM", "PR.AC", "PR.DS", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task", "ESCU - Get Parent Process Info - Response Task"]
support_searches = ["ESCU - Baseline of DNS Query Length - MLTK", "ESCU - Baseline of blocked outbound traffic from AWS"]
investigative_searches = ["ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Info - Response Task"]
support_searches = ["ESCU - Baseline of blocked outbound traffic from AWS", "ESCU - Baseline of DNS Query Length - MLTK"]
data_models = ["Network_Resolution", "Network_Traffic"]
providing_technologies = none
description = Detect and investigate tactics, techniques, and procedures leveraged by attackers to establish and operate command and control channels. Implants installed by attackers on compromised endpoints use these channels to receive instructions and send data back to the malicious operators.
@@ -414,9 +414,9 @@ modification_date = 2020-02-04
id = 854d78bf-d0e2-4f4e-b05c-640905f86d7a
version = 3
reference = ["https://attack.mitre.org/wiki/Technique/T1003", "https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for.html"]
detection_searches = ["ESCU - Access LSASS Memory for Dump Creation - Rule", "ESCU - Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - Create Remote Thread into LSASS - Rule", "ESCU - Creation of Shadow Copy - Rule", "ESCU - Creation of Shadow Copy with wmic and powershell - Rule", "ESCU - Creation of lsass Dump with Taskmgr - Rule", "ESCU - Credential Dumping via Copy Command from Shadow Copy - Rule", "ESCU - Credential Dumping via Symlink to Shadow Copy - Rule", "ESCU - Detect Credential Dumping through LSASS access - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Unsigned Image Loaded by LSASS - Rule"]
detection_searches = ["ESCU - Access LSASS Memory for Dump Creation - Rule", "ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - Create Remote Thread into LSASS - Rule", "ESCU - Creation of Shadow Copy - Rule", "ESCU - Creation of Shadow Copy with wmic and powershell - Rule", "ESCU - Creation of lsass Dump with Taskmgr - Rule", "ESCU - Credential Dumping via Copy Command from Shadow Copy - Rule", "ESCU - Credential Dumping via Symlink to Shadow Copy - Rule", "ESCU - Detect Credential Dumping through LSASS access - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Unsigned Image Loaded by LSASS - Rule"]
mappings = {"cis20": ["CIS 16", "CIS 3", "CIS 5", "CIS 6", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Installation"], "mitre_attack": ["T1003.001", "T1003.002", "T1003.003", "T1059.001"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.IP"]}
investigative_searches = ["ESCU - Investigate Pass the Hash Attempts - Response Task", "ESCU - Investigate Previous Unseen User - Response Task", "ESCU - Investigate Failed Logins for Multiple Destinations - Response Task", "ESCU - Investigate Pass the Ticket Attempts - Response Task"]
investigative_searches = ["ESCU - Investigate Pass the Hash Attempts - Response Task", "ESCU - Investigate Pass the Ticket Attempts - Response Task", "ESCU - Investigate Failed Logins for Multiple Destinations - Response Task", "ESCU - Investigate Previous Unseen User - Response Task"]
support_searches = []
data_models = ["Endpoint"]
providing_technologies = none
@@ -435,8 +435,8 @@ version = 2
reference = ["https://www.us-cert.gov/ncas/alerts/TA18-074A"]
detection_searches = ["ESCU - Create local admin accounts using net exe - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Scheduled Task Deleted Or Created via CMD - Rule", "ESCU - Single Letter Process On Endpoint - Rule", "ESCU - Suspicious Reg exe Process - Rule"]
mappings = {"cis20": ["CIS 12", "CIS 16", "CIS 2", "CIS 3", "CIS 5", "CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Installation"], "mitre_attack": ["T1021.002", "T1053.005", "T1059.001", "T1059.003", "T1071.002", "T1112", "T1136.001", "T1204.002", "T1543.003", "T1547.001", "T1562.004"], "nist": ["DE.AE", "DE.CM", "ID.AM", "PR.AC", "PR.AT", "PR.DS", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Process File Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task"]
support_searches = ["ESCU - Previously seen command line arguments", "ESCU - Baseline of SMB Traffic - MLTK"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process File Activity - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Process Info - Response Task"]
support_searches = ["ESCU - Baseline of SMB Traffic - MLTK", "ESCU - Previously seen command line arguments"]
data_models = ["Endpoint", "Network_Traffic"]
providing_technologies = none
description = Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA18-074A. Some of the activities that adversaries used in these compromises included spearfishing attacks, malware, watering-hole domains, many and more.
@@ -473,7 +473,7 @@ version = 1
reference = ["https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html", "https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/", "http://www.noip.com/blog/2014/07/11/dynamic-dns-can-use-2/", "https://www.splunk.com/blog/2015/08/04/detecting-dynamic-dns-domains-in-splunk.html"]
detection_searches = ["ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - DNS record changed - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule"]
mappings = {"cis20": ["CIS 1", "CIS 12", "CIS 13", "CIS 3", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control"], "mitre_attack": ["T1048.003", "T1071.004", "T1189"], "nist": ["DE.AE", "DE.CM", "ID.AM", "PR.DS", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - DNS Hijack Enrichment - Response Task", "ESCU - Get DNS Server History for a host - Response Task"]
investigative_searches = ["ESCU - Get DNS Server History for a host - Response Task", "ESCU - DNS Hijack Enrichment - Response Task"]
support_searches = ["ESCU - Discover DNS records"]
data_models = ["Network_Resolution"]
providing_technologies = none
@@ -515,7 +515,7 @@ version = 1
reference = ["https://www.cisecurity.org/controls/data-protection/", "https://www.sans.org/reading-room/whitepapers/dns/splunk-detect-dns-tunneling-37022", "https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/"]
detection_searches = ["ESCU - Detect USB device insertion - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Detection of DNS Tunnels - Rule"]
mappings = {"cis20": ["CIS 12", "CIS 13", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Installation"], "mitre_attack": ["T1048.003", "T1189"], "nist": ["DE.AE", "DE.CM", "PR.DS", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"]
investigative_searches = ["ESCU - Get Notable History - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Info - Response Task"]
support_searches = []
data_models = ["Change_Analysis", "Network_Resolution"]
providing_technologies = none
@@ -566,8 +566,8 @@ version = 2
reference = ["https://attack.mitre.org/wiki/Technique/T1089", "https://blog.malwarebytes.com/cybercrime/2015/11/vonteera-adware-uses-certificates-to-disable-anti-malware/", "https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Tools-Report.pdf"]
detection_searches = ["ESCU - Attempt To Add Certificate To Untrusted Store - Rule", "ESCU - Attempt To Stop Security Service - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - Unload Sysmon Filter Driver - Rule"]
mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Installation"], "mitre_attack": ["T1112", "T1543.003", "T1553.004", "T1562.001", "T1562.004"], "nist": ["DE.CM", "PR.AC", "PR.AT", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task"]
support_searches = ["ESCU - Previously seen command line arguments", "ESCU - Baseline of SMB Traffic - MLTK"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = ["ESCU - Baseline of SMB Traffic - MLTK", "ESCU - Previously seen command line arguments"]
data_models = ["Endpoint"]
providing_technologies = none
description = Looks for activities and techniques associated with the disabling of security tools on a Windows system, such as suspicious `reg.exe` processes, processes launching netsh, and many others.
@@ -600,7 +600,7 @@ version = 2
reference = ["https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html", "https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/", "http://www.noip.com/blog/2014/07/11/dynamic-dns-can-use-2/", "https://www.splunk.com/blog/2015/08/04/detecting-dynamic-dns-domains-in-splunk.html"]
detection_searches = ["ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Detect web traffic to dynamic domain providers - Rule"]
mappings = {"cis20": ["CIS 12", "CIS 13", "CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control"], "mitre_attack": ["T1071.001", "T1189"], "nist": ["DE.AE", "DE.CM", "DE.DP", "PR.DS", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get DNS Server History for a host - Response Task"]
investigative_searches = ["ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"]
support_searches = []
data_models = ["Network_Resolution", "Web"]
providing_technologies = none
@@ -617,7 +617,7 @@ version = 1
reference = ["https://www.us-cert.gov/ncas/alerts/TA18-201A", "https://www.first.org/resources/papers/conf2017/Advanced-Incident-Detection-and-Threat-Hunting-using-Sysmon-and-Splunk.pdf", "https://www.vkremez.com/2017/05/emotet-banking-trojan-malware-analysis.html"]
detection_searches = ["ESCU - Detect Rare Executables - Rule", "ESCU - Detect Use of cmd exe to Launch Script Interpreters - Rule", "ESCU - Detection of tools built by NirSoft - Rule", "ESCU - Email Attachments With Lots Of Spaces - Rule", "ESCU - Prohibited Software On Endpoint - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Suspicious Email Attachment Extensions - Rule"]
mappings = {"cis20": ["CIS 12", "CIS 2", "CIS 3", "CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Delivery", "Exploitation", "Installation"], "mitre_attack": ["T1021.002", "T1059.003", "T1072", "T1547.001", "T1566.001"], "nist": ["DE.AE", "DE.CM", "ID.AM", "PR.DS", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Process Info - Response Task"]
support_searches = ["ESCU - Baseline of SMB Traffic - MLTK"]
data_models = ["Email", "Endpoint", "Network_Traffic"]
providing_technologies = none
@@ -670,7 +670,7 @@ modification_date = 2021-03-03
id = beae2ab0-7c3f-11eb-8b63-acde48001122
version = 1
reference = ["https://www.splunk.com/en_us/blog/security/detecting-hafnium-exchange-server-zero-day-activity-in-splunk.html", "https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/", "https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/", "https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/"]
detection_searches = ["ESCU - Any Powershell DownloadString - Rule", "ESCU - Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Detect Exchange Web Shell - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Nishang PowershellTCPOneLine - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Unified Messaging Service Spawning a Process - Rule", "ESCU - W3WP Spawning Shell - Rule"]
detection_searches = ["ESCU - Any Powershell DownloadString - Rule", "ESCU - Detect Exchange Web Shell - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Nishang PowershellTCPOneLine - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Unified Messaging Service Spawning a Process - Rule", "ESCU - W3WP Spawning Shell - Rule"]
mappings = {"cis20": ["CIS 16", "CIS 3", "CIS 5", "CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Exploitation", "Installation"], "mitre_attack": ["T1003.001", "T1003.003", "T1021.002", "T1059.001", "T1114.002", "T1136.001", "T1190", "T1505.003"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.IP", "PR.PT"]}
investigative_searches = []
support_searches = []
@@ -691,8 +691,8 @@ version = 2
reference = ["https://www.us-cert.gov/HIDDEN-COBRA-North-Korean-Malicious-Cyber-Activity", "https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Destructive-Malware-Report.pdf"]
detection_searches = ["ESCU - Create or delete windows shares using net exe - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Remote Desktop Process Running On System - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Suspicious File Write - Rule"]
mappings = {"cis20": ["CIS 12", "CIS 16", "CIS 3", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control"], "mitre_attack": ["T1021.001", "T1021.002", "T1048.003", "T1059.001", "T1059.003", "T1070.005", "T1071.002", "T1071.004"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Outbound Emails to Hidden Cobra Threat Actors - Response Task", "ESCU - Get Parent Process Info - Response Task"]
support_searches = ["ESCU - Baseline of DNS Query Length - MLTK", "ESCU - Previously seen command line arguments", "ESCU - Baseline of SMB Traffic - MLTK"]
investigative_searches = ["ESCU - Get Outbound Emails to Hidden Cobra Threat Actors - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Info - Response Task"]
support_searches = ["ESCU - Baseline of SMB Traffic - MLTK", "ESCU - Previously seen command line arguments", "ESCU - Baseline of DNS Query Length - MLTK"]
data_models = ["Endpoint", "Network_Resolution", "Network_Traffic"]
providing_technologies = none
description = Monitor for and investigate activities, including the creation or deletion of hidden shares and file writes, that may be evidence of infiltration by North Korean government-sponsored cybercriminals. Details of this activity were reported in DHS Report TA-18-149A.
@@ -711,7 +711,7 @@ version = 1
reference = ["https://blog.malwarebytes.com/cybercrime/2016/09/hosts-file-hijacks/"]
detection_searches = ["ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Windows hosts file modification - Rule"]
mappings = {"cis20": ["CIS 1", "CIS 12", "CIS 13", "CIS 3", "CIS 8", "CIS 9"], "kill_chain_phases": ["Command and Control"], "mitre_attack": ["T1048.003", "T1071.004"], "nist": ["DE.AE", "DE.CM", "ID.AM", "PR.AC", "PR.DS", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Notable History - Response Task", "ESCU - Get DNS Server History for a host - Response Task"]
investigative_searches = ["ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = []
data_models = ["Network_Resolution"]
providing_technologies = none
@@ -776,7 +776,7 @@ version = 1
reference = ["https://github.com/splunk/cloud-datamodel-security-research"]
detection_searches = ["ESCU - Amazon EKS Kubernetes Pod scan detection - Rule", "ESCU - Amazon EKS Kubernetes cluster scan detection - Rule", "ESCU - GCP Kubernetes cluster pod scan detection - Rule", "ESCU - GCP Kubernetes cluster scan detection - Rule", "ESCU - Kubernetes Azure pod scan fingerprint - Rule", "ESCU - Kubernetes Azure scan fingerprint - Rule"]
mappings = {"kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1526"]}
investigative_searches = ["ESCU - GCP Kubernetes activity by src ip - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Amazon EKS Kubernetes activity by src ip - Response Task"]
investigative_searches = ["ESCU - GCP Kubernetes activity by src ip - Response Task", "ESCU - Amazon EKS Kubernetes activity by src ip - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = []
data_models = []
providing_technologies = none
@@ -827,7 +827,7 @@ version = 2
reference = ["https://www.fireeye.com/blog/executive-perspective/2015/08/malware_lateral_move.html"]
detection_searches = ["ESCU - Detect Activity Related to Pass the Hash Attacks - Rule", "ESCU - Kerberoasting spn request with RC4 encryption - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Remote Desktop Process Running On System - Rule", "ESCU - Schtasks scheduling job on remote system - Rule"]
mappings = {"cis20": ["CIS 16", "CIS 3", "CIS 5", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1021.001", "T1053.005", "T1550.002", "T1558.003"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.AT", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Parent Process Info - Response Task"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Process Info - Response Task"]
support_searches = []
data_models = ["Endpoint", "Network_Traffic"]
providing_technologies = none
@@ -846,9 +846,9 @@ modification_date = 2017-08-23
id = 2c8ff66e-0b57-42af-8ad7-912438a403fc
version = 4
reference = ["https://blogs.mcafee.com/mcafee-labs/malware-employs-powershell-to-infect-systems/", "https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/"]
detection_searches = ["ESCU - Any Powershell DownloadFile - Rule", "ESCU - Any Powershell DownloadString - Rule", "ESCU - Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Malicious PowerShell Process - Encoded Command - Rule", "ESCU - Malicious PowerShell Process - Multiple Suspicious Command-Line Arguments - Rule", "ESCU - Malicious PowerShell Process With Obfuscation Techniques - Rule"]
detection_searches = ["ESCU - Any Powershell DownloadFile - Rule", "ESCU - Any Powershell DownloadString - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Malicious PowerShell Process - Encoded Command - Rule", "ESCU - Malicious PowerShell Process - Multiple Suspicious Command-Line Arguments - Rule", "ESCU - Malicious PowerShell Process With Obfuscation Techniques - Rule", "ESCU - Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule"]
mappings = {"cis20": ["CIS 3", "CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Exploitation", "Installation"], "mitre_attack": ["T1027", "T1059.001"], "nist": ["DE.CM", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get History Of Email Sources - Response Task"]
support_searches = []
data_models = ["Endpoint"]
providing_technologies = none
@@ -874,8 +874,8 @@ version = 1
reference = ["https://www.carbonblack.com/2016/03/04/tracking-locky-ransomware-using-carbon-black/"]
detection_searches = ["ESCU - Extended Period Without Successful Netbackup Backups - Rule", "ESCU - Unsuccessful Netbackup backups - Rule"]
mappings = {"cis20": ["CIS 10"], "nist": ["PR.IP"]}
investigative_searches = ["ESCU - Get Notable History - Response Task", "ESCU - All backup logs for host - Response Task"]
support_searches = ["ESCU - Monitor Successful Backups", "ESCU - Monitor Unsuccessful Backups"]
investigative_searches = ["ESCU - All backup logs for host - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = ["ESCU - Monitor Unsuccessful Backups", "ESCU - Monitor Successful Backups"]
data_models = []
providing_technologies = none
description = Address common concerns when monitoring your backup processes. These searches can help you reduce risks from ransomware, device theft, or denial of physical access to a host by backing up data on endpoints.
@@ -891,7 +891,7 @@ version = 1
reference = ["https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/"]
detection_searches = ["ESCU - Prohibited Software On Endpoint - Rule"]
mappings = {"cis20": ["CIS 2"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Installation"], "nist": ["ID.AM", "PR.DS"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = []
data_models = ["Endpoint"]
providing_technologies = none
@@ -945,8 +945,8 @@ version = 1
reference = ["https://docs.microsoft.com/en-us/previous-versions/tn-archive/bb490939(v=technet.10)", "https://htmlpreview.github.io/?https://github.com/MatthewDemaske/blogbackup/blob/master/netshell.html", "http://blog.jpcert.or.jp/2016/01/windows-commands-abused-by-attackers.html"]
detection_searches = ["ESCU - Processes created by netsh - Rule", "ESCU - Processes launching netsh - Rule"]
mappings = {"cis20": ["CIS 8"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562.004"], "nist": ["DE.CM", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task"]
support_searches = ["ESCU - Previously seen command line arguments", "ESCU - Baseline of SMB Traffic - MLTK"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = ["ESCU - Baseline of SMB Traffic - MLTK", "ESCU - Previously seen command line arguments"]
data_models = ["Endpoint"]
providing_technologies = none
description = Detect activities and various techniques associated with the abuse of `netsh.exe`, which can disable local firewall settings or set up a remote connection to a host from an infected system.
@@ -980,8 +980,8 @@ version = 2
reference = ["https://www.symantec.com/blogs/threat-intelligence/orangeworm-targets-healthcare-us-europe-asia", "https://www.infosecurity-magazine.com/news/healthcare-targeted-by-hacker/"]
detection_searches = ["ESCU - First Time Seen Running Windows Service - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule"]
mappings = {"cis20": ["CIS 2", "CIS 3", "CIS 5", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Installation"], "mitre_attack": ["T1059.001", "T1059.003", "T1543.003", "T1569.002"], "nist": ["DE.AE", "DE.CM", "ID.AM", "PR.AC", "PR.AT", "PR.DS", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task"]
support_searches = ["ESCU - Previously seen command line arguments", "ESCU - Previously Seen Running Windows Services - Update", "ESCU - Previously Seen Running Windows Services - Initial"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get History Of Email Sources - Response Task"]
support_searches = ["ESCU - Previously Seen Running Windows Services - Update", "ESCU - Previously Seen Running Windows Services - Initial", "ESCU - Previously seen command line arguments"]
data_models = ["Endpoint"]
providing_technologies = none
description = Detect activities and various techniques associated with the Orangeworm Attack Group, a group that frequently targets the healthcare industry.
@@ -991,30 +991,6 @@ Healthcare may be a promising target, because it is notoriously behind in techno
This Analytic Story is designed to help you detect and investigate suspicious activities that may be indicative of an Orangeworm attack. One detection search looks for command-line arguments. Another monitors for uses of sc.exe, a non-essential Windows file that can manipulate Windows services. One of the investigative searches helps you get more information on web hosts that you suspect have been compromised.
product = ['Splunk Enterprise', 'Splunk Enterprise Security', 'Splunk Cloud']
[Phishing Payloads]
category = Adversary Tactics
creation_date = 2019-04-29
modification_date = 2019-04-29
id = 57226b40-94f3-4ce5-b101-a75f67759c27
version = 1
reference = ["https://www.fireeye.com/blog/threat-research/2019/04/spear-phishing-campaign-targets-ukraine-government.html"]
detection_searches = ["ESCU - Detect Oulook exe writing a zip file - Rule", "ESCU - Process Creating LNK file in Suspicious Location - Rule"]
mappings = {"cis20": ["CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Installation"], "mitre_attack": ["T1566.001", "T1566.002"], "nist": ["ID.AM", "PR.DS"]}
investigative_searches = ["ESCU - Get Parent Process Info - Response Task"]
support_searches = []
data_models = []
providing_technologies = none
description = Detect signs of malicious payloads that may indicate that your environment has been breached via a phishing attack.
narrative = Despite its simplicity, phishing remains the most pervasive and dangerous cyberthreat. In fact, research shows that as many as [91% of all successful attacks](https://digitalguardian.com/blog/91-percent-cyber-attacks-start-phishing-email-heres-how-protect-against-phishing) are initiated via a phishing email. \
As most people know, these emails use fraudulent domains, [email scraping](https://www.cyberscoop.com/emotet-trojan-phishing-scraping-templates-cofense-geodo/), familiar contact names inserted as senders, and other tactics to lure targets into clicking a malicious link, opening an attachment with a [nefarious payload](https://www.cyberscoop.com/emotet-trojan-phishing-scraping-templates-cofense-geodo/), or entering sensitive personal information that perpetrators may intercept. This attack technique requires a relatively low level of skill and allows adversaries to easily cast a wide net. Worse, because its success relies on the gullibility of humans, it's impossible to completely "automate" it out of your environment. However, you can use ES and ESCU to detect and investigate potentially malicious payloads injected into your environment subsequent to a phishing attack. \
While any kind of file may contain a malicious payload, some are more likely to be perceived as benign (and thus more often escape notice) by the average victim&#151;especially when the attacker sends an email that seems to be from one of their contacts. An example is Microsoft Office files. Most corporate users are familiar with documents with the following suffixes: .doc/.docx (MS Word), .xls/.xlsx (MS Excel), and .ppt/.pptx (MS PowerPoint), so they may click without a second thought, slashing a hole in their organizations' security. \
Following is a typical series of events, according to an [article by Trend Micro](https://blog.trendmicro.com/trendlabs-security-intelligence/rising-trend-attackers-using-lnk-files-download-malware/):\
1. Attacker sends a phishing email. Recipient downloads the attached file, which is typically a .docx or .zip file with an embedded .lnk file\
1. The .lnk file executes a PowerShell script\
1. Powershell executes a reverse shell, rendering the exploit successful </ol>As a side note, adversaries are likely to use a tool like Empire to craft and obfuscate payloads and their post-injection activities, such as [exfiltration, lateral movement, and persistence](https://github.com/EmpireProject/Empire).\
This Analytic Story focuses on detecting signs that a malicious payload has been injected into your environment. For example, one search detects outlook.exe writing a .zip file. Another looks for suspicious .lnk files launching processes.
product = ['Splunk Enterprise', 'Splunk Enterprise Security', 'Splunk Cloud']
[Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns]
category = Adversary Tactics
creation_date = 2020-01-22
@@ -1024,8 +1000,8 @@ version = 1
reference = ["https://www.infosecurity-magazine.com/news/scope-of-mudcarp-attacks-highlight-1/", "http://blog.amossys.fr/badflick-is-not-so-bad.html"]
detection_searches = ["ESCU - First time seen command line argument - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Unusually Long Command Line - Rule"]
mappings = {"cis20": ["CIS 3", "CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control"], "mitre_attack": ["T1059.001", "T1059.003", "T1547.001"], "nist": ["DE.AE", "DE.CM", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task"]
support_searches = ["ESCU - Previously seen command line arguments", "ESCU - Baseline of Command Line Length - MLTK"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get History Of Email Sources - Response Task"]
support_searches = ["ESCU - Baseline of Command Line Length - MLTK", "ESCU - Previously seen command line arguments"]
data_models = ["Endpoint"]
providing_technologies = none
description = Monitor your environment for suspicious behaviors that resemble the techniques employed by the MUDCARP threat group.
@@ -1068,7 +1044,7 @@ version = 1
reference = ["http://www.novetta.com/2015/02/advanced-methods-to-detect-advanced-cyber-attacks-protocol-abuse/"]
detection_searches = ["ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - TOR Traffic - Rule"]
mappings = {"cis20": ["CIS 12", "CIS 13", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Delivery"], "mitre_attack": ["T1048", "T1048.003", "T1071.001", "T1189"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.DS", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Info - Response Task"]
support_searches = []
data_models = ["Network_Resolution", "Network_Traffic"]
providing_technologies = none
@@ -1083,9 +1059,9 @@ modification_date = 2020-02-04
id = cf309d0d-d4aa-4fbb-963d-1e79febd3756
version = 1
reference = ["https://www.carbonblack.com/2017/06/28/carbon-black-threat-research-technical-analysis-petya-notpetya-ransomware/", "https://www.splunk.com/blog/2017/06/27/closing-the-detection-to-mitigation-gap-or-to-petya-or-notpetya-whocares-.html"]
detection_searches = ["ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Scheduled tasks used in BadRabbit ransomware - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Suspicious wevtutil Usage - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - TOR Traffic - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - Windows Event Log Cleared - Rule"]
detection_searches = ["ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Scheduled tasks used in BadRabbit ransomware - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Suspicious wevtutil Usage - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - TOR Traffic - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - WinEvent Scheduled Task Created Within Public Path - Rule", "ESCU - WinEvent Scheduled Task Created to Spawn Shell - Rule", "ESCU - Windows Event Log Cleared - Rule"]
mappings = {"cis20": ["CIS 10", "CIS 12", "CIS 3", "CIS 5", "CIS 6", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Delivery", "Exploitation", "Privilege Escalation"], "mitre_attack": ["T1021.002", "T1036.003", "T1047", "T1048", "T1053.005", "T1070", "T1070.001", "T1071.001", "T1485", "T1490", "T1547.001"], "nist": ["DE.AE", "DE.CM", "DE.DP", "PR.AC", "PR.AT", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Process Info - Response Task"]
support_searches = ["ESCU - Baseline of Command Line Length - MLTK", "ESCU - Baseline of SMB Traffic - MLTK"]
data_models = ["Endpoint", "Network_Traffic"]
providing_technologies = none
@@ -1135,7 +1111,7 @@ modification_date = 2020-11-06
id = 507edc74-13d5-4339-878e-b9744ded1f35
version = 1
reference = ["https://www.splunk.com/en_us/blog/security/detecting-ryuk-using-splunk-attack-range.html", "https://www.crowdstrike.com/blog/big-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/", "https://us-cert.cisa.gov/ncas/alerts/aa20-302a"]
detection_searches = ["ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - NLTest Domain Trust Discovery - Rule", "ESCU - Remote Desktop Network Bruteforce - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Ryuk Test Files Detected - Rule", "ESCU - Ryuk Wake on LAN Command - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - Windows DisableAntiSpyware Registry - Rule", "ESCU - Windows Security Account Manager Stopped - Rule", "ESCU - Windows connhost exe started forcefully - Rule"]
detection_searches = ["ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - NLTest Domain Trust Discovery - Rule", "ESCU - Remote Desktop Network Bruteforce - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Ryuk Test Files Detected - Rule", "ESCU - Ryuk Wake on LAN Command - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - WinEvent Scheduled Task Created Within Public Path - Rule", "ESCU - WinEvent Scheduled Task Created to Spawn Shell - Rule", "ESCU - Windows DisableAntiSpyware Registry - Rule", "ESCU - Windows Security Account Manager Stopped - Rule", "ESCU - Windows connhost exe started forcefully - Rule"]
mappings = {"cis20": ["CIS 12", "CIS 16", "CIS 3", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Delivery", "Exploitation", "Lateral Movement", "Privilege Escalation", "Reconnaissance"], "mitre_attack": ["T1021.001", "T1053.005", "T1059.003", "T1482", "T1485", "T1486", "T1489", "T1490", "T1562.001"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Notable History - Response Task"]
support_searches = []
@@ -1172,7 +1148,7 @@ version = 1
reference = ["https://www.crowdstrike.com/blog/an-in-depth-analysis-of-samsam-ransomware-and-boss-spider/", "https://nakedsecurity.sophos.com/2018/07/31/samsam-the-almost-6-million-ransomware/", "https://thehackernews.com/2018/07/samsam-ransomware-attacks.html"]
detection_searches = ["ESCU - Batch File Write to System32 - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect attackers scanning for vulnerable JBoss servers - Rule", "ESCU - Detect malicious requests to exploit JBoss servers - Rule", "ESCU - File with Samsam Extension - Rule", "ESCU - Prohibited Software On Endpoint - Rule", "ESCU - Remote Desktop Network Bruteforce - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Samsam Test File Write - Rule", "ESCU - Spike in File Writes - Rule"]
mappings = {"cis20": ["CIS 10", "CIS 12", "CIS 16", "CIS 18", "CIS 2", "CIS 3", "CIS 4", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Delivery", "Installation", "Reconnaissance"], "mitre_attack": ["T1021.001", "T1021.002", "T1082", "T1204.002", "T1485", "T1486", "T1490"], "nist": ["DE.AE", "DE.CM", "ID.AM", "ID.RA", "PR.AC", "PR.DS", "PR.IP", "PR.MA", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Parent Process Info - Response Task"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Process Info - Response Task"]
support_searches = []
data_models = ["Endpoint", "Network_Traffic", "Web"]
providing_technologies = none
@@ -1202,6 +1178,30 @@ description = Silver Sparrow, identified by Red Canary Intelligence, is a new fo
narrative = Silver Sparrow works is a dropper and uses typical persistence mechanisms on a Mac. It is cross platform, covering both Intel and Apple M1 architecture. To this date, no implant has been downloaded for malicious purposes. During installation of the update.pkg or updater.pkg file, the malicious software utilizes JavaScript to generate files and scripts on disk for persistence.These files later download a implant from an S3 bucket every hour. This analytic assists with identifying different types of macOS malware families establishing LaunchAgent persistence. Per SentinelOne source, it is predicted that Silver Sparrow is likely selling itself as a mechanism to 3rd party “affiliates” or pay-per-install (PPI) partners, typically seen as commodity adware/malware. Additional indicators and behaviors may be found within the references.
product = ['Splunk Enterprise', 'Splunk Enterprise Security', 'Splunk Cloud']
[Spearphishing Attachments]
category = Adversary Tactics
creation_date = 2019-04-29
modification_date = 2019-04-29
id = 57226b40-94f3-4ce5-b101-a75f67759c27
version = 1
reference = ["https://www.fireeye.com/blog/threat-research/2019/04/spear-phishing-campaign-targets-ukraine-government.html"]
detection_searches = ["ESCU - Detect Outlook exe writing a zip file - Rule", "ESCU - Excel Spawning PowerShell - Rule", "ESCU - Excel Spawning Windows Script Host - Rule", "ESCU - Office Application Spawn rundll32 process - Rule", "ESCU - Office Document Creating Schedule Task - Rule", "ESCU - Office Document Executing Macro Code - Rule", "ESCU - Office Document Spawned Child Process To Download - Rule", "ESCU - Office Product Spawning Rundll32 with no DLL - Rule", "ESCU - Process Creating LNK file in Suspicious Location - Rule", "ESCU - Winword Spawning Cmd - Rule", "ESCU - Winword Spawning PowerShell - Rule"]
mappings = {"cis20": ["CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Exploitation", "Installation"], "mitre_attack": ["T1003.002", "T1566.001", "T1566.002"], "nist": ["ID.AM", "PR.DS"]}
investigative_searches = []
support_searches = []
data_models = ["Endpoint"]
providing_technologies = none
description = Detect signs of malicious payloads that may indicate that your environment has been breached via a phishing attack.
narrative = Despite its simplicity, phishing remains the most pervasive and dangerous cyberthreat. In fact, research shows that as many as [91% of all successful attacks](https://digitalguardian.com/blog/91-percent-cyber-attacks-start-phishing-email-heres-how-protect-against-phishing) are initiated via a phishing email. \
As most people know, these emails use fraudulent domains, [email scraping](https://www.cyberscoop.com/emotet-trojan-phishing-scraping-templates-cofense-geodo/), familiar contact names inserted as senders, and other tactics to lure targets into clicking a malicious link, opening an attachment with a [nefarious payload](https://www.cyberscoop.com/emotet-trojan-phishing-scraping-templates-cofense-geodo/), or entering sensitive personal information that perpetrators may intercept. This attack technique requires a relatively low level of skill and allows adversaries to easily cast a wide net. Worse, because its success relies on the gullibility of humans, it's impossible to completely "automate" it out of your environment. However, you can use ES and ESCU to detect and investigate potentially malicious payloads injected into your environment subsequent to a phishing attack. \
While any kind of file may contain a malicious payload, some are more likely to be perceived as benign (and thus more often escape notice) by the average victim&#151;especially when the attacker sends an email that seems to be from one of their contacts. An example is Microsoft Office files. Most corporate users are familiar with documents with the following suffixes: .doc/.docx (MS Word), .xls/.xlsx (MS Excel), and .ppt/.pptx (MS PowerPoint), so they may click without a second thought, slashing a hole in their organizations' security. \
Following is a typical series of events, according to an [article by Trend Micro](https://blog.trendmicro.com/trendlabs-security-intelligence/rising-trend-attackers-using-lnk-files-download-malware/):\
1. Attacker sends a phishing email. Recipient downloads the attached file, which is typically a .docx or .zip file with an embedded .lnk file\
1. The .lnk file executes a PowerShell script\
1. Powershell executes a reverse shell, rendering the exploit successful </ol>As a side note, adversaries are likely to use a tool like Empire to craft and obfuscate payloads and their post-injection activities, such as [exfiltration, lateral movement, and persistence](https://github.com/EmpireProject/Empire).\
This Analytic Story focuses on detecting signs that a malicious payload has been injected into your environment. For example, one search detects outlook.exe writing a .zip file. Another looks for suspicious .lnk files launching processes.
product = ['Splunk Enterprise', 'Splunk Enterprise Security', 'Splunk Cloud']
[Spectre And Meltdown Vulnerabilities]
category = Vulnerability
creation_date = 2018-01-08
@@ -1254,7 +1254,7 @@ version = 1
reference = ["https://nvd.nist.gov/vuln/detail/CVE-2018-11409", "https://www.splunk.com/view/SP-CAAAP5E#VulnerabilityDescriptionsandRatings", "https://www.exploit-db.com/exploits/44865/"]
detection_searches = ["ESCU - Splunk Enterprise Information Disclosure - Rule"]
mappings = {"cis20": ["CIS 18", "CIS 3", "CIS 4"], "kill_chain_phases": ["Delivery"], "nist": ["DE.CM", "ID.RA", "PR.AC", "PR.IP", "PR.PT", "RS.MI"]}
investigative_searches = ["ESCU - Get Notable History - Response Task", "ESCU - Investigate Network Traffic From src ip - Response Task"]
investigative_searches = ["ESCU - Investigate Network Traffic From src ip - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = []
data_models = []
providing_technologies = none
@@ -1274,8 +1274,8 @@ version = 1
reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"]
detection_searches = ["ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule", "ESCU - Abnormally High AWS Instances Launched by User - Rule", "ESCU - Abnormally High AWS Instances Terminated by User - MLTK - Rule", "ESCU - Abnormally High AWS Instances Terminated by User - Rule", "ESCU - EC2 Instance Started In Previously Unseen Region - Rule", "ESCU - EC2 Instance Started With Previously Unseen User - Rule"]
mappings = {"cis20": ["CIS 1", "CIS 12", "CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004", "T1535"], "nist": ["DE.AE", "DE.DP", "ID.AM"]}
investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task"]
support_searches = ["ESCU - Baseline of Excessive AWS Instances Terminated by User - MLTK", "ESCU - Baseline of Excessive AWS Instances Launched by User - MLTK", "ESCU - Previously Seen EC2 Launches By User", "ESCU - Previously Seen AWS Regions"]
investigative_searches = ["ESCU - Get Notable History - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task"]
support_searches = ["ESCU - Previously Seen EC2 Launches By User", "ESCU - Baseline of Excessive AWS Instances Terminated by User - MLTK", "ESCU - Baseline of Excessive AWS Instances Launched by User - MLTK", "ESCU - Previously Seen AWS Regions"]
data_models = []
providing_technologies = none
description = Use the searches in this Analytic Story to monitor your AWS EC2 instances for evidence of anomalous activity and suspicious behaviors, such as EC2 instances that originate from unusual locations or those launched by previously unseen users (among others). Included investigative searches will help you probe more deeply, when the information warrants it.
@@ -1308,8 +1308,8 @@ version = 2
reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf", "https://www.tripwire.com/state-of-security/security-data-protection/cloud/public-aws-s3-buckets-writable/"]
detection_searches = ["ESCU - Detect New Open S3 Buckets over AWS CLI - Rule", "ESCU - Detect New Open S3 buckets - Rule", "ESCU - Detect S3 access from a new IP - Rule", "ESCU - Detect Spike in S3 Bucket deletion - Rule"]
mappings = {"cis20": ["CIS 13", "CIS 14"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1530"], "nist": ["DE.CM", "DE.DP", "PR.AC", "PR.DS"]}
investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - AWS S3 Bucket details via bucketName - Response Task"]
support_searches = ["ESCU - Baseline of S3 Bucket deletion activity by ARN", "ESCU - Previously seen S3 bucket access by remote IP"]
investigative_searches = ["ESCU - Get Notable History - Response Task", "ESCU - AWS S3 Bucket details via bucketName - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task"]
support_searches = ["ESCU - Previously seen S3 bucket access by remote IP", "ESCU - Baseline of S3 Bucket deletion activity by ARN"]
data_models = []
providing_technologies = none
description = Use the searches in this Analytic Story to monitor your AWS S3 buckets for evidence of anomalous activity and suspicious behaviors, such as detecting open S3 buckets and buckets being accessed from a new IP. The contextual and investigative searches will give you more information, when required.
@@ -1327,7 +1327,7 @@ version = 1
reference = ["https://rhinosecuritylabs.com/aws/hiding-cloudcobalt-strike-beacon-c2-using-amazon-apis/"]
detection_searches = ["ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule"]
mappings = {"cis20": ["CIS 11"], "kill_chain_phases": ["Actions on Objectives", "Command and Control"], "nist": ["DE.AE", "DE.CM", "PR.AC"]}
investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task"]
investigative_searches = ["ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Info - Response Task"]
support_searches = ["ESCU - Baseline of blocked outbound traffic from AWS"]
data_models = []
providing_technologies = none
@@ -1348,7 +1348,7 @@ reference = ["https://aws.amazon.com/blogs/security/aws-cloudtrail-now-tracks-cr
detection_searches = ["ESCU - AWS Cross Account Activity From Previously Unseen Account - Rule", "ESCU - Detect AWS Console Login by New User - Rule", "ESCU - Detect AWS Console Login by User from New City - Rule", "ESCU - Detect AWS Console Login by User from New Country - Rule", "ESCU - Detect AWS Console Login by User from New Region - Rule"]
mappings = {"cis20": ["CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1535"], "nist": ["DE.AE", "DE.DP", "PR.AC", "PR.DS"]}
investigative_searches = ["ESCU - Investigate AWS User Activities by user field - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = ["ESCU - Previously Seen Users In CloudTrail - Update", "ESCU - Previously Seen Users in CloudTrail - Initial", "ESCU - Previously Seen AWS Cross Account Activity - Initial", "ESCU - Previously Seen AWS Cross Account Activity - Update"]
support_searches = ["ESCU - Previously Seen Users In CloudTrail - Update", "ESCU - Previously Seen AWS Cross Account Activity - Update", "ESCU - Previously Seen Users in CloudTrail - Initial", "ESCU - Previously Seen AWS Cross Account Activity - Initial"]
data_models = ["Authentication"]
providing_technologies = none
description = Monitor your cloud authentication events. Searches within this Analytic Story leverage the recent cloud updates to the Authentication data model to help you stay aware of and investigate suspicious login activity.
@@ -1365,8 +1365,8 @@ version = 1
reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"]
detection_searches = ["ESCU - Abnormally High Number Of Cloud Instances Destroyed - Rule", "ESCU - Abnormally High Number Of Cloud Instances Launched - Rule", "ESCU - Cloud Instance Modified By Previously Unseen User - Rule"]
mappings = {"cis20": ["CIS 1", "CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004"], "nist": ["DE.AE", "DE.DP", "ID.AM"]}
investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task"]
support_searches = ["ESCU - Baseline Of Cloud Instances Destroyed", "ESCU - Baseline Of Cloud Instances Launched", "ESCU - Previously Seen Cloud Instance Modifications By User - Initial", "ESCU - Previously Seen Cloud Instance Modifications By User - Update"]
investigative_searches = ["ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task"]
support_searches = ["ESCU - Baseline Of Cloud Instances Launched", "ESCU - Previously Seen Cloud Instance Modifications By User - Initial", "ESCU - Previously Seen Cloud Instance Modifications By User - Update", "ESCU - Baseline Of Cloud Instances Destroyed"]
data_models = ["Change"]
providing_technologies = none
description = Monitor your cloud infrastructure provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your cloud environment.
@@ -1383,7 +1383,7 @@ reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.p
detection_searches = ["ESCU - Cloud Provisioning Activity From Previously Unseen City - Rule", "ESCU - Cloud Provisioning Activity From Previously Unseen Country - Rule", "ESCU - Cloud Provisioning Activity From Previously Unseen IP Address - Rule", "ESCU - Cloud Provisioning Activity From Previously Unseen Region - Rule"]
mappings = {"cis20": ["CIS 1"], "mitre_attack": ["T1078"], "nist": ["ID.AM"]}
investigative_searches = ["ESCU - Get Notable History - Response Task"]
support_searches = ["ESCU - Previously Seen Cloud Provisioning Activity Sources - Update", "ESCU - Previously Seen Cloud Provisioning Activity Sources - Initial"]
support_searches = ["ESCU - Previously Seen Cloud Provisioning Activity Sources - Initial", "ESCU - Previously Seen Cloud Provisioning Activity Sources - Update"]
data_models = ["Change"]
providing_technologies = none
description = Monitor your cloud infrastructure provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your cloud environment.
@@ -1398,10 +1398,10 @@ modification_date = 2020-09-04
id = 1ed5ce7d-5469-4232-92af-89d1a3595b39
version = 1
reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf", "https://redlock.io/blog/cryptojacking-tesla"]
detection_searches = ["ESCU - Abnormally High Number Of Cloud Infrastructure API Calls - Rule", "ESCU - Abnormally High Number Of Cloud Security Group API Calls - Rule", "ESCU - Cloud API Calls From Previously Unseen User Roles - Rule"]
mappings = {"cis20": ["CIS 1", "CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078", "T1078.004"], "nist": ["DE.CM", "DE.DP", "ID.AM", "PR.AC"]}
detection_searches = ["ESCU - AWS IAM AccessDenied Discovery Events - Rule", "ESCU - Abnormally High Number Of Cloud Infrastructure API Calls - Rule", "ESCU - Abnormally High Number Of Cloud Security Group API Calls - Rule", "ESCU - Cloud API Calls From Previously Unseen User Roles - Rule"]
mappings = {"cis20": ["CIS 1", "CIS 16"], "kill_chain_phases": ["Actions on Objectives", "Reconnaissance"], "mitre_attack": ["T1078", "T1078.004", "T1580"], "nist": ["DE.CM", "DE.DP", "ID.AM", "PR.AC"]}
investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task"]
support_searches = ["ESCU - Baseline Of Cloud Security Group API Calls Per User", "ESCU - Previously Seen Cloud API Calls Per User Role - Update", "ESCU - Previously Seen Cloud API Calls Per User Role - Initial", "ESCU - Baseline Of Cloud Infrastructure API Calls Per User"]
support_searches = ["ESCU - Baseline Of Cloud Infrastructure API Calls Per User", "ESCU - Previously Seen Cloud API Calls Per User Role - Initial", "ESCU - Previously Seen Cloud API Calls Per User Role - Update", "ESCU - Baseline Of Cloud Security Group API Calls Per User"]
data_models = ["Change"]
providing_technologies = none
description = Detect and investigate suspicious activities by users and roles in your cloud environments.
@@ -1418,8 +1418,8 @@ version = 2
reference = ["https://attack.mitre.org/wiki/Technique/T1059", "https://www.microsoft.com/en-us/wdsi/threats/macro-malware", "https://www.fireeye.com/content/dam/fireeye-www/services/pdfs/mandiant-apt1-report.pdf"]
detection_searches = ["ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Detect Use of cmd exe to Launch Script Interpreters - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Unusually Long Command Line - Rule"]
mappings = {"cis20": ["CIS 3", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Exploitation"], "mitre_attack": ["T1036.003", "T1059.001", "T1059.003"], "nist": ["DE.CM", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task"]
support_searches = ["ESCU - Previously seen command line arguments", "ESCU - Baseline of Command Line Length - MLTK"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = ["ESCU - Baseline of Command Line Length - MLTK", "ESCU - Previously seen command line arguments"]
data_models = ["Endpoint"]
providing_technologies = none
description = Leveraging the Windows command-line interface (CLI) is one of the most common attack techniques--one that is also detailed in the MITRE ATT&CK framework. Use this Analytic Story to help you identify unusual or suspicious use of the CLI on Windows systems.
@@ -1435,7 +1435,7 @@ version = 1
reference = ["http://blogs.splunk.com/2015/10/01/random-words-on-entropy-and-dns/", "http://www.darkreading.com/analytics/security-monitoring/got-malware-three-signs-revealed-in-dns-traffic/d/d-id/1139680", "https://live.paloaltonetworks.com/t5/Threat-Vulnerability-Articles/What-are-suspicious-DNS-queries/ta-p/71454"]
detection_searches = ["ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Detect Long DNS TXT Record Response - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Detection of DNS Tunnels - Rule", "ESCU - Excessive DNS Failures - Rule"]
mappings = {"cis20": ["CIS 1", "CIS 12", "CIS 13", "CIS 3", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control"], "mitre_attack": ["T1048.003", "T1071.004", "T1189"], "nist": ["DE.AE", "DE.CM", "ID.AM", "PR.DS", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get Parent Process Info - Response Task"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Info - Response Task"]
support_searches = ["ESCU - Baseline of DNS Query Length - MLTK"]
data_models = ["Network_Resolution"]
providing_technologies = none
@@ -1452,7 +1452,7 @@ version = 1
reference = ["https://www.splunk.com/blog/2015/06/26/phishing-hits-a-new-level-of-quality/"]
detection_searches = ["ESCU - Email Attachments With Lots Of Spaces - Rule", "ESCU - Monitor Email For Brand Abuse - Rule", "ESCU - Suspicious Email - UBA Anomaly - Rule", "ESCU - Suspicious Email Attachment Extensions - Rule"]
mappings = {"cis20": ["CIS 12", "CIS 3", "CIS 7"], "kill_chain_phases": ["Delivery"], "mitre_attack": ["T1566", "T1566.001"], "nist": ["DE.AE", "PR.IP"]}
investigative_searches = ["ESCU - Get Notable History - Response Task", "ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Email Info - Response Task"]
investigative_searches = ["ESCU - Get Email Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Emails From Specific Sender - Response Task"]
support_searches = ["ESCU - DNSTwist Domain Names"]
data_models = ["Email", "UEBA"]
providing_technologies = none
@@ -1490,8 +1490,8 @@ version = 2
reference = ["https://redcanary.com/blog/introducing-atomictestharnesses/", "https://redcanary.com/blog/windows-registry-attacks-threat-detection/", "https://attack.mitre.org/techniques/T1218/005/", "https://medium.com/@mbromileyDFIR/malware-monday-aebb456356c5"]
detection_searches = ["ESCU - Detect MSHTA Url in Command Line - Rule", "ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Detect Rundll32 Inline HTA Execution - Rule", "ESCU - Detect mshta inline hta execution - Rule", "ESCU - Detect mshta renamed - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Suspicious mshta child process - Rule", "ESCU - Suspicious mshta spawn - Rule"]
mappings = {"cis20": ["CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Exploitation"], "mitre_attack": ["T1059.003", "T1218.005", "T1547.001"], "nist": ["DE.AE", "DE.CM", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task"]
support_searches = ["ESCU - Previously seen command line arguments", "ESCU - Baseline of Command Line Length - MLTK"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = ["ESCU - Baseline of Command Line Length - MLTK", "ESCU - Previously seen command line arguments"]
data_models = ["Endpoint"]
providing_technologies = none
description = Monitor and detect techniques used by attackers who leverage the mshta.exe process to execute malicious code.
@@ -1519,7 +1519,7 @@ version = 1
reference = ["https://attack.mitre.org/wiki/Technique/T1078", "https://owasp.org/www-community/attacks/Credential_stuffing", "https://searchsecurity.techtarget.com/answer/What-is-a-password-spraying-attack-and-how-does-it-work"]
detection_searches = ["ESCU - Multiple Okta Users With Invalid Credentials From The Same IP - Rule", "ESCU - Okta Account Lockout Events - Rule", "ESCU - Okta Failed SSO Attempts - Rule", "ESCU - Okta User Logins From Multiple Cities - Rule"]
mappings = {"cis20": ["CIS 16"], "mitre_attack": ["T1078.001"], "nist": ["DE.CM"]}
investigative_searches = ["ESCU - Investigate User Activities In Okta - Response Task", "ESCU - Investigate Okta Activity by IP Address - Response Task", "ESCU - Investigate Okta Activity by app - Response Task"]
investigative_searches = ["ESCU - Investigate Okta Activity by app - Response Task", "ESCU - Investigate Okta Activity by IP Address - Response Task", "ESCU - Investigate User Activities In Okta - Response Task"]
support_searches = []
data_models = []
providing_technologies = none
@@ -1553,8 +1553,8 @@ modification_date = 2021-02-03
id = 80a65487-854b-42f1-80a1-935e4c170694
version = 1
reference = ["https://attack.mitre.org/techniques/T1218/011/", "https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md", "https://lolbas-project.github.io/lolbas/Binaries/Rundll32"]
detection_searches = ["ESCU - Detect Rundll32 Application Control Bypass - advpack - Rule", "ESCU - Detect Rundll32 Application Control Bypass - setupapi - Rule", "ESCU - Detect Rundll32 Application Control Bypass - syssetup - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Suspicious Rundll32 Rename - Rule", "ESCU - Suspicious Rundll32 StartW - Rule", "ESCU - Suspicious Rundll32 dllregisterserver - Rule", "ESCU - Suspicious Rundll32 no Command Line Arguments - Rule"]
mappings = {"cis20": ["CIS 16", "CIS 3", "CIS 5", "CIS 8"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1003.001", "T1036.003", "T1218.011"], "nist": ["DE.CM", "PR.PT"]}
detection_searches = ["ESCU - Detect Rundll32 Application Control Bypass - advpack - Rule", "ESCU - Detect Rundll32 Application Control Bypass - setupapi - Rule", "ESCU - Detect Rundll32 Application Control Bypass - syssetup - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Rundll32 with no Command Line Arguments with Network - Rule", "ESCU - Suspicious Rundll32 Rename - Rule", "ESCU - Suspicious Rundll32 StartW - Rule", "ESCU - Suspicious Rundll32 dllregisterserver - Rule", "ESCU - Suspicious Rundll32 no Command Line Arguments - Rule"]
mappings = {"cis20": ["CIS 16", "CIS 3", "CIS 5", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Exploitation"], "mitre_attack": ["T1003.001", "T1036.003", "T1218.011"], "nist": ["DE.CM", "PR.PT"]}
investigative_searches = []
support_searches = []
data_models = ["Endpoint"]
@@ -1572,7 +1572,7 @@ version = 2
reference = ["https://www.blackhat.com/docs/us-15/materials/us-15-Graeber-Abusing-Windows-Management-Instrumentation-WMI-To-Build-A-Persistent%20Asynchronous-And-Fileless-Backdoor-wp.pdf", "https://www.fireeye.com/blog/threat-research/2017/03/wmimplant_a_wmi_ba.html"]
detection_searches = ["ESCU - Process Execution via WMI - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - Remote WMI Command Attempt - Rule", "ESCU - Script Execution via WMI - Rule", "ESCU - WMI Permanent Event Subscription - Rule", "ESCU - WMI Permanent Event Subscription - Sysmon - Rule", "ESCU - WMI Temporary Event Subscription - Rule"]
mappings = {"cis20": ["CIS 3", "CIS 5"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1047", "T1546.003"], "nist": ["PR.AC", "PR.AT", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task", "ESCU - Get Parent Process Info - Response Task"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = []
data_models = ["Endpoint"]
providing_technologies = none
@@ -1591,7 +1591,7 @@ version = 1
reference = ["https://redcanary.com/blog/windows-registry-attacks-threat-detection/", "https://attack.mitre.org/wiki/Technique/T1112"]
detection_searches = ["ESCU - Disabling Remote User Account Control - Rule", "ESCU - Monitor Registry Keys for Print Monitors - Rule", "ESCU - Reg exe used to hide files directories via registry keys - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Registry Keys Used For Privilege Escalation - Rule", "ESCU - Registry Keys for Creating SHIM Databases - Rule", "ESCU - Remote Registry Key modifications - Rule", "ESCU - Suspicious Changes to File Associations - Rule"]
mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 8"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1546.001", "T1546.011", "T1546.012", "T1547.001", "T1547.010", "T1548.002", "T1564.001"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = []
data_models = ["Endpoint"]
providing_technologies = none
@@ -1676,7 +1676,7 @@ version = 1
reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"]
detection_searches = ["ESCU - EC2 Instance Modified With Previously Unseen User - Rule"]
mappings = {"cis20": ["CIS 1"], "mitre_attack": ["T1078.004"], "nist": ["ID.AM"]}
investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task"]
investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = ["ESCU - Previously Seen EC2 Modifications By User"]
data_models = []
providing_technologies = none
@@ -1694,7 +1694,7 @@ version = 2
reference = ["https://www.fireeye.com/blog/threat-research/2017/08/monitoring-windows-console-activity-part-two.html", "https://www.splunk.com/pdfs/technical-briefs/advanced-threat-detection-and-response-tech-brief.pdf", "https://www.sans.org/reading-room/whitepapers/logging/detecting-security-incidents-windows-workstation-event-logs-34262"]
detection_searches = ["ESCU - Detect Rare Executables - Rule", "ESCU - Detect processes used for System Network Configuration Discovery - Rule", "ESCU - RunDLL Loading DLL By Ordinal - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - Uncommon Processes On Endpoint - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Unusually Long Command Line - Rule"]
mappings = {"cis20": ["CIS 2", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Installation"], "mitre_attack": ["T1016", "T1036.003", "T1204.002", "T1218.011"], "nist": ["DE.CM", "ID.AM", "PR.DS", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = ["ESCU - Baseline of Command Line Length - MLTK"]
data_models = ["Endpoint"]
providing_technologies = none
@@ -1713,7 +1713,7 @@ version = 1
reference = ["https://www.monkey.org/~dugsong/dsniff/"]
detection_searches = ["ESCU - Protocols passing authentication in cleartext - Rule"]
mappings = {"cis20": ["CIS 14", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Reconnaissance"], "nist": ["DE.AE", "PR.AC", "PR.DS", "PR.PT"]}
investigative_searches = ["ESCU - Get Notable History - Response Task", "ESCU - Get Process Information For Port Activity - Response Task"]
investigative_searches = ["ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = []
data_models = ["Network_Traffic"]
providing_technologies = none
@@ -1730,7 +1730,7 @@ version = 1
reference = ["https://www.fbi.gov/scams-and-safety/common-fraud-schemes/internet-fraud", "https://www.fbi.gov/news/stories/2017-internet-crime-report-released-050718"]
detection_searches = ["ESCU - Web Fraud - Account Harvesting - Rule", "ESCU - Web Fraud - Anomalous User Clickspeed - Rule", "ESCU - Web Fraud - Password Sharing Across Accounts - Rule"]
mappings = {"cis20": ["CIS 16", "CIS 6"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078", "T1136"], "nist": ["DE.AE", "DE.CM", "DE.DP"]}
investigative_searches = ["ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Web Session Information via session id - Response Task"]
investigative_searches = ["ESCU - Get Web Session Information via session id - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Emails From Specific Sender - Response Task"]
support_searches = []
data_models = []
providing_technologies = none
@@ -1769,7 +1769,7 @@ version = 1
reference = ["https://attack.mitre.org/wiki/Defense_Evasion"]
detection_searches = ["ESCU - Disable Registry Tool - Rule", "ESCU - Disable Show Hidden Files - Rule", "ESCU - Disable Windows Behavior Monitoring - Rule", "ESCU - Disable Windows SmartScreen Protection - Rule", "ESCU - Disabling CMD Application - Rule", "ESCU - Disabling ControlPanel - Rule", "ESCU - Disabling Firewall with Netsh - Rule", "ESCU - Disabling FolderOptions Windows Feature - Rule", "ESCU - Disabling NoRun Windows App - Rule", "ESCU - Disabling Remote User Account Control - Rule", "ESCU - Disabling SystemRestore In Registry - Rule", "ESCU - Disabling Task Manager - Rule", "ESCU - Eventvwr UAC Bypass - Rule", "ESCU - FodHelper UAC Bypass - Rule", "ESCU - Hiding Files And Directories With Attrib exe - Rule", "ESCU - Reg exe used to hide files directories via registry keys - Rule", "ESCU - Remote Registry Key modifications - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - Windows DisableAntiSpyware Registry - Rule"]
mappings = {"cis20": ["CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Delivery", "Exploitation", "Privilege Escalation"], "mitre_attack": ["T1112", "T1222.001", "T1548.002", "T1562.001", "T1564.001"], "nist": ["DE.CM", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = []
data_models = ["Endpoint"]
providing_technologies = none
@@ -1786,7 +1786,7 @@ version = 1
reference = ["https://blog.malwarebytes.com/cybercrime/2013/12/file-extensions-2/", "https://attack.mitre.org/wiki/Technique/T1042"]
detection_searches = ["ESCU - Execution of File With Spaces Before Extension - Rule", "ESCU - Execution of File with Multiple Extensions - Rule", "ESCU - Suspicious Changes to File Associations - Rule"]
mappings = {"cis20": ["CIS 3", "CIS 8"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1036.003", "T1546.001"], "nist": ["DE.CM", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = []
data_models = ["Endpoint"]
providing_technologies = none
@@ -1807,7 +1807,7 @@ version = 2
reference = ["https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/", "https://zeltser.com/security-incident-log-review-checklist/", "http://journeyintoir.blogspot.com/2013/01/re-introducing-usnjrnl.html"]
detection_searches = ["ESCU - Deleting Shadow Copies - Rule", "ESCU - Suspicious wevtutil Usage - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - Windows Event Log Cleared - Rule"]
mappings = {"cis20": ["CIS 10", "CIS 3", "CIS 5", "CIS 6", "CIS 8"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1070", "T1070.001", "T1490"], "nist": ["DE.AE", "DE.CM", "DE.DP", "PR.AC", "PR.AT", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = []
data_models = ["Endpoint"]
providing_technologies = none
@@ -1823,9 +1823,9 @@ modification_date = 2018-05-31
id = 30874d4f-20a1-488f-85ec-5d52ef74e3f9
version = 2
reference = ["http://www.fuzzysecurity.com/tutorials/19.html", "https://www.fireeye.com/blog/threat-research/2010/07/malware-persistence-windows-registry.html", "http://resources.infosecinstitute.com/common-malware-persistence-mechanisms/", "https://www.fireeye.com/blog/threat-research/2017/05/fin7-shim-databases-persistence.html", "https://www.youtube.com/watch?v=dq2Hv7J9fvk"]
detection_searches = ["ESCU - Certutil exe certificate extraction - Rule", "ESCU - Detect Path Interception By Creation Of program exe - Rule", "ESCU - Hiding Files And Directories With Attrib exe - Rule", "ESCU - Monitor Registry Keys for Print Monitors - Rule", "ESCU - Reg exe Manipulating Windows Services Registry Keys - Rule", "ESCU - Reg exe used to hide files directories via registry keys - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Registry Keys for Creating SHIM Databases - Rule", "ESCU - Remote Registry Key modifications - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Shim Database File Creation - Rule", "ESCU - Shim Database Installation With Suspicious Parameters - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule"]
mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Exploitation", "Installation", "Privilege Escalation"], "mitre_attack": ["T1053.005", "T1222.001", "T1543.003", "T1546.011", "T1547.001", "T1547.010", "T1564.001", "T1574.009", "T1574.011"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.AT", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task"]
detection_searches = ["ESCU - Certutil exe certificate extraction - Rule", "ESCU - Detect Path Interception By Creation Of program exe - Rule", "ESCU - Hiding Files And Directories With Attrib exe - Rule", "ESCU - Monitor Registry Keys for Print Monitors - Rule", "ESCU - Reg exe Manipulating Windows Services Registry Keys - Rule", "ESCU - Reg exe used to hide files directories via registry keys - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Registry Keys for Creating SHIM Databases - Rule", "ESCU - Remote Registry Key modifications - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Shedule Task with HTTP Command Arguments - Rule", "ESCU - Shim Database File Creation - Rule", "ESCU - Shim Database Installation With Suspicious Parameters - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - WinEvent Scheduled Task Created Within Public Path - Rule", "ESCU - WinEvent Scheduled Task Created to Spawn Shell - Rule"]
mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Exploitation", "Installation", "Privilege Escalation"], "mitre_attack": ["T1053", "T1053.005", "T1222.001", "T1543.003", "T1546.011", "T1547.001", "T1547.010", "T1564.001", "T1574.009", "T1574.011"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.AT", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = []
data_models = ["Endpoint"]
providing_technologies = none
@@ -1842,7 +1842,7 @@ version = 2
reference = ["https://attack.mitre.org/tactics/TA0004/"]
detection_searches = ["ESCU - Child Processes of Spoolsv exe - Rule", "ESCU - Overwriting Accessibility Binaries - Rule", "ESCU - Registry Keys Used For Privilege Escalation - Rule", "ESCU - Uncommon Processes On Endpoint - Rule"]
mappings = {"cis20": ["CIS 2", "CIS 5", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Exploitation"], "mitre_attack": ["T1068", "T1204.002", "T1546.008", "T1546.012"], "nist": ["DE.CM", "ID.AM", "PR.AC", "PR.DS", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = []
data_models = ["Endpoint"]
providing_technologies = none
@@ -1859,7 +1859,7 @@ version = 3
reference = ["https://attack.mitre.org/wiki/Technique/T1050", "https://attack.mitre.org/wiki/Technique/T1031"]
detection_searches = ["ESCU - First Time Seen Running Windows Service - Rule", "ESCU - Reg exe Manipulating Windows Services Registry Keys - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule"]
mappings = {"cis20": ["CIS 2", "CIS 3", "CIS 5", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Installation"], "mitre_attack": ["T1543.003", "T1569.002", "T1574.011"], "nist": ["DE.AE", "DE.CM", "ID.AM", "PR.AC", "PR.AT", "PR.DS", "PR.IP", "PR.PT"]}
investigative_searches = ["ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task"]
investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"]
support_searches = ["ESCU - Previously Seen Running Windows Services - Update", "ESCU - Previously Seen Running Windows Services - Initial"]
data_models = ["Endpoint"]
providing_technologies = none
+542 -117
View File
File diff suppressed because it is too large Load Diff
+2 -2
View File
@@ -4,7 +4,7 @@
is_configured = false
state = enabled
state_change_requires_restart = false
build = 25653
build = 27110
[triggers]
reload.analytic_stories = simple
@@ -19,7 +19,7 @@ reload.content-version = simple
[launcher]
author = Splunk
version = 3.18.0
version = 3.19.0
description = Explore the Analytic Stories included with ES Content Updates.
[ui]
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-04-14T19:13:35 UTC
# On Date: 2021-04-22T21:35:40 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+1 -1
View File
@@ -1,2 +1,2 @@
[content-version]
version = 3.18.0
version = 3.19.0
+58 -58
View File
@@ -11,7 +11,7 @@ label = AWS Cryptomining
description = Monitor your AWS EC2 instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or EC2 instances started by previously unseen users are just a few examples of potentially malicious behavior.
disabled = 0
panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task", "panel://workbench_panel_get_ec2_launch_details___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task"]
panels = ["panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_ec2_launch_details___response_task", "panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task"]
[panel_group://workbench_panel_group_aws_iam_privilege_escalation]
label = AWS IAM Privilege Escalation
@@ -25,7 +25,7 @@ label = AWS Network ACL Activity
description = Monitor your AWS network infrastructure for bad configurations and malicious activity. Investigative searches help you probe deeper, when the facts warrant it.
disabled = 0
panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_aws_network_interface_details_via_resourceid___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_aws_network_acl_details_from_id___response_task"]
panels = ["panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_aws_network_interface_details_via_resourceid___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_aws_network_acl_details_from_id___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_process_info___response_task"]
[panel_group://workbench_panel_group_aws_security_hub_alerts]
label = AWS Security Hub Alerts
@@ -39,7 +39,7 @@ label = AWS Suspicious Provisioning Activities
description = Monitor your AWS provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your network.
disabled = 0
panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_all_aws_activity_from_city___response_task", "panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_get_all_aws_activity_from_country___response_task", "panel://workbench_panel_get_all_aws_activity_from_region___response_task"]
panels = ["panel://workbench_panel_get_all_aws_activity_from_city___response_task", "panel://workbench_panel_get_all_aws_activity_from_country___response_task", "panel://workbench_panel_get_all_aws_activity_from_region___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task"]
[panel_group://workbench_panel_group_aws_user_monitoring]
label = AWS User Monitoring
@@ -53,7 +53,7 @@ label = Apache Struts Vulnerability
description = Detect and investigate activities--such as unusually long `Content-Type` length, suspicious java classes and web servers executing suspicious processes--consistent with attempts to exploit Apache Struts vulnerabilities.
disabled = 0
panels = ["panel://workbench_panel_investigate_web_posts_from_src___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_investigate_suspicious_strings_in_http_header___response_task"]
panels = ["panel://workbench_panel_investigate_suspicious_strings_in_http_header___response_task", "panel://workbench_panel_investigate_web_posts_from_src___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_asset_tracking]
label = Asset Tracking
@@ -81,7 +81,7 @@ label = Brand Monitoring
description = Detect and investigate activity that may indicate that an adversary is using faux domains to mislead users into interacting with malicious infrastructure. Monitor DNS, email, and web traffic for permutations of your brand name.
disabled = 0
panels = ["panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_emails_from_specific_sender___response_task", "panel://workbench_panel_get_email_info___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task"]
panels = ["panel://workbench_panel_get_email_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_emails_from_specific_sender___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task"]
[panel_group://workbench_panel_group_clop_ransomware]
label = Clop Ransomware
@@ -95,7 +95,7 @@ label = Cloud Cryptomining
description = Monitor your cloud compute instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or compute instances started by previously unseen users are just a few examples of potentially malicious behavior.
disabled = 0
panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task", "panel://workbench_panel_get_ec2_launch_details___response_task", "panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task"]
panels = ["panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_ec2_launch_details___response_task", "panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task"]
[panel_group://workbench_panel_group_cloud_federated_credential_abuse]
label = Cloud Federated Credential Abuse
@@ -116,21 +116,21 @@ label = ColdRoot MacOS RAT
description = Leverage searches that allow you to detect and investigate unusual activities that relate to the ColdRoot Remote Access Trojan that affects MacOS. An example of some of these activities are changing sensative binaries in the MacOS sub-system, detecting process names and executables associated with the RAT, detecting when a keyboard tab is installed on a MacOS machine and more.
disabled = 0
panels = ["panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_investigate_network_traffic_from_src_ip___response_task"]
panels = ["panel://workbench_panel_investigate_network_traffic_from_src_ip___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_collection_and_staging]
label = Collection and Staging
description = Monitor for and investigate activities--such as suspicious writes to the Windows Recycling Bin or email servers sending high amounts of traffic to specific hosts, for example--that may indicate that an adversary is harvesting and exfiltrating sensitive data.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_command_and_control]
label = Command and Control
description = Detect and investigate tactics, techniques, and procedures leveraged by attackers to establish and operate command and control channels. Implants installed by attackers on compromised endpoints use these channels to receive instructions and send data back to the malicious operators.
disabled = 0
panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_aws_network_interface_details_via_resourceid___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_aws_network_acl_details_from_id___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_aws_network_interface_details_via_resourceid___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_aws_network_acl_details_from_id___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_process_info___response_task"]
[panel_group://workbench_panel_group_common_phishing_frameworks]
label = Common Phishing Frameworks
@@ -151,14 +151,14 @@ label = Credential Dumping
description = Uncover activity consistent with credential dumping, a technique wherein attackers compromise systems and attempt to obtain and exfiltrate passwords. The threat actors use these pilfered credentials to further escalate privileges and spread throughout a target environment. The included searches in this Analytic Story are designed to identify attempts to credential dumping.
disabled = 0
panels = ["panel://workbench_panel_investigate_pass_the_hash_attempts___response_task", "panel://workbench_panel_investigate_previous_unseen_user___response_task", "panel://workbench_panel_investigate_failed_logins_for_multiple_destinations___response_task", "panel://workbench_panel_investigate_pass_the_ticket_attempts___response_task"]
panels = ["panel://workbench_panel_investigate_pass_the_hash_attempts___response_task", "panel://workbench_panel_investigate_pass_the_ticket_attempts___response_task", "panel://workbench_panel_investigate_failed_logins_for_multiple_destinations___response_task", "panel://workbench_panel_investigate_previous_unseen_user___response_task"]
[panel_group://workbench_panel_group_dhs_report_ta18_074a]
label = DHS Report TA18-074A
description = Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA18-074A. Some of the activities that adversaries used in these compromises included spearfishing attacks, malware, watering-hole domains, many and more.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_process_file_activity___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_file_activity___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_process_info___response_task"]
[panel_group://workbench_panel_group_dns_amplification_attacks]
label = DNS Amplification Attacks
@@ -172,7 +172,7 @@ label = DNS Hijacking
description = Secure your environment against DNS hijacks with searches that help you detect and investigate unauthorized changes to DNS records.
disabled = 0
panels = ["panel://workbench_panel_dns_hijack_enrichment___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task"]
panels = ["panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_dns_hijack_enrichment___response_task"]
[panel_group://workbench_panel_group_data_exfiltration]
label = Data Exfiltration
@@ -186,7 +186,7 @@ label = Data Protection
description = Fortify your data-protection arsenal--while continuing to ensure data confidentiality and integrity--with searches that monitor for and help you investigate possible signs of data exfiltration.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task"]
panels = ["panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_process_info___response_task"]
[panel_group://workbench_panel_group_deobfuscate_decode_files_or_information]
label = Deobfuscate-Decode Files or Information
@@ -207,7 +207,7 @@ label = Disabling Security Tools
description = Looks for activities and techniques associated with the disabling of security tools on a Windows system, such as suspicious `reg.exe` processes, processes launching netsh, and many others.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_domain_trust_discovery]
label = Domain Trust Discovery
@@ -221,14 +221,14 @@ label = Dynamic DNS
description = Detect and investigate hosts in your environment that may be communicating with dynamic domain providers. Attackers may leverage these services to help them avoid firewall blocks and deny lists.
disabled = 0
panels = ["panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task"]
panels = ["panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task"]
[panel_group://workbench_panel_group_emotet_malware__dhs_report_ta18_201a_]
label = Emotet Malware DHS Report TA18-201A
description = Detect rarely used executables, specific registry paths that may confer malware survivability and persistence, instances where cmd.exe is used to launch script interpreters, and other indicators that the Emotet financial malware has compromised your environment.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_process_info___response_task"]
[panel_group://workbench_panel_group_f5_tmui_rce_cve_2020_5902]
label = F5 TMUI RCE CVE-2020-5902
@@ -256,14 +256,14 @@ label = Hidden Cobra Malware
description = Monitor for and investigate activities, including the creation or deletion of hidden shares and file writes, that may be evidence of infiltration by North Korean government-sponsored cybercriminals. Details of this activity were reported in DHS Report TA-18-149A.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_investigate_successful_remote_desktop_authentications___response_task", "panel://workbench_panel_get_outbound_emails_to_hidden_cobra_threat_actors___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_outbound_emails_to_hidden_cobra_threat_actors___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_investigate_successful_remote_desktop_authentications___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_process_info___response_task"]
[panel_group://workbench_panel_group_host_redirection]
label = Host Redirection
description = Detect evidence of tactics used to redirect traffic from a host to a destination other than the one intended--potentially one that is part of an adversary's attack infrastructure. An example is redirecting communications regarding patches and updates or misleading users into visiting a malicious website.
disabled = 0
panels = ["panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task"]
panels = ["panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_ingress_tool_transfer]
label = Ingress Tool Transfer
@@ -284,7 +284,7 @@ label = Kubernetes Scanning Activity
description = This story addresses detection against Kubernetes cluster fingerprint scan and attack by providing information on items such as source ip, user agent, cluster names.
disabled = 0
panels = ["panel://workbench_panel_gcp_kubernetes_activity_by_src_ip___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_amazon_eks_kubernetes_activity_by_src_ip___response_task"]
panels = ["panel://workbench_panel_gcp_kubernetes_activity_by_src_ip___response_task", "panel://workbench_panel_amazon_eks_kubernetes_activity_by_src_ip___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_kubernetes_sensitive_object_access_activity]
label = Kubernetes Sensitive Object Access Activity
@@ -305,28 +305,28 @@ label = Lateral Movement
description = Detect and investigate tactics, techniques, and procedures around how attackers move laterally within the enterprise. Because lateral movement can expose the adversary to detection, it should be an important focus for security analysts.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_investigate_successful_remote_desktop_authentications___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_investigate_successful_remote_desktop_authentications___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_process_info___response_task"]
[panel_group://workbench_panel_group_malicious_powershell]
label = Malicious PowerShell
description = Attackers are finding stealthy ways "live off the land," leveraging utilities and tools that come standard on the endpoint--such as PowerShell--to achieve their goals without downloading binary files. These searches can help you detect and investigate PowerShell command-line options that may be indicative of malicious intent.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task"]
[panel_group://workbench_panel_group_monitor_backup_solution]
label = Monitor Backup Solution
description = Address common concerns when monitoring your backup processes. These searches can help you reduce risks from ransomware, device theft, or denial of physical access to a host by backing up data on endpoints.
disabled = 0
panels = ["panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_all_backup_logs_for_host___response_task"]
panels = ["panel://workbench_panel_all_backup_logs_for_host___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_monitor_for_unauthorized_software]
label = Monitor for Unauthorized Software
description = Identify and investigate prohibited/unauthorized software or processes that may be concealing malicious behavior within your environment.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_monitor_for_updates]
label = Monitor for Updates
@@ -347,7 +347,7 @@ label = Netsh Abuse
description = Detect activities and various techniques associated with the abuse of `netsh.exe`, which can disable local firewall settings or set up a remote connection to a host from an infected system.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_office_365_detections]
label = Office 365 Detections
@@ -361,35 +361,28 @@ label = Orangeworm Attack Group
description = Detect activities and various techniques associated with the Orangeworm Attack Group, a group that frequently targets the healthcare industry.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
[panel_group://workbench_panel_group_phishing_payloads]
label = Phishing Payloads
description = Detect signs of malicious payloads that may indicate that your environment has been breached via a phishing attack.
disabled = 0
panels = ["panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task"]
[panel_group://workbench_panel_group_possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns]
label = Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns
description = Monitor your environment for suspicious behaviors that resemble the techniques employed by the MUDCARP threat group.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task"]
[panel_group://workbench_panel_group_prohibited_traffic_allowed_or_protocol_mismatch]
label = Prohibited Traffic Allowed or Protocol Mismatch
description = Detect instances of prohibited network traffic allowed in the environment, as well as protocols running on non-standard ports. Both of these types of behaviors typically violate policy and can be leveraged by attackers.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_process_info___response_task"]
[panel_group://workbench_panel_group_ransomware]
label = Ransomware
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to ransomware--spikes in SMB traffic, suspicious wevtutil usage, the presence of common ransomware extensions, and system processes run from unexpected locations, and many others.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_sysmon_wmi_activity_for_host___response_task", "panel://workbench_panel_get_backup_logs_for_endpoint___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_sysmon_wmi_activity_for_host___response_task", "panel://workbench_panel_get_backup_logs_for_endpoint___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_process_info___response_task"]
[panel_group://workbench_panel_group_ransomware_cloud]
label = Ransomware Cloud
@@ -424,7 +417,7 @@ label = SamSam Ransomware
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the SamSam ransomware, including looking for file writes associated with SamSam, RDP brute force attacks, the presence of files with SamSam ransomware extensions, suspicious psexec use, and more.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_backup_logs_for_endpoint___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_investigate_successful_remote_desktop_authentications___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_investigate_successful_remote_desktop_authentications___response_task", "panel://workbench_panel_get_backup_logs_for_endpoint___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_process_info___response_task"]
[panel_group://workbench_panel_group_silver_sparrow]
label = Silver Sparrow
@@ -433,6 +426,13 @@ disabled = 0
panels = ["panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_spearphishing_attachments]
label = Spearphishing Attachments
description = Detect signs of malicious payloads that may indicate that your environment has been breached via a phishing attack.
disabled = 0
panels = ["panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_spectre_and_meltdown_vulnerabilities]
label = Spectre And Meltdown Vulnerabilities
description = Assess and mitigate your systems' vulnerability to Spectre and Meltdown exploitation with the searches in this Analytic Story.
@@ -452,14 +452,14 @@ label = Splunk Enterprise Vulnerability CVE-2018-11409
description = Reduce the risk of CVE-2018-11409, an information disclosure vulnerability within some older versions of Splunk Enterprise, with searches designed to help ensure that your Splunk system does not leak information to authenticated users.
disabled = 0
panels = ["panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_investigate_network_traffic_from_src_ip___response_task"]
panels = ["panel://workbench_panel_investigate_network_traffic_from_src_ip___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_suspicious_aws_ec2_activities]
label = Suspicious AWS EC2 Activities
description = Use the searches in this Analytic Story to monitor your AWS EC2 instances for evidence of anomalous activity and suspicious behaviors, such as EC2 instances that originate from unusual locations or those launched by previously unseen users (among others). Included investigative searches will help you probe more deeply, when the information warrants it.
disabled = 0
panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task", "panel://workbench_panel_get_ec2_launch_details___response_task", "panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task"]
panels = ["panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_ec2_launch_details___response_task", "panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task"]
[panel_group://workbench_panel_group_suspicious_aws_login_activities]
label = Suspicious AWS Login Activities
@@ -473,14 +473,14 @@ label = Suspicious AWS S3 Activities
description = Use the searches in this Analytic Story to monitor your AWS S3 buckets for evidence of anomalous activity and suspicious behaviors, such as detecting open S3 buckets and buckets being accessed from a new IP. The contextual and investigative searches will give you more information, when required.
disabled = 0
panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_aws_s3_bucket_details_via_bucketname___response_task"]
panels = ["panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_aws_s3_bucket_details_via_bucketname___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task"]
[panel_group://workbench_panel_group_suspicious_aws_traffic]
label = Suspicious AWS Traffic
description = Leverage these searches to monitor your AWS network traffic for evidence of anomalous activity and suspicious behaviors, such as a spike in blocked outbound traffic in your virtual private cloud (VPC).
disabled = 0
panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_aws_network_interface_details_via_resourceid___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_aws_network_acl_details_from_id___response_task"]
panels = ["panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_aws_network_interface_details_via_resourceid___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_aws_network_acl_details_from_id___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_process_info___response_task"]
[panel_group://workbench_panel_group_suspicious_cloud_authentication_activities]
label = Suspicious Cloud Authentication Activities
@@ -494,7 +494,7 @@ label = Suspicious Cloud Instance Activities
description = Monitor your cloud infrastructure provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your cloud environment.
disabled = 0
panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task"]
panels = ["panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task"]
[panel_group://workbench_panel_group_suspicious_cloud_provisioning_activities]
label = Suspicious Cloud Provisioning Activities
@@ -515,21 +515,21 @@ label = Suspicious Command-Line Executions
description = Leveraging the Windows command-line interface (CLI) is one of the most common attack techniques--one that is also detailed in the MITRE ATT&CK framework. Use this Analytic Story to help you identify unusual or suspicious use of the CLI on Windows systems.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_suspicious_dns_traffic]
label = Suspicious DNS Traffic
description = Attackers often attempt to hide within or otherwise abuse the domain name system (DNS). You can thwart attempts to manipulate this omnipresent protocol by monitoring for these types of abuses.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_process_info___response_task"]
[panel_group://workbench_panel_group_suspicious_emails]
label = Suspicious Emails
description = Email remains one of the primary means for attackers to gain an initial foothold within the modern enterprise. Detect and investigate suspicious emails in your environment with the help of the searches in this Analytic Story.
disabled = 0
panels = ["panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_emails_from_specific_sender___response_task", "panel://workbench_panel_get_email_info___response_task"]
panels = ["panel://workbench_panel_get_email_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_emails_from_specific_sender___response_task"]
[panel_group://workbench_panel_group_suspicious_gcp_storage_activities]
label = Suspicious GCP Storage Activities
@@ -543,14 +543,14 @@ label = Suspicious MSHTA Activity
description = Monitor and detect techniques used by attackers who leverage the mshta.exe process to execute malicious code.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_suspicious_okta_activity]
label = Suspicious Okta Activity
description = Monitor your Okta environment for suspicious activities. Due to the Covid outbreak, many users are migrating over to leverage cloud services more and more. Okta is a popular tool to manage multiple users and the web-based applications they need to stay productive. The searches in this story will help monitor your Okta environment for suspicious activities and associated user behaviors.
disabled = 0
panels = ["panel://workbench_panel_investigate_user_activities_in_okta___response_task", "panel://workbench_panel_investigate_okta_activity_by_ip_address___response_task", "panel://workbench_panel_investigate_okta_activity_by_app___response_task"]
panels = ["panel://workbench_panel_investigate_okta_activity_by_app___response_task", "panel://workbench_panel_investigate_okta_activity_by_ip_address___response_task", "panel://workbench_panel_investigate_user_activities_in_okta___response_task"]
[panel_group://workbench_panel_group_suspicious_regsvr32_activity]
label = Suspicious Regsvr32 Activity
@@ -571,14 +571,14 @@ label = Suspicious WMI Use
description = Attackers are increasingly abusing Windows Management Instrumentation (WMI), a framework and associated utilities available on all modern Windows operating systems. Because WMI can be leveraged to manage both local and remote systems, it is important to identify the processes executed and the user context within which the activity occurred.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_sysmon_wmi_activity_for_host___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_sysmon_wmi_activity_for_host___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_suspicious_windows_registry_activities]
label = Suspicious Windows Registry Activities
description = Monitor and detect registry changes initiated from remote locations, which can be a sign that an attacker has infiltrated your system.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_suspicious_zoom_child_processes]
label = Suspicious Zoom Child Processes
@@ -606,28 +606,28 @@ label = Unusual AWS EC2 Modifications
description = Identify unusual changes to your AWS EC2 instances that may indicate malicious activity. Modifications to your EC2 instances by previously unseen users is an example of an activity that may warrant further investigation.
disabled = 0
panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task"]
panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_unusual_processes]
label = Unusual Processes
description = Quickly identify systems running new or unusual processes in your environment that could be indicators of suspicious activity. Processes run from unusual locations, those with conspicuously long command lines, and rare executables are all examples of activities that may warrant deeper investigation.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_use_of_cleartext_protocols]
label = Use of Cleartext Protocols
description = Leverage searches that detect cleartext network protocols that may leak credentials or should otherwise be encrypted.
disabled = 0
panels = ["panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task"]
panels = ["panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_web_fraud_detection]
label = Web Fraud Detection
description = Monitor your environment for activity consistent with common attack techniques bad actors use when attempting to compromise web servers or other web-related assets.
disabled = 0
panels = ["panel://workbench_panel_get_emails_from_specific_sender___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_web_session_information_via_session_id___response_task"]
panels = ["panel://workbench_panel_get_web_session_information_via_session_id___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_emails_from_specific_sender___response_task"]
[panel_group://workbench_panel_group_windows_dns_sigred_cve_2020_1350]
label = Windows DNS SIGRed CVE-2020-1350
@@ -641,42 +641,42 @@ label = Windows Defense Evasion Tactics
description = Detect tactics used by malware to evade defenses on Windows endpoints. A few of these include suspicious `reg.exe` processes, files hidden with `attrib.exe` and disabling user-account control, among many others
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_windows_file_extension_and_association_abuse]
label = Windows File Extension and Association Abuse
description = Detect and investigate suspected abuse of file extensions and Windows file associations. Some of the malicious behaviors involved may include inserting spaces before file extensions or prepending the file extension with a different one, among other techniques.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_windows_log_manipulation]
label = Windows Log Manipulation
description = Adversaries often try to cover their tracks by manipulating Windows logs. Use these searches to help you monitor for suspicious activity surrounding log files--an essential component of an effective defense.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_windows_persistence_techniques]
label = Windows Persistence Techniques
description = Monitor for activities and techniques associated with maintaining persistence on a Windows system--a sign that an adversary may have compromised your environment.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_windows_privilege_escalation]
label = Windows Privilege Escalation
description = Monitor for and investigate activities that may be associated with a Windows privilege-escalation attack, including unusual processes running on endpoints, modified registry keys, and more.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"]
[panel_group://workbench_panel_group_windows_service_abuse]
label = Windows Service Abuse
description = Windows services are often used by attackers for persistence and the ability to load drivers or otherwise interact with the Windows kernel. This Analytic Story helps you monitor your environment for indications that Windows services are being modified or created in a suspicious manner.
disabled = 0
panels = ["panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_parent_process_info___response_task"]
panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"]
+95 -7
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-04-14T19:13:35 UTC
# On Date: 2021-04-22T21:35:40 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -339,6 +339,26 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[aws_iam_accessdenied_discovery_events_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[aws_iam_assume_role_policy_brute_force_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[aws_iam_delete_policy_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[aws_iam_failure_group_deletion_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[aws_iam_successful_group_deletion_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[aws_network_access_control_list_created_with_all_open_ports_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -419,10 +439,6 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[attempt_to_stop_security_service_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -571,6 +587,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[dllhost_with_no_command_line_arguments_with_network_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[dns_query_length_outliers___mltk_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -731,11 +751,11 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[detect_oulook_exe_writing_a__zip_file_filter]
[detect_outbound_smb_traffic_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[detect_outbound_smb_traffic_filter]
[detect_outlook_exe_writing_a_zip_file_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -1015,6 +1035,14 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[excel_spawning_powershell_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[excel_spawning_windows_script_host_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[excessive_dns_failures_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -1075,6 +1103,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[gpupdate_with_no_command_line_arguments_with_network_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[hiding_files_and_directories_with_attrib_exe_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -1295,6 +1327,26 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[office_application_spawn_rundll32_process_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[office_document_creating_schedule_task_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[office_document_executing_macro_code_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[office_document_spawned_child_process_to_download_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[office_product_spawning_rundll32_with_no_dll_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[okta_account_lockout_events_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -1419,6 +1471,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[rundll32_with_no_command_line_arguments_with_network_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[ryuk_test_files_detected_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -1467,6 +1523,18 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[searchprotocolhost_with_no_command_line_with_network_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[set_default_powershell_execution_policy_to_unrestricted_or_bypass_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[shedule_task_with_http_command_arguments_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[shim_database_file_creation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -1703,6 +1771,14 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[winevent_scheduled_task_created_within_public_path_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[winevent_scheduled_task_created_to_spawn_shell_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_adfind_exe_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -1727,6 +1803,18 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[winword_spawning_cmd_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[winword_spawning_powershell_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[winword_spawning_windows_script_host_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[aws_detect_attach_to_role_policy_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
+946 -78
View File
File diff suppressed because it is too large Load Diff
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-04-14T19:13:35 UTC
# On Date: 2021-04-22T21:35:40 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+348 -120
View File
File diff suppressed because it is too large Load Diff
+139 -241
View File
@@ -1,107 +1,5 @@
mitre_id,technique,tactics,groups
T1484.002,Domain Trust Modification,Defense Evasion|Privilege Escalation,UNC2452
T1484.001,Group Policy Modification,Defense Evasion|Privilege Escalation,no
T1606.002,SAML Tokens,Credential Access,UNC2452
T1606.001,Web Cookies,Credential Access,UNC2452
T1606,Forge Web Credentials,Credential Access,no
T1059.008,Network Device CLI,Execution,no
T1602.002,Network Device Configuration Dump,Collection,no
T1542.005,TFTP Boot,Defense Evasion|Persistence,no
T1542.004,ROMMONkit,Defense Evasion|Persistence,no
T1602.001,SNMP (MIB Dump),Collection,no
T1602,Data from Configuration Repository,Collection,no
T1601.002,Downgrade System Image,Defense Evasion,no
T1601.001,Patch System Image,Defense Evasion,no
T1601,Modify System Image,Defense Evasion,no
T1600.002,Disable Crypto Hardware,Defense Evasion,no
T1600.001,Reduce Key Space,Defense Evasion,no
T1600,Weaken Encryption,Defense Evasion,no
T1556.004,Network Device Authentication,Credential Access|Defense Evasion,no
T1599.001,Network Address Translation Traversal,Defense Evasion,no
T1599,Network Boundary Bridging,Defense Evasion,no
T1020.001,Traffic Duplication,Exfiltration,no
T1557.002,ARP Cache Poisoning,Credential Access|Collection,Cleaver
T1588.006,Vulnerabilities,Resource Development,no
T1053.006,Systemd Timers,Execution|Persistence|Privilege Escalation,no
T1562.008,Disable Cloud Logs,Defense Evasion,no
T1547.012,Print Processors,Persistence|Privilege Escalation,no
T1598.003,Spearphishing Link,Reconnaissance,no
T1598.002,Spearphishing Attachment,Reconnaissance,no
T1598.001,Spearphishing Service,Reconnaissance,no
T1598,Phishing for Information,Reconnaissance,no
T1597.002,Purchase Technical Data,Reconnaissance,no
T1597.001,Threat Intel Vendors,Reconnaissance,no
T1597,Search Closed Sources,Reconnaissance,no
T1596.005,Scan Databases,Reconnaissance,no
T1596.004,CDNs,Reconnaissance,no
T1596.003,Digital Certificates,Reconnaissance,no
T1596.001,DNS/Passive DNS,Reconnaissance,no
T1596.002,WHOIS,Reconnaissance,no
T1596,Search Open Technical Databases,Reconnaissance,no
T1595.002,Vulnerability Scanning,Reconnaissance,no
T1595.001,Scanning IP Blocks,Reconnaissance,no
T1595,Active Scanning,Reconnaissance,no
T1594,Search Victim-Owned Websites,Reconnaissance,no
T1593.002,Search Engines,Reconnaissance,no
T1593.001,Social Media,Reconnaissance,no
T1593,Search Open Websites/Domains,Reconnaissance,no
T1592.004,Client Configurations,Reconnaissance,no
T1592.003,Firmware,Reconnaissance,no
T1592.002,Software,Reconnaissance,no
T1592.001,Hardware,Reconnaissance,no
T1592,Gather Victim Host Information,Reconnaissance,no
T1591.004,Identify Roles,Reconnaissance,no
T1591.003,Identify Business Tempo,Reconnaissance,no
T1591.001,Determine Physical Locations,Reconnaissance,no
T1591.002,Business Relationships,Reconnaissance,no
T1591,Gather Victim Org Information,Reconnaissance,no
T1590.006,Network Security Appliances,Reconnaissance,no
T1590.005,IP Addresses,Reconnaissance,no
T1590.004,Network Topology,Reconnaissance,no
T1590.003,Network Trust Dependencies,Reconnaissance,no
T1590.002,DNS,Reconnaissance,no
T1590.001,Domain Properties,Reconnaissance,no
T1590,Gather Victim Network Information,Reconnaissance,no
T1589.003,Employee Names,Reconnaissance,no
T1589.002,Email Addresses,Reconnaissance,no
T1589.001,Credentials,Reconnaissance,no
T1589,Gather Victim Identity Information,Reconnaissance,no
T1588.005,Exploits,Resource Development,no
T1588.004,Digital Certificates,Resource Development,no
T1588.003,Code Signing Certificates,Resource Development,Wizard Spider
T1588.002,Tool,Resource Development,no
T1588.001,Malware,Resource Development,Turla|APT1
T1588,Obtain Capabilities,Resource Development,no
T1587.004,Exploits,Resource Development,no
T1587.003,Digital Certificates,Resource Development,APT29|PROMETHIUM
T1587.002,Code Signing Certificates,Resource Development,PROMETHIUM|Patchwork
T1587.001,Malware,Resource Development,UNC2452|Turla|FIN7|Night Dragon|Cleaver
T1587,Develop Capabilities,Resource Development,no
T1586.002,Email Accounts,Resource Development,no
T1586.001,Social Media Accounts,Resource Development,no
T1586,Compromise Accounts,Resource Development,no
T1585.002,Email Accounts,Resource Development,APT1
T1585.001,Social Media Accounts,Resource Development,Cleaver
T1585,Establish Accounts,Resource Development,APT17
T1584.006,Web Services,Resource Development,Turla
T1584.005,Botnet,Resource Development,no
T1584.004,Server,Resource Development,Turla|APT16
T1584.003,Virtual Private Server,Resource Development,Turla
T1584.002,DNS Server,Resource Development,no
T1584.001,Domains,Resource Development,APT1
T1583.006,Web Services,Resource Development,APT17|APT29
T1583.005,Botnet,Resource Development,no
T1583.004,Server,Resource Development,no
T1583.003,Virtual Private Server,Resource Development,TEMP.Veles
T1583.002,DNS Server,Resource Development,no
T1584,Compromise Infrastructure,Resource Development,no
T1583.001,Domains,Resource Development,APT1|APT28
T1583,Acquire Infrastructure,Resource Development,no
T1564.007,VBA Stomping,Defense Evasion,no
T1558.004,AS-REP Roasting,Credential Access,no
T1580,Cloud Infrastructure Discovery,Discovery,no
T1218.012,Verclsid,Defense Evasion,no
T1205.001,Port Knocking,Defense Evasion|Persistence|Command And Control,PROMETHIUM
T1205.001,Port Knocking,Defense Evasion|Persistence|Command And Control,no
T1564.006,Run Virtual Instance,Defense Evasion,no
T1564.005,Hidden File System,Defense Evasion,Strider|Equation
T1556.003,Pluggable Authentication Modules,Credential Access|Defense Evasion,no
@@ -109,7 +7,7 @@ T1574.012,COR_PROFILER,Persistence|Privilege Escalation|Defense Evasion,Blue Moc
T1562.007,Disable or Modify Cloud Firewall,Defense Evasion,no
T1098.004,SSH Authorized Keys,Persistence,no
T1480.001,Environmental Keying,Defense Evasion,APT41|Equation
T1059.007,JavaScript/JScript,Execution,FIN6|APT32|FIN7|Cobalt Group|Molerats|TA505|Silence|Leafminer
T1059.007,JavaScript/JScript,Execution,APT32|FIN7|Cobalt Group|Molerats|TA505|Silence|Leafminer
T1578.004,Revert Cloud Instance,Defense Evasion,no
T1578.003,Delete Cloud Instance,Defense Evasion,no
T1578.001,Create Snapshot,Defense Evasion,no
@@ -126,31 +24,31 @@ T1546.015,Component Object Model Hijacking,Privilege Escalation|Persistence,APT2
T1071.004,DNS,Command And Control,APT39|Tropic Trooper|OilRig|Ke3chang|Cobalt Group|APT18|APT41|FIN7
T1071.003,Mail Protocols,Command And Control,APT32|SilverTerrier|APT28
T1071.002,File Transfer Protocols,Command And Control,APT41|SilverTerrier|Machete|Honeybee
T1071.001,Web Protocols,Command And Control,UNC2452|Sandworm Team|TA505|Rocke|APT39|Tropic Trooper|MuddyWater|Wizard Spider|Inception|APT41|SilverTerrier|Machete|APT28|WIRTE|APT33|FIN4|Night Dragon|APT18|APT38|Threat Group-3390|Ke3chang|Dark Caracal|APT19|Cobalt Group|Rancor|Orangeworm|APT37|Turla|Lazarus Group|APT32|Magic Hound|BRONZE BUTLER|OilRig|Gamaredon Group|Stealth Falcon
T1071.001,Web Protocols,Command And Control,Sandworm Team|TA505|Rocke|APT39|Tropic Trooper|MuddyWater|Wizard Spider|Inception|APT41|SilverTerrier|Machete|APT28|WIRTE|APT33|FIN4|Night Dragon|APT18|APT38|Cobalt Group|APT19|Threat Group-3390|Rancor|Orangeworm|APT37|Ke3chang|Dark Caracal|Turla|Lazarus Group|BRONZE BUTLER|APT32|OilRig|Magic Hound|Gamaredon Group|Stealth Falcon
T1572,Protocol Tunneling,Command And Control,OilRig|Cobalt Group|FIN6
T1048.003,Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol,Exfiltration,Wizard Spider|FIN6|APT32|APT33|Thrip|FIN8|OilRig|Lazarus Group
T1048.002,Exfiltration Over Asymmetric Encrypted Non-C2 Protocol,Exfiltration,UNC2452
T1048.003,Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol,Exfiltration,APT32|APT33|Thrip|FIN8|OilRig|Lazarus Group
T1048.002,Exfiltration Over Asymmetric Encrypted Non-C2 Protocol,Exfiltration,no
T1048.001,Exfiltration Over Symmetric Encrypted Non-C2 Protocol,Exfiltration,no
T1001.003,Protocol Impersonation,Command And Control,Lazarus Group
T1001.002,Steganography,Command And Control,APT29|Axiom
T1001.002,Steganography,Command And Control,Axiom
T1001.001,Junk Data,Command And Control,APT28
T1132.002,Non-Standard Encoding,Command And Control,no
T1132.001,Standard Encoding,Command And Control,Sandworm Team|Tropic Trooper|MuddyWater|APT33|APT19|Lazarus Group|BRONZE BUTLER|Patchwork
T1090.004,Domain Fronting,Command And Control,APT29
T1090.003,Multi-hop Proxy,Command And Control,Inception|FIN4|APT29
T1090.002,External Proxy,Command And Control,APT39|Silence|Soft Cell|MuddyWater|APT3|FIN5|Lazarus Group|menuPass|APT28
T1090.001,Internal Proxy,Command And Control,UNC2452|APT39|Strider
T1090.001,Internal Proxy,Command And Control,APT39|Strider
T1102.003,One-Way Communication,Command And Control,Leviathan
T1102.002,Bidirectional Communication,Command And Control,APT29|Sandworm Team|APT39|APT12|Turla|FIN7|APT37|Magic Hound|Carbanak
T1102.002,Bidirectional Communication,Command And Control,Sandworm Team|APT39|APT12|Turla|FIN7|APT37|Magic Hound|Carbanak
T1102.001,Dead Drop Resolver,Command And Control,Rocke|APT41|BRONZE BUTLER|RTM|Patchwork
T1571,Non-Standard Port,Command And Control,Sandworm Team|Rocke|DarkVishnya|Silence|APT-C-36|Magic Hound|APT33|APT32|TEMP.Veles|Lazarus Group|FIN7
T1074.002,Remote Data Staging,Collection,UNC2452|Threat Group-3390|menuPass|FIN6|Night Dragon|FIN8
T1074.001,Local Data Staging,Collection,Machete|Soft Cell|TEMP.Veles|Honeybee|Dragonfly 2.0|Patchwork|Leviathan|APT3|FIN5|menuPass|Lazarus Group|Threat Group-3390|APT28
T1074.002,Remote Data Staging,Collection,Threat Group-3390|menuPass|FIN6|Night Dragon|FIN8
T1074.001,Local Data Staging,Collection,Machete|Soft Cell|TEMP.Veles|Patchwork|Dragonfly 2.0|Honeybee|Leviathan|APT3|FIN5|menuPass|FIN6|Lazarus Group|Threat Group-3390|APT28
T1078.004,Cloud Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,APT33
T1564.004,NTFS File Attributes,Defense Evasion,APT32
T1564.003,Hidden Window,Defense Evasion,Gorgon Group|Deep Panda|DarkHydrus|CopyKittens|APT19|APT32|APT28|APT3|Magic Hound
T1078.003,Local Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,PROMETHIUM|Tropic Trooper|FIN10|Stolen Pencil|APT32
T1078.002,Domain Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,Wizard Spider|APT29|TA505|APT3|Threat Group-1314
T1078.003,Local Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,Tropic Trooper|FIN10|Stolen Pencil|APT32
T1078.002,Domain Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,TA505|APT3|Threat Group-1314
T1078.001,Default Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,no
T1564.002,Hidden Users,Defense Evasion,no
T1574.006,LD_PRELOAD,Persistence|Privilege Escalation|Defense Evasion,Rocke
@@ -166,37 +64,37 @@ T1574,Hijack Execution Flow,Persistence|Privilege Escalation|Defense Evasion,no
T1069.001,Local Groups,Discovery,Turla|OilRig|admin@338
T1570,Lateral Tool Transfer,Lateral Movement,APT32|Wizard Spider|Turla|FIN10
T1568.003,DNS Calculation,Command And Control,APT12
T1204.002,Malicious File,Execution,FIN6|PROMETHIUM|APT30|Magic Hound|Windshift|APT33|Sandworm Team|Naikon|Whitefly|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Wizard Spider|Mofang|Frankenstein|RTM|Inception|BlackTech|APT-C-36|Machete|admin@338|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Dragonfly 2.0|Dark Caracal|FIN7|APT32|Cobalt Group|DarkHydrus|Patchwork|Rancor|MuddyWater|BRONZE BUTLER|APT19|Gorgon Group|OilRig|Lazarus Group|APT29|menuPass|TA459|FIN8|Elderwood|PLATINUM|Leviathan|APT37|APT28
T1204.001,Malicious Link,Execution,Wizard Spider|Patchwork|Windshift|APT32|Molerats|Mofang|BlackTech|TA505|OilRig|Machete|Leviathan|FIN8|FIN4|Elderwood|Dragonfly 2.0|Cobalt Group|APT39|Night Dragon|APT33|Turla
T1204.002,Malicious File,Execution,Magic Hound|Windshift|APT33|Sandworm Team|Naikon|Whitefly|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Wizard Spider|Mofang|Frankenstein|RTM|Inception|BlackTech|APT-C-36|Machete|admin@338|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|APT19|Dragonfly 2.0|BRONZE BUTLER|Cobalt Group|DarkHydrus|Gorgon Group|Patchwork|OilRig|Dark Caracal|MuddyWater|Lazarus Group|FIN7|APT32|Rancor|APT37|FIN8|APT28|Elderwood|TA459|APT29|Leviathan|menuPass|PLATINUM
T1204.001,Malicious Link,Execution,Patchwork|Windshift|APT32|Molerats|Mofang|BlackTech|TA505|OilRig|Machete|Leviathan|FIN8|FIN4|Elderwood|Dragonfly 2.0|Cobalt Group|APT39|Night Dragon|APT33|Turla
T1195.003,Compromise Hardware Supply Chain,Initial Access,no
T1195.002,Compromise Software Supply Chain,Initial Access,UNC2452|GOLD SOUTHFIELD|Dragonfly|Sandworm Team|APT41
T1195.002,Compromise Software Supply Chain,Initial Access,Sandworm Team|APT41
T1195.001,Compromise Software Dependencies and Development Tools,Initial Access,no
T1568.001,Fast Flux DNS,Command And Control,Machete|TA505
T1568.001,Fast Flux DNS,Command And Control,TA505
T1052.001,Exfiltration over USB,Exfiltration,Tropic Trooper
T1569.002,Service Execution,Execution,Wizard Spider|Blue Mockingbird|APT39|APT41|Silence|FIN6|APT32|Ke3chang|Honeybee
T1569.002,Service Execution,Execution,Blue Mockingbird|APT39|APT41|Silence|FIN6|APT32|Honeybee|Ke3chang
T1569.001,Launchctl,Execution,no
T1569,System Services,Execution,no
T1568.002,Domain Generation Algorithms,Command And Control,APT41
T1568,Dynamic Resolution,Command And Control,UNC2452
T1568,Dynamic Resolution,Command And Control,no
T1011.001,Exfiltration Over Bluetooth,Exfiltration,no
T1567.002,Exfiltration to Cloud Storage,Exfiltration,Leviathan|Turla
T1567.001,Exfiltration to Code Repository,Exfiltration,no
T1059.006,Python,Execution,APT29|Rocke|BRONZE BUTLER|APT39|Dragonfly 2.0|Machete
T1059.005,Visual Basic,Execution,Lazarus Group|APT33|Sandworm Team|Gamaredon Group|Sharpshooter|Molerats|Frankenstein|Inception|APT-C-36|Rancor|Patchwork|MuddyWater|Honeybee|FIN7|APT37|BRONZE BUTLER|APT32|Turla|TA505|Silence|WIRTE|FIN4|Gorgon Group|Cobalt Group|Leviathan|TA459|Magic Hound
T1059.006,Python,Execution,Rocke|BRONZE BUTLER|APT39|Dragonfly 2.0|Machete
T1059.005,Visual Basic,Execution,APT33|Sandworm Team|Gamaredon Group|Sharpshooter|Molerats|Frankenstein|Inception|APT-C-36|Rancor|Patchwork|MuddyWater|Honeybee|FIN7|APT37|BRONZE BUTLER|APT32|Turla|TA505|Silence|WIRTE|FIN4|Cobalt Group|Gorgon Group|Leviathan|TA459|Magic Hound
T1059.004,Unix Shell,Execution,Rocke|APT41
T1059.003,Windows Command Shell,Execution,UNC2452|Wizard Spider|FIN6|TA505|Blue Mockingbird|Tropic Trooper|Frankenstein|OilRig|Lazarus Group|Honeybee|Cobalt Group|FIN7|APT41|Soft Cell|Turla|Silence|APT32|Darkhotel|MuddyWater|APT18|APT38|Gorgon Group|Ke3chang|Dragonfly 2.0|Rancor|Dark Caracal|APT37|APT28|Leviathan|FIN8|Sowbug|Magic Hound|BRONZE BUTLER|menuPass|Threat Group-3390|FIN10|Gamaredon Group|Patchwork|Suckfly|Threat Group-1314|APT3|admin@338|APT1
T1059.003,Windows Command Shell,Execution,TA505|Blue Mockingbird|Tropic Trooper|Frankenstein|OilRig|Lazarus Group|Honeybee|Cobalt Group|FIN7|APT41|Soft Cell|Turla|Silence|APT32|APT39|Darkhotel|MuddyWater|APT18|APT38|Dark Caracal|Gorgon Group|Dragonfly 2.0|Rancor|Ke3chang|APT37|Leviathan|FIN8|APT28|Magic Hound|Sowbug|BRONZE BUTLER|FIN10|Threat Group-3390|menuPass|Gamaredon Group|Suckfly|Patchwork|Threat Group-1314|APT3|admin@338|APT1
T1059.002,AppleScript,Execution,no
T1059.001,PowerShell,Execution,UNC2452|Lazarus Group|Chimera|Blue Mockingbird|APT39|DarkVishnya|Molerats|Wizard Spider|Frankenstein|Inception|Silence|APT41|Kimsuky|Soft Cell|TA505|WIRTE|TEMP.Veles|APT33|Gallmaker|Turla|APT19|DarkHydrus|APT28|Gorgon Group|Thrip|Cobalt Group|Dragonfly 2.0|Leviathan|TA459|MuddyWater|FIN8|Magic Hound|CopyKittens|BRONZE BUTLER|OilRig|FIN10|Threat Group-3390|APT32|FIN7|menuPass|Patchwork|Stealth Falcon|FIN6|Poseidon Group|APT3|APT29|Deep Panda
T1059.001,PowerShell,Execution,Blue Mockingbird|APT39|DarkVishnya|Molerats|Wizard Spider|Frankenstein|Inception|Silence|APT41|Kimsuky|Soft Cell|TA505|WIRTE|TEMP.Veles|APT33|Gallmaker|Turla|APT19|DarkHydrus|APT28|Thrip|Gorgon Group|Cobalt Group|Dragonfly 2.0|Leviathan|TA459|FIN8|MuddyWater|Magic Hound|OilRig|BRONZE BUTLER|CopyKittens|APT32|FIN7|FIN10|Threat Group-3390|menuPass|Patchwork|Stealth Falcon|FIN6|Poseidon Group|APT3|APT29|Deep Panda
T1567,Exfiltration Over Web Service,Exfiltration,no
T1497.003,Time Based Evasion,Defense Evasion|Discovery,no
T1497.002,User Activity Based Checks,Defense Evasion|Discovery,FIN7
T1497.001,System Checks,Defense Evasion|Discovery,Frankenstein
T1498.002,Reflection Amplification,Impact,no
T1498.001,Direct Network Flood,Impact,no
T1566.003,Spearphishing via Service,Initial Access,Lazarus Group|Magic Hound|Windshift|FIN6|OilRig|Dark Caracal
T1566.002,Spearphishing Link,Initial Access,Wizard Spider|APT1|Windshift|Molerats|Mofang|BlackTech|Machete|Kimsuky|TA505|Stolen Pencil|APT39|FIN4|APT32|Night Dragon|APT28|Cobalt Group|Dragonfly 2.0|Turla|OilRig|APT33|Leviathan|Patchwork|Elderwood|APT29|Magic Hound|FIN8
T1566.001,Spearphishing Attachment,Initial Access,APT1|FIN6|APT30|Magic Hound|Windshift|APT33|Sandworm Team|Naikon|Gamaredon Group|Sharpshooter|Molerats|Mofang|Wizard Spider|RTM|Frankenstein|Inception|BlackTech|APT-C-36|APT41|Machete|admin@338|Kimsuky|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Tropic Trooper|Turla|Lazarus Group|Cobalt Group|FIN7|OilRig|BRONZE BUTLER|APT32|Gorgon Group|Rancor|DarkHydrus|APT19|Dragonfly 2.0|FIN8|PLATINUM|MuddyWater|TA459|Leviathan|Elderwood|APT29|APT37|menuPass|APT28|Patchwork
T1566,Phishing,Initial Access,GOLD SOUTHFIELD|Dragonfly
T1566.003,Spearphishing via Service,Initial Access,Magic Hound|Windshift|FIN6|OilRig|Dark Caracal
T1566.002,Spearphishing Link,Initial Access,Windshift|Molerats|Mofang|BlackTech|Machete|Kimsuky|TA505|Stolen Pencil|APT39|FIN4|APT32|Night Dragon|Turla|APT28|Cobalt Group|Dragonfly 2.0|OilRig|APT33|Elderwood|Leviathan|Magic Hound|Patchwork|APT29|FIN8
T1566.001,Spearphishing Attachment,Initial Access,Magic Hound|Windshift|APT33|Sandworm Team|Naikon|Gamaredon Group|Sharpshooter|Molerats|Mofang|Wizard Spider|RTM|Frankenstein|Inception|BlackTech|APT-C-36|APT41|Machete|admin@338|Kimsuky|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Tropic Trooper|Turla|Gorgon Group|Rancor|DarkHydrus|Cobalt Group|FIN7|OilRig|Lazarus Group|APT19|Dragonfly 2.0|BRONZE BUTLER|APT32|FIN8|MuddyWater|APT28|TA459|Leviathan|Patchwork|PLATINUM|Elderwood|APT29|APT37|menuPass
T1566,Phishing,Initial Access,no
T1565.003,Runtime Data Manipulation,Impact,APT38
T1565.002,Transmitted Data Manipulation,Impact,APT38
T1565.001,Stored Data Manipulation,Impact,FIN4|APT38
@@ -206,18 +104,18 @@ T1564,Hide Artifacts,Defense Evasion,no
T1563.002,RDP Hijacking,Lateral Movement,no
T1563.001,SSH Hijacking,Lateral Movement,no
T1563,Remote Service Session Hijacking,Lateral Movement,no
T1518.001,Security Software Discovery,Discovery,Wizard Spider|Turla|Rocke|Frankenstein|The White Company|Cobalt Group|Darkhotel|MuddyWater|Tropic Trooper|FIN8|Patchwork|Naikon
T1518.001,Security Software Discovery,Discovery,Turla|Rocke|Frankenstein|The White Company|Cobalt Group|Darkhotel|MuddyWater|Tropic Trooper|FIN8|Patchwork|Naikon
T1069.003,Cloud Groups,Discovery,no
T1069.002,Domain Groups,Discovery,Turla|Wizard Spider|Inception|OilRig|FIN6|Dragonfly 2.0|Ke3chang
T1087.004,Cloud Account,Discovery,no
T1087.003,Email Account,Discovery,Sandworm Team|TA505
T1087.002,Domain Account,Discovery,Wizard Spider|Chimera|Turla|Sandworm Team|Dragonfly 2.0|OilRig|BRONZE BUTLER|menuPass|FIN6|Poseidon Group|Ke3chang
T1087.002,Domain Account,Discovery,Turla|Sandworm Team|Dragonfly 2.0|OilRig|BRONZE BUTLER|menuPass|FIN6|Poseidon Group|Ke3chang
T1087.001,Local Account,Discovery,Turla|Poseidon Group|OilRig|Ke3chang|APT32|APT1|Threat Group-3390|APT3|admin@338
T1553.004,Install Root Certificate,Defense Evasion,no
T1562.004,Disable or Modify System Firewall,Defense Evasion,UNC2452|Rocke|Lazarus Group|Kimsuky|Dragonfly 2.0|Carbanak
T1562.003,Impair Command History Logging,Defense Evasion,no
T1562.002,Disable Windows Event Logging,Defense Evasion,UNC2452|Threat Group-3390
T1562.001,Disable or Modify Tools,Defense Evasion,UNC2452|Wizard Spider|FIN6|Gamaredon Group|BRONZE BUTLER|Rocke|Kimsuky|Turla|Night Dragon|Gorgon Group|Lazarus Group|Putter Panda
T1562.004,Disable or Modify System Firewall,Defense Evasion,Rocke|Lazarus Group|Kimsuky|Dragonfly 2.0|Carbanak
T1562.003,HISTCONTROL,Defense Evasion,no
T1562.002,Disable Windows Event Logging,Defense Evasion,Threat Group-3390
T1562.001,Disable or Modify Tools,Defense Evasion,Gamaredon Group|BRONZE BUTLER|Rocke|Kimsuky|Turla|Night Dragon|Gorgon Group|Lazarus Group|Putter Panda
T1562,Impair Defenses,Defense Evasion,no
T1003.004,LSA Secrets,Credential Access,OilRig|MuddyWater|menuPass|Leafminer|Ke3chang|Dragonfly 2.0|APT33|Threat Group-3390
T1003.005,Cached Domain Credentials,Credential Access,OilRig|MuddyWater|Leafminer|APT33
@@ -226,8 +124,8 @@ T1561.001,Disk Content Wipe,Impact,Lazarus Group
T1561,Disk Wipe,Impact,no
T1560.003,Archive via Custom Method,Collection,Lazarus Group|Kimsuky|CopyKittens|FIN6
T1560.002,Archive via Library,Collection,Lazarus Group|Threat Group-3390
T1560.001,Archive via Utility,Collection,UNC2452|Chimera|APT41|Soft Cell|Turla|Gallmaker|APT33|APT39|MuddyWater|Magic Hound|FIN8|BRONZE BUTLER|CopyKittens|Sowbug|APT3|menuPass|APT1|Ke3chang
T1560,Archive Collected Data,Collection,menuPass|APT32|Patchwork|APT28|Dragonfly 2.0|Honeybee|FIN6|Lazarus Group|Ke3chang
T1560.001,Archive via Utility,Collection,APT41|Soft Cell|Turla|Gallmaker|APT33|APT39|MuddyWater|Magic Hound|FIN8|BRONZE BUTLER|CopyKittens|APT3|Sowbug|menuPass|APT1|Ke3chang
T1560,Archive Collected Data,Collection,menuPass|APT32|Honeybee|Patchwork|APT28|Dragonfly 2.0|FIN6|Lazarus Group|Ke3chang
T1499.004,Application or System Exploitation,Impact,no
T1499.003,Application Exhaustion Flood,Impact,no
T1499.002,Service Exhaustion Flood,Impact,no
@@ -235,7 +133,7 @@ T1499.001,OS Exhaustion Flood,Impact,no
T1491.002,External Defacement,Impact,no
T1491.001,Internal Defacement,Impact,Lazarus Group
T1114.003,Email Forwarding Rule,Collection,no
T1114.002,Remote Email Collection,Collection,UNC2452|APT1|FIN4|Ke3chang|Leafminer|Dragonfly 2.0|APT28
T1114.002,Remote Email Collection,Collection,APT1|FIN4|APT28|Dragonfly 2.0|Ke3chang|Leafminer
T1114.001,Local Email Collection,Collection,Magic Hound|APT1
T1134.005,SID-History Injection,Defense Evasion|Privilege Escalation,no
T1134.004,Parent PID Spoofing,Defense Evasion|Privilege Escalation,no
@@ -244,93 +142,93 @@ T1134.002,Create Process with Token,Defense Evasion|Privilege Escalation,Turla|L
T1134.001,Token Impersonation/Theft,Defense Evasion|Privilege Escalation,APT28
T1213.002,Sharepoint,Collection,Ke3chang|APT28
T1213.001,Confluence,Collection,no
T1555.003,Credentials from Web Browsers,Credential Access,FIN6|Magic Hound|Sandworm Team|Inception|Stealth Falcon|OilRig|Leafminer|APT33|APT3|Kimsuky|TA505|Stolen Pencil|MuddyWater|APT37|Patchwork|Molerats
T1555.003,Credentials from Web Browsers,Credential Access,Magic Hound|Sandworm Team|Inception|Stealth Falcon|OilRig|Leafminer|APT33|APT3|Kimsuky|TA505|Stolen Pencil|MuddyWater|APT37|Patchwork|Molerats
T1555.002,Securityd Memory,Credential Access,no
T1555.001,Keychain,Credential Access,no
T1559.002,Dynamic Data Exchange,Execution,Sharpshooter|TA505|MuddyWater|Gallmaker|Cobalt Group|Patchwork|APT37|FIN7|APT28
T1559.002,Dynamic Data Exchange,Execution,Sharpshooter|TA505|MuddyWater|Gallmaker|Patchwork|Cobalt Group|APT37|APT28|FIN7
T1559.001,Component Object Model,Execution,Gamaredon Group|MuddyWater
T1559,Inter-Process Communication,Execution,no
T1558.002,Silver Ticket,Credential Access,no
T1558.001,Golden Ticket,Credential Access,Ke3chang
T1558,Steal or Forge Kerberos Tickets,Credential Access,no
T1557.001,LLMNR/NBT-NS Poisoning and SMB Relay,Credential Access|Collection,Wizard Spider
T1557.001,LLMNR/NBT-NS Poisoning and SMB Relay,Credential Access|Collection,no
T1557,Man-in-the-Middle,Credential Access|Collection,no
T1556.002,Password Filter DLL,Credential Access|Defense Evasion,Strider
T1556.001,Domain Controller Authentication,Credential Access|Defense Evasion,Chimera
T1556.001,Domain Controller Authentication,Credential Access|Defense Evasion,no
T1556,Modify Authentication Process,Credential Access|Defense Evasion,no
T1056.004,Credential API Hooking,Collection|Credential Access,PLATINUM
T1056.003,Web Portal Capture,Collection|Credential Access,no
T1056.002,GUI Input Capture,Collection|Credential Access,FIN4
T1056.001,Keylogging,Collection|Credential Access,APT32|Sandworm Team|APT39|APT41|Kimsuky|menuPass|Stolen Pencil|FIN4|APT38|OilRig|Ke3chang|PLATINUM|Sowbug|Magic Hound|Group5|Lazarus Group|Threat Group-3390|APT3|Darkhotel|APT28
T1555,Credentials from Password Stores,Credential Access,UNC2452|FIN6|APT39|OilRig|MuddyWater|Leafminer|APT33|Turla|Stealth Falcon
T1056.001,Keylogging,Collection|Credential Access,APT32|Sandworm Team|APT39|APT41|Kimsuky|menuPass|Stolen Pencil|FIN4|APT38|Ke3chang|OilRig|PLATINUM|Sowbug|Magic Hound|Group5|Lazarus Group|Threat Group-3390|APT3|Darkhotel|APT28
T1555,Credentials from Password Stores,Credential Access,APT39|OilRig|MuddyWater|Leafminer|APT33|Turla|Stealth Falcon
T1552.005,Cloud Instance Metadata API,Credential Access,no
T1003.008,/etc/passwd and /etc/shadow,Credential Access,no
T1003.007,Proc Filesystem,Credential Access,no
T1003.006,DCSync,Credential Access,UNC2452
T1558.003,Kerberoasting,Credential Access,UNC2452|Wizard Spider
T1003.006,DCSync,Credential Access,no
T1558.003,Kerberoasting,Credential Access,no
T1552.006,Group Policy Preferences,Credential Access,APT33
T1003.003,NTDS,Credential Access,Wizard Spider|Chimera|FIN6|Dragonfly 2.0
T1003.002,Security Account Manager,Credential Access,Wizard Spider|Threat Group-3390|Ke3chang|Soft Cell|Night Dragon|Dragonfly 2.0|menuPass
T1003.001,LSASS Memory,Credential Access,Sandworm Team|Whitefly|Blue Mockingbird|Silence|Threat Group-3390|Leviathan|APT41|Soft Cell|TEMP.Veles|APT33|APT39|Stolen Pencil|APT32|Leafminer|Lazarus Group|Magic Hound|MuddyWater|FIN8|PLATINUM|OilRig|BRONZE BUTLER|FIN6|APT3|APT28|APT1|Ke3chang|Cleaver
T1003.003,NTDS,Credential Access,FIN6|Dragonfly 2.0
T1003.002,Security Account Manager,Credential Access,Threat Group-3390|Ke3chang|Soft Cell|Night Dragon|Dragonfly 2.0|menuPass
T1003.001,LSASS Memory,Credential Access,Sandworm Team|Whitefly|Blue Mockingbird|Silence|Threat Group-3390|Leviathan|APT41|Soft Cell|TEMP.Veles|APT33|APT39|Stolen Pencil|APT32|Lazarus Group|Leafminer|Magic Hound|MuddyWater|PLATINUM|FIN8|BRONZE BUTLER|OilRig|FIN6|APT3|APT28|APT1|Ke3chang|Cleaver
T1110.004,Credential Stuffing,Credential Access,no
T1110.003,Password Spraying,Credential Access,APT28|APT33|Leafminer|Lazarus Group
T1110.002,Password Cracking,Credential Access,FIN6|APT41|Dragonfly 2.0|APT3
T1110.001,Password Guessing,Credential Access,APT28
T1021.006,Windows Remote Management,Lateral Movement,UNC2452|Wizard Spider|Threat Group-3390
T1110.003,Password Spraying,Credential Access,APT33|Leafminer|Lazarus Group
T1110.002,Password Cracking,Credential Access,APT41|Dragonfly 2.0|APT3
T1110.001,Password Guessing,Credential Access,no
T1021.006,Windows Remote Management,Lateral Movement,Threat Group-3390
T1021.005,VNC,Lateral Movement,GCMAN
T1021.004,SSH,Lateral Movement,Rocke|TEMP.Veles|Leviathan|APT39|OilRig|menuPass|GCMAN
T1021.003,Distributed Component Object Model,Lateral Movement,no
T1021.002,SMB/Windows Admin Shares,Lateral Movement,Wizard Spider|Chimera|Blue Mockingbird|APT39|APT32|Orangeworm|FIN8|APT3|Lazarus Group|Threat Group-1314|Turla|Deep Panda|Ke3chang
T1021.001,Remote Desktop Protocol,Lateral Movement,Chimera|Blue Mockingbird|Wizard Spider|Silence|APT41|TEMP.Veles|Leviathan|APT39|Stolen Pencil|Cobalt Group|Dragonfly 2.0|FIN8|APT3|OilRig|FIN10|menuPass|Patchwork|FIN6|Lazarus Group|APT1|Axiom
T1021.002,SMB/Windows Admin Shares,Lateral Movement,Blue Mockingbird|APT39|APT32|Orangeworm|FIN8|APT3|Lazarus Group|Threat Group-1314|Turla|Deep Panda|Ke3chang
T1021.001,Remote Desktop Protocol,Lateral Movement,Blue Mockingbird|Wizard Spider|Silence|APT41|TEMP.Veles|Leviathan|APT39|Stolen Pencil|Cobalt Group|Dragonfly 2.0|FIN8|APT3|OilRig|menuPass|FIN10|Patchwork|FIN6|Lazarus Group|APT1|Axiom
T1554,Compromise Client Software Binary,Persistence,no
T1036.006,Space after Filename,Defense Evasion,no
T1036.005,Match Legitimate Name or Location,Defense Evasion,UNC2452|Chimera|PROMETHIUM|Rocke|Sandworm Team|APT39|Blue Mockingbird|Whitefly|Tropic Trooper|Silence|APT41|menuPass|TEMP.Veles|MuddyWater|BRONZE BUTLER|Sowbug|APT32|Patchwork|Poseidon Group|admin@338|Carbanak|APT1
T1036.004,Masquerade Task or Service,Defense Evasion,UNC2452|Lazarus Group|PROMETHIUM|Wizard Spider|APT-C-36|Carbanak|APT32|FIN6|FIN7
T1036.005,Match Legitimate Name or Location,Defense Evasion,Rocke|Sandworm Team|APT39|Blue Mockingbird|Whitefly|Tropic Trooper|Silence|APT41|menuPass|TEMP.Veles|MuddyWater|BRONZE BUTLER|Sowbug|APT32|Patchwork|Poseidon Group|admin@338|Carbanak|APT1
T1036.004,Masquerade Task or Service,Defense Evasion,Wizard Spider|APT-C-36|Carbanak|APT32|FIN6|FIN7
T1036.003,Rename System Utilities,Defense Evasion,menuPass|APT32|Soft Cell|PLATINUM
T1036.002,Right-to-Left Override,Defense Evasion,BRONZE BUTLER|BlackTech|Ke3chang|Scarlet Mimic
T1036.001,Invalid Code Signature,Defense Evasion,Windshift|APT37
T1036.001,Invalid Code Signature,Defense Evasion,Windshift
T1553.003,SIP and Trust Provider Hijacking,Defense Evasion,no
T1553.002,Code Signing,Defense Evasion,UNC2452|Wizard Spider|PROMETHIUM|Patchwork|Silence|APT41|FIN6|TA505|FIN7|Honeybee|Leviathan|CopyKittens|Winnti Group|Suckfly|Molerats|Darkhotel
T1553.002,Code Signing,Defense Evasion,Patchwork|Silence|APT41|FIN6|TA505|FIN7|Honeybee|Leviathan|APT37|CopyKittens|Winnti Group|Suckfly|Molerats|Darkhotel
T1553.001,Gatekeeper Bypass,Defense Evasion,no
T1553,Subvert Trust Controls,Defense Evasion,no
T1027.003,Steganography,Defense Evasion,BRONZE BUTLER|Tropic Trooper|MuddyWater|APT37
T1027.002,Software Packing,Defense Evasion,Lazarus Group|TA505|Rocke|Soft Cell|The White Company|APT39|APT38|Dark Caracal|Elderwood|APT3|Patchwork|APT29|Night Dragon
T1027.001,Binary Padding,Defense Evasion,Gamaredon Group|APT32|Patchwork|Leviathan|BRONZE BUTLER|Moafee
T1027.002,Software Packing,Defense Evasion,TA505|Rocke|Soft Cell|The White Company|APT39|APT38|Dark Caracal|Elderwood|APT3|Patchwork|APT29|Night Dragon
T1027.001,Binary Padding,Defense Evasion,Gamaredon Group|Patchwork|APT32|Leviathan|BRONZE BUTLER|Moafee
T1222.002,Linux and Mac File and Directory Permissions Modification,Defense Evasion,Rocke|APT32
T1222.001,Windows File and Directory Permissions Modification,Defense Evasion,Wizard Spider
T1552.004,Private Keys,Credential Access,UNC2452|Rocke
T1222.001,Windows File and Directory Permissions Modification,Defense Evasion,no
T1552.004,Private Keys,Credential Access,Rocke
T1552.003,Bash History,Credential Access,no
T1552.002,Credentials in Registry,Credential Access,APT32
T1552.001,Credentials In Files,Credential Access,Leafminer|APT33|OilRig|TA505|Stolen Pencil|MuddyWater|APT3
T1552,Unsecured Credentials,Credential Access,no
T1216.001,PubPrn,Defense Evasion,APT32
T1070.006,Timestomp,Defense Evasion,UNC2452|Rocke|TEMP.Veles|APT32|Lazarus Group|APT28
T1070.006,Timestomp,Defense Evasion,Rocke|TEMP.Veles|APT32|Lazarus Group|APT28
T1070.005,Network Share Connection Removal,Defense Evasion,Threat Group-3390
T1070.004,File Deletion,Defense Evasion,UNC2452|FIN6|Sandworm Team|Rocke|Tropic Trooper|Gamaredon Group|Wizard Spider|APT41|Kimsuky|Silence|The White Company|TEMP.Veles|APT32|APT38|Honeybee|Patchwork|Cobalt Group|Dragonfly 2.0|menuPass|FIN8|BRONZE BUTLER|FIN5|APT3|OilRig|Magic Hound|FIN10|APT28|Threat Group-3390|Group5|Lazarus Group|APT18|APT29
T1070.004,File Deletion,Defense Evasion,Sandworm Team|Rocke|Tropic Trooper|Gamaredon Group|Wizard Spider|APT41|Kimsuky|Silence|The White Company|TEMP.Veles|APT32|APT38|Patchwork|Honeybee|Cobalt Group|Dragonfly 2.0|menuPass|FIN8|OilRig|FIN5|BRONZE BUTLER|Magic Hound|APT3|FIN10|APT28|Threat Group-3390|Group5|Lazarus Group|APT18|APT29
T1070.003,Clear Command History,Defense Evasion,APT41
T1550.004,Web Session Cookie,Defense Evasion|Lateral Movement,UNC2452
T1550.004,Web Session Cookie,Defense Evasion|Lateral Movement,no
T1550.001,Application Access Token,Defense Evasion|Lateral Movement,APT28
T1550.003,Pass the Ticket,Defense Evasion|Lateral Movement,APT32|BRONZE BUTLER|APT29
T1550.002,Pass the Hash,Defense Evasion|Lateral Movement,Soft Cell|APT32|Night Dragon|APT28|APT1
T1550,Use Alternate Authentication Material,Defense Evasion|Lateral Movement,UNC2452
T1550,Use Alternate Authentication Material,Defense Evasion|Lateral Movement,no
T1548.004,Elevated Execution with Prompt,Privilege Escalation|Defense Evasion,no
T1548.003,Sudo and Sudo Caching,Privilege Escalation|Defense Evasion,no
T1548.002,Bypass User Account Control,Privilege Escalation|Defense Evasion,APT37|MuddyWater|Honeybee|Cobalt Group|Threat Group-3390|BRONZE BUTLER|Patchwork|APT29
T1548.002,Bypass User Access Control,Privilege Escalation|Defense Evasion,APT37|MuddyWater|Honeybee|Cobalt Group|Threat Group-3390|BRONZE BUTLER|Patchwork|APT29
T1548.001,Setuid and Setgid,Privilege Escalation|Defense Evasion,no
T1548,Abuse Elevation Control Mechanism,Privilege Escalation|Defense Evasion,no
T1136.003,Cloud Account,Persistence,no
T1070.002,Clear Linux or Mac System Logs,Defense Evasion,Rocke
T1070.001,Clear Windows Event Logs,Defense Evasion,APT41|APT38|Dragonfly 2.0|APT32|FIN8|FIN5|APT28
T1136.002,Domain Account,Persistence,Soft Cell
T1136.001,Local Account,Persistence,APT39|APT41|Leafminer|Dragonfly 2.0|APT3
T1136.001,Local Account,Persistence,APT39|APT41|Dragonfly 2.0|Leafminer|APT3
T1547.011,Plist Modification,Persistence|Privilege Escalation,no
T1547.010,Port Monitors,Persistence|Privilege Escalation,no
T1547.009,Shortcut Modification,Persistence|Privilege Escalation,APT39|Darkhotel|APT29|Gorgon Group|Dragonfly 2.0|Leviathan|Lazarus Group
T1547.008,LSASS Driver,Persistence|Privilege Escalation,no
T1547.007,Re-opened Applications,Persistence|Privilege Escalation,no
T1547.006,Kernel Modules and Extensions,Persistence|Privilege Escalation,no
T1547.005,Security Support Provider,Persistence|Privilege Escalation,Lazarus Group
T1547.004,Winlogon Helper DLL,Persistence|Privilege Escalation,Wizard Spider|Tropic Trooper|Turla
T1547.005,Security Support Provider,Persistence|Privilege Escalation,no
T1547.004,Winlogon Helper DLL,Persistence|Privilege Escalation,Tropic Trooper|Turla
T1547.003,Time Providers,Persistence|Privilege Escalation,no
T1546.014,Emond,Privilege Escalation|Persistence,no
T1546.013,PowerShell Profile,Privilege Escalation|Persistence,Turla
@@ -346,30 +244,30 @@ T1546.007,Netsh Helper DLL,Privilege Escalation|Persistence,no
T1546.006,LC_LOAD_DYLIB Addition,Privilege Escalation|Persistence,no
T1546.005,Trap,Privilege Escalation|Persistence,no
T1546.004,.bash_profile and .bashrc,Privilege Escalation|Persistence,no
T1546.003,Windows Management Instrumentation Event Subscription,Privilege Escalation|Persistence,UNC2452|APT33|Blue Mockingbird|Turla|Leviathan|APT29
T1546.003,Windows Management Instrumentation Event Subscription,Privilege Escalation|Persistence,APT33|Blue Mockingbird|Turla|Leviathan|APT29
T1546.002,Screensaver,Privilege Escalation|Persistence,no
T1546.001,Change Default File Association,Privilege Escalation|Persistence,Kimsuky
T1547.001,Registry Run Keys / Startup Folder,Persistence|Privilege Escalation,Wizard Spider|PROMETHIUM|Rocke|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Silence|RTM|Inception|APT41|Machete|Kimsuky|APT33|APT39|APT32|APT18|Turla|Dark Caracal|Cobalt Group|Honeybee|APT19|Ke3chang|Threat Group-3390|Dragonfly 2.0|Gorgon Group|MuddyWater|APT37|Leviathan|BRONZE BUTLER|Magic Hound|APT3|FIN10|FIN7|Patchwork|FIN6|Lazarus Group|Putter Panda|APT29|Darkhotel
T1547.001,Registry Run Keys / Startup Folder,Persistence|Privilege Escalation,Rocke|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Silence|RTM|Inception|APT41|Machete|Kimsuky|APT33|APT39|APT32|APT18|Turla|Dark Caracal|Cobalt Group|Honeybee|Threat Group-3390|Dragonfly 2.0|Gorgon Group|Ke3chang|APT19|Leviathan|MuddyWater|APT37|BRONZE BUTLER|Magic Hound|APT3|FIN10|FIN7|Patchwork|FIN6|Lazarus Group|Putter Panda|APT29|Darkhotel
T1218.002,Control Panel,Defense Evasion,no
T1218.010,Regsvr32,Defense Evasion,Blue Mockingbird|Inception|WIRTE|APT19|Cobalt Group|Leviathan|APT32|Deep Panda
T1218.010,Regsvr32,Defense Evasion,Blue Mockingbird|Inception|WIRTE|Cobalt Group|APT19|Leviathan|APT32|Deep Panda
T1218.009,Regsvcs/Regasm,Defense Evasion,no
T1218.005,Mshta,Defense Evasion,Lazarus Group|Inception|Kimsuky|APT32|MuddyWater|FIN7
T1218.004,InstallUtil,Defense Evasion,menuPass
T1218.001,Compiled HTML File,Defense Evasion,APT41|Silence|OilRig|Lazarus Group|Dark Caracal
T1218.005,Mshta,Defense Evasion,Inception|Kimsuky|APT32|MuddyWater|FIN7
T1218.004,InstallUtil,Defense Evasion,no
T1218.001,Compiled HTML File,Defense Evasion,APT41|Silence|Lazarus Group|Dark Caracal|OilRig
T1218.003,CMSTP,Defense Evasion,Cobalt Group|MuddyWater
T1218.011,Rundll32,Defense Evasion,UNC2452|Gamaredon Group|APT32|Sandworm Team|Blue Mockingbird|TA505|MuddyWater|APT29|APT19|CopyKittens|APT3|Carbanak|APT28
T1218.011,Rundll32,Defense Evasion,APT32|Sandworm Team|Blue Mockingbird|TA505|MuddyWater|APT29|APT19|CopyKittens|APT3|Carbanak|APT28
T1547,Boot or Logon Autostart Execution,Persistence|Privilege Escalation,no
T1546,Event Triggered Execution,Privilege Escalation|Persistence,no
T1098.003,Add Office 365 Global Administrator Role,Persistence,no
T1098.002,Exchange Email Delegate Permissions,Persistence,UNC2452|Magic Hound
T1098.001,Additional Cloud Credentials,Persistence,UNC2452
T1098.002,Exchange Email Delegate Permissions,Persistence,Magic Hound
T1098.001,Additional Azure Service Principal Credentials,Persistence,no
T1543.004,Launch Daemon,Persistence|Privilege Escalation,no
T1543.003,Windows Service,Persistence|Privilege Escalation,PROMETHIUM|Blue Mockingbird|DarkVishnya|Wizard Spider|APT32|APT41|Kimsuky|Tropic Trooper|Threat Group-3390|Honeybee|Cobalt Group|Ke3chang|FIN7|APT19|APT3|Lazarus Group|Carbanak
T1543.003,Windows Service,Persistence|Privilege Escalation,Blue Mockingbird|DarkVishnya|Wizard Spider|APT32|APT41|Kimsuky|Tropic Trooper|Cobalt Group|Ke3chang|Honeybee|FIN7|Threat Group-3390|APT19|APT3|Lazarus Group|Carbanak
T1543.002,Systemd Service,Persistence|Privilege Escalation,Rocke
T1543.001,Launch Agent,Persistence|Privilege Escalation,no
T1037.005,Startup Items,Persistence|Privilege Escalation,no
T1037.004,Rc.common,Persistence|Privilege Escalation,no
T1055.012,Process Hollowing,Defense Evasion|Privilege Escalation,menuPass|Gorgon Group|Threat Group-3390|Patchwork
T1055.012,Process Hollowing,Defense Evasion|Privilege Escalation,Threat Group-3390|menuPass|Gorgon Group|Patchwork
T1055.013,Process Doppelgänging,Defense Evasion|Privilege Escalation,Leafminer
T1055.011,Extra Window Memory Injection,Defense Evasion|Privilege Escalation,no
T1055.014,VDSO Hijacking,Defense Evasion|Privilege Escalation,no
@@ -379,7 +277,7 @@ T1055.005,Thread Local Storage,Defense Evasion|Privilege Escalation,no
T1055.004,Asynchronous Procedure Call,Defense Evasion|Privilege Escalation,no
T1055.003,Thread Execution Hijacking,Defense Evasion|Privilege Escalation,no
T1055.002,Portable Executable Injection,Defense Evasion|Privilege Escalation,Rocke|Gorgon Group
T1055.001,Dynamic-link Library Injection,Defense Evasion|Privilege Escalation,Wizard Spider|TA505|Turla|Tropic Trooper|Lazarus Group|Putter Panda
T1055.001,Dynamic-link Library Injection,Defense Evasion|Privilege Escalation,TA505|Turla|Tropic Trooper|Lazarus Group|Putter Panda
T1037.003,Network Logon Script,Persistence|Privilege Escalation,no
T1543,Create or Modify System Process,Persistence|Privilege Escalation,no
T1037.002,Logon Script (Mac),Persistence|Privilege Escalation,no
@@ -393,7 +291,7 @@ T1505.001,SQL Stored Procedures,Persistence,no
T1053.003,Cron,Execution|Persistence|Privilege Escalation,Rocke
T1053.004,Launchd,Execution|Persistence|Privilege Escalation,no
T1053.001,At (Linux),Execution|Persistence|Privilege Escalation,no
T1053.005,Scheduled Task,Execution|Persistence|Privilege Escalation,UNC2452|Chimera|Gamaredon Group|Blue Mockingbird|MuddyWater|Wizard Spider|Frankenstein|APT-C-36|BRONZE BUTLER|APT41|Machete|Soft Cell|Silence|TEMP.Veles|APT33|APT39|Cobalt Group|OilRig|Rancor|Dragonfly 2.0|Patchwork|FIN8|FIN7|APT32|menuPass|FIN10|Stealth Falcon|FIN6|APT3|APT29
T1053.005,Scheduled Task,Execution|Persistence|Privilege Escalation,Gamaredon Group|Blue Mockingbird|MuddyWater|Wizard Spider|Frankenstein|APT-C-36|BRONZE BUTLER|APT41|Machete|Soft Cell|Silence|TEMP.Veles|APT33|APT39|Dragonfly 2.0|Patchwork|OilRig|Rancor|Cobalt Group|FIN8|menuPass|FIN10|APT32|FIN7|Stealth Falcon|FIN6|APT3|APT29
T1053.002,At (Windows),Execution|Persistence|Privilege Escalation,BRONZE BUTLER|Threat Group-3390|APT18
T1542,Pre-OS Boot,Defense Evasion|Persistence,no
T1137.001,Office Template Macros,Persistence,MuddyWater
@@ -418,52 +316,52 @@ T1526,Cloud Service Discovery,Discovery,no
T1505,Server Software Component,Persistence,no
T1499,Endpoint Denial of Service,Impact,no
T1497,Virtualization/Sandbox Evasion,Defense Evasion|Discovery,no
T1498,Network Denial of Service,Impact,APT28
T1498,Network Denial of Service,Impact,no
T1496,Resource Hijacking,Impact,Blue Mockingbird|Rocke|APT41|Lazarus Group
T1495,Firmware Corruption,Impact,no
T1491,Defacement,Impact,no
T1490,Inhibit System Recovery,Impact,no
T1489,Service Stop,Impact,Wizard Spider|Lazarus Group
T1489,Service Stop,Impact,Lazarus Group
T1486,Data Encrypted for Impact,Impact,APT41|TA505|APT38
T1485,Data Destruction,Impact,Sandworm Team|Lazarus Group|APT38
T1484,Domain Policy Modification,Defense Evasion|Privilege Escalation,no
T1482,Domain Trust Discovery,Discovery,UNC2452|Wizard Spider
T1484,Group Policy Modification,Defense Evasion|Privilege Escalation,no
T1482,Domain Trust Discovery,Discovery,Wizard Spider
T1480,Execution Guardrails,Defense Evasion,no
T1220,XSL Script Processing,Defense Evasion,Cobalt Group
T1222,File and Directory Permissions Modification,Defense Evasion,no
T1221,Template Injection,Defense Evasion,Gamaredon Group|Frankenstein|Inception|APT28|Tropic Trooper|Dragonfly 2.0|DarkHydrus
T1203,Exploitation for Client Execution,Execution,Sandworm Team|MuddyWater|Frankenstein|Inception|BlackTech|APT41|admin@338|Threat Group-3390|APT12|The White Company|APT33|APT32|APT28|Tropic Trooper|BRONZE BUTLER|Lazarus Group|Cobalt Group|APT29|Patchwork|Leviathan|APT37|Elderwood|TA459
T1200,Hardware Additions,Initial Access,DarkVishnya
T1202,Indirect Command Execution,Defense Evasion,no
T1213,Data from Information Repositories,Collection,FIN6|Turla
T1207,Rogue Domain Controller,Defense Evasion,no
T1204,User Execution,Execution,no
T1217,Browser Bookmark Discovery,Discovery,no
T1190,Exploit Public-Facing Application,Initial Access,UNC2452|APT28|APT29|GOLD SOUTHFIELD|Blue Mockingbird|Rocke|APT39|BlackTech|APT41|Soft Cell|Night Dragon|Axiom
T1210,Exploitation of Remote Services,Lateral Movement,Wizard Spider|Threat Group-3390|APT28
T1220,XSL Script Processing,Defense Evasion,Cobalt Group
T1197,BITS Jobs,Defense Evasion|Persistence,Patchwork|APT41|Leviathan
T1217,Browser Bookmark Discovery,Discovery,no
T1213,Data from Information Repositories,Collection,Turla
T1189,Drive-by Compromise,Initial Access,Turla|Windshift|RTM|Darkhotel|APT38|Dragonfly 2.0|BRONZE BUTLER|Leafminer|Dark Caracal|APT19|APT32|Lazarus Group|Threat Group-3390|Elderwood|APT37|Patchwork|PLATINUM
T1203,Exploitation for Client Execution,Execution,Sandworm Team|MuddyWater|Frankenstein|Inception|BlackTech|APT41|admin@338|Threat Group-3390|APT12|The White Company|APT33|APT32|APT28|Tropic Trooper|Lazarus Group|BRONZE BUTLER|Cobalt Group|APT37|Patchwork|Leviathan|Elderwood|TA459|APT29
T1212,Exploitation for Credential Access,Credential Access,no
T1211,Exploitation for Defense Evasion,Defense Evasion,APT28
T1190,Exploit Public-Facing Application,Initial Access,Blue Mockingbird|Rocke|APT39|BlackTech|APT41|Soft Cell|Night Dragon|Axiom
T1210,Exploitation of Remote Services,Lateral Movement,Threat Group-3390|APT28
T1202,Indirect Command Execution,Defense Evasion,no
T1200,Hardware Additions,Initial Access,DarkVishnya
T1201,Password Policy Discovery,Discovery,Turla|OilRig
T1219,Remote Access Software,Command And Control,Sandworm Team|DarkVishnya|RTM|Kimsuky|Night Dragon|Thrip|Cobalt Group|Carbanak
T1207,Rogue Domain Controller,Defense Evasion,no
T1199,Trusted Relationship,Initial Access,APT28|menuPass
T1218,Signed Binary Proxy Execution,Defense Evasion,no
T1204,User Execution,Execution,no
T1216,Signed Script Proxy Execution,Defense Evasion,no
T1195,Supply Chain Compromise,Initial Access,Elderwood
T1205,Traffic Signaling,Defense Evasion|Persistence|Command And Control,no
T1189,Drive-by Compromise,Initial Access,Dragonfly|PROMETHIUM|Turla|Windshift|RTM|Darkhotel|APT38|Lazarus Group|APT32|Dark Caracal|Dragonfly 2.0|BRONZE BUTLER|Leafminer|APT19|Threat Group-3390|APT37|Patchwork|PLATINUM|Elderwood
T1212,Exploitation for Credential Access,Credential Access,no
T1219,Remote Access Software,Command And Control,Sandworm Team|DarkVishnya|RTM|Kimsuky|Night Dragon|Thrip|Cobalt Group|Carbanak
T1211,Exploitation for Defense Evasion,Defense Evasion,APT28
T1218,Signed Binary Proxy Execution,Defense Evasion,no
T1216,Signed Script Proxy Execution,Defense Evasion,no
T1199,Trusted Relationship,Initial Access,GOLD SOUTHFIELD|APT28|menuPass
T1176,Browser Extensions,Persistence,Kimsuky|Stolen Pencil
T1175,Component Object Model and Distributed COM,Lateral Movement|Execution,no
T1187,Forced Authentication,Credential Access,DarkHydrus|Dragonfly 2.0
T1185,Man in the Browser,Collection,no
T1187,Forced Authentication,Credential Access,Dragonfly 2.0|DarkHydrus
T1149,LC_MAIN Hijacking,Defense Evasion,no
T1134,Access Token Manipulation,Defense Evasion|Privilege Escalation,Blue Mockingbird
T1136,Create Account,Persistence,no
T1134,Access Token Manipulation,Defense Evasion|Privilege Escalation,FIN6|Blue Mockingbird
T1135,Network Share Discovery,Discovery,Wizard Spider|APT32|APT39|DarkVishnya|APT41|Tropic Trooper|APT1|Dragonfly 2.0|Sowbug
T1140,Deobfuscate/Decode Files or Information,Defense Evasion,UNC2452|Rocke|Sandworm Team|Gamaredon Group|Molerats|Frankenstein|Turla|WIRTE|Darkhotel|Tropic Trooper|menuPass|Threat Group-3390|Gorgon Group|APT19|Honeybee|Leviathan|MuddyWater|APT28|OilRig|BRONZE BUTLER
T1140,Deobfuscate/Decode Files or Information,Defense Evasion,Rocke|Sandworm Team|Gamaredon Group|Molerats|Frankenstein|Turla|WIRTE|Darkhotel|Tropic Trooper|menuPass|Honeybee|Threat Group-3390|APT19|Gorgon Group|Leviathan|MuddyWater|APT28|OilRig|BRONZE BUTLER
T1149,LC_MAIN Hijacking,Defense Evasion,no
T1135,Network Share Discovery,Discovery,APT32|APT39|DarkVishnya|APT41|Tropic Trooper|APT1|Dragonfly 2.0|Sowbug
T1137,Office Application Startup,Persistence,Gamaredon Group|APT32
T1153,Source,Execution,no
T1133,External Remote Services,Persistence|Initial Access,Wizard Spider|GOLD SOUTHFIELD|Chimera|Sandworm Team|APT41|Soft Cell|TEMP.Veles|Night Dragon|Ke3chang|OilRig|Dragonfly 2.0|FIN5|Threat Group-3390|APT18
T1133,External Remote Services,Persistence|Initial Access,Sandworm Team|APT41|Soft Cell|TEMP.Veles|Night Dragon|OilRig|Dragonfly 2.0|Ke3chang|FIN5|Threat Group-3390|APT18
T1132,Data Encoding,Command And Control,no
T1129,Shared Modules,Execution,no
T1127,Trusted Developer Utilities Proxy Execution,Defense Evasion,no
@@ -471,72 +369,72 @@ T1125,Video Capture,Collection,Silence|FIN7
T1124,System Time Discovery,Discovery,The White Company|Lazarus Group|BRONZE BUTLER|Turla
T1123,Audio Capture,Collection,APT37
T1120,Peripheral Device Discovery,Discovery,Turla|APT37|Gamaredon Group|Equation|APT28
T1119,Automated Collection,Collection,Gamaredon Group|Tropic Trooper|Frankenstein|APT1|APT28|Patchwork|FIN5|OilRig|Threat Group-3390|FIN6
T1119,Automated Collection,Collection,Tropic Trooper|Frankenstein|APT1|APT28|Patchwork|OilRig|FIN5|Threat Group-3390|FIN6
T1115,Clipboard Data,Collection,APT39|APT38
T1114,Email Collection,Collection,no
T1113,Screen Capture,Collection,Gamaredon Group|APT39|Silence|MuddyWater|OilRig|Dragonfly 2.0|FIN7|Dark Caracal|BRONZE BUTLER|Magic Hound|Group5|APT28
T1112,Modify Registry,Defense Evasion,Lazarus Group|Gamaredon Group|Blue Mockingbird|Wizard Spider|Silence|APT41|Turla|APT32|APT38|Dragonfly 2.0|Patchwork|APT19|Gorgon Group|Threat Group-3390|Honeybee|FIN8
T1113,Screen Capture,Collection,Gamaredon Group|APT39|Silence|MuddyWater|Dragonfly 2.0|OilRig|Dark Caracal|FIN7|BRONZE BUTLER|Magic Hound|Group5|APT28
T1112,Modify Registry,Defense Evasion,Gamaredon Group|Blue Mockingbird|Wizard Spider|Silence|APT41|Turla|APT32|APT38|Dragonfly 2.0|APT19|Threat Group-3390|Honeybee|Patchwork|Gorgon Group|FIN8
T1111,Two-Factor Authentication Interception,Credential Access,no
T1110,Brute Force,Credential Access,DarkVishnya|APT39|OilRig|FIN5|Turla
T1108,Redundant Access,Defense Evasion|Persistence,no
T1106,Native API,Execution,Chimera|Gamaredon Group|Tropic Trooper|Sharpshooter|Turla|Silence|APT37|Gorgon Group
T1105,Ingress Tool Transfer,Command And Control,UNC2452|Chimera|Sandworm Team|Whitefly|Rocke|APT39|Tropic Trooper|Sharpshooter|Molerats|Frankenstein|Silence|APT-C-36|APT41|Soft Cell|TA505|WIRTE|APT33|MuddyWater|APT18|APT38|Rancor|OilRig|Dragonfly 2.0|Cobalt Group|Turla|Gorgon Group|APT37|Leviathan|Elderwood|PLATINUM|FIN8|Magic Hound|APT32|APT3|BRONZE BUTLER|menuPass|FIN7|Gamaredon Group|Patchwork|Lazarus Group|Threat Group-3390|APT28
T1106,Native API,Execution,Gamaredon Group|Tropic Trooper|Sharpshooter|Turla|Silence|Gorgon Group|APT37
T1105,Ingress Tool Transfer,Command And Control,Sandworm Team|Whitefly|Rocke|APT39|Tropic Trooper|Sharpshooter|Molerats|Frankenstein|Silence|APT-C-36|APT41|Soft Cell|TA505|WIRTE|APT33|MuddyWater|APT18|APT38|Rancor|Cobalt Group|Turla|Gorgon Group|OilRig|Dragonfly 2.0|APT37|FIN8|PLATINUM|Leviathan|Elderwood|Magic Hound|APT3|APT32|BRONZE BUTLER|menuPass|FIN7|Gamaredon Group|Patchwork|Lazarus Group|Threat Group-3390|APT28
T1104,Multi-Stage Channels,Command And Control,APT41|MuddyWater|APT3
T1102,Web Service,Command And Control,Chimera|Gamaredon Group|Rocke|Inception|FIN6
T1102,Web Service,Command And Control,Gamaredon Group|Rocke|Inception|FIN6
T1098,Account Manipulation,Persistence,APT3|Dragonfly 2.0|Lazarus Group
T1095,Non-Application Layer Protocol,Command And Control,FIN6|APT29|PLATINUM|APT3
T1095,Non-Application Layer Protocol,Command And Control,APT29|PLATINUM|APT3
T1092,Communication Through Removable Media,Command And Control,APT28
T1091,Replication Through Removable Media,Lateral Movement|Initial Access,Tropic Trooper|Darkhotel|APT28
T1090,Proxy,Command And Control,Sandworm Team|Blue Mockingbird|APT41|Turla
T1087,Account Discovery,Discovery,UNC2452
T1083,File and Directory Discovery,Discovery,UNC2452|Gamaredon Group|Tropic Trooper|Inception|APT41|Kimsuky|APT32|MuddyWater|APT18|Dragonfly 2.0|Leafminer|Honeybee|Dark Caracal|APT3|BRONZE BUTLER|Sowbug|Magic Hound|APT28|Patchwork|Lazarus Group|Dust Storm|admin@338|Turla|Ke3chang
T1082,System Information Discovery,Discovery,UNC2452|Wizard Spider|Rocke|Sandworm Team|Blue Mockingbird|Tropic Trooper|Frankenstein|Inception|Kimsuky|Darkhotel|MuddyWater|APT18|APT37|Honeybee|APT19|APT32|Magic Hound|Sowbug|OilRig|APT3|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|admin@338|Turla|Ke3chang
T1080,Taint Shared Content,Lateral Movement,Gamaredon Group|BRONZE BUTLER|Darkhotel
T1078,Valid Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,UNC2452|Chimera|Sandworm Team|Wizard Spider|Silence|APT41|Soft Cell|TEMP.Veles|APT39|FIN4|Night Dragon|Dragonfly 2.0|Leviathan|APT33|FIN8|FIN5|OilRig|APT28|FIN10|menuPass|Suckfly|FIN6|Threat Group-3390|APT18|PittyTiger|Carbanak
T1090,Proxy,Command And Control,Sandworm Team|Blue Mockingbird|Wizard Spider|APT41|Turla
T1087,Account Discovery,Discovery,no
T1083,File and Directory Discovery,Discovery,Gamaredon Group|Tropic Trooper|Inception|APT41|Kimsuky|APT32|MuddyWater|APT18|Leafminer|Honeybee|Dark Caracal|Dragonfly 2.0|Magic Hound|Sowbug|BRONZE BUTLER|APT3|APT28|Patchwork|Lazarus Group|Dust Storm|admin@338|Turla|Ke3chang
T1082,System Information Discovery,Discovery,Rocke|Sandworm Team|Blue Mockingbird|Tropic Trooper|Frankenstein|Inception|Kimsuky|Darkhotel|MuddyWater|APT18|Honeybee|APT19|APT37|APT32|Magic Hound|OilRig|APT3|Sowbug|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|admin@338|Turla|Ke3chang
T1080,Taint Shared Content,Lateral Movement,BRONZE BUTLER|Darkhotel
T1078,Valid Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,Sandworm Team|Wizard Spider|Silence|APT41|Soft Cell|TEMP.Veles|APT39|FIN4|Night Dragon|Dragonfly 2.0|FIN8|Leviathan|APT33|OilRig|FIN5|menuPass|APT28|FIN10|Suckfly|FIN6|Threat Group-3390|APT18|PittyTiger|Carbanak
T1074,Data Staged,Collection,Wizard Spider
T1072,Software Deployment Tools,Execution|Lateral Movement,Silence|APT32|Threat Group-1314
T1071,Application Layer Protocol,Command And Control,Rocke|Magic Hound|Dragonfly 2.0
T1070,Indicator Removal on Host,Defense Evasion,UNC2452
T1069,Permission Groups Discovery,Discovery,UNC2452|TA505|APT3
T1070,Indicator Removal on Host,Defense Evasion,no
T1069,Permission Groups Discovery,Discovery,TA505|APT3
T1068,Exploitation for Privilege Escalation,Privilege Escalation,Whitefly|APT33|Cobalt Group|PLATINUM|FIN8|APT32|Threat Group-3390|FIN6|APT28
T1064,Scripting,Defense Evasion|Execution,no
T1062,Hypervisor,Persistence,no
T1061,Graphical User Interface,Execution,no
T1059,Command and Scripting Interpreter,Execution,APT32|Molerats|Whitefly|APT39|APT19|FIN7|Dragonfly 2.0|OilRig|FIN5|Stealth Falcon|FIN6|Ke3chang
T1057,Process Discovery,Discovery,UNC2452|Rocke|Frankenstein|Inception|Darkhotel|MuddyWater|APT1|APT38|Tropic Trooper|APT37|Honeybee|OilRig|APT3|Magic Hound|APT28|Winnti Group|Stealth Falcon|Poseidon Group|Lazarus Group|Molerats|Turla|Deep Panda|Ke3chang
T1059,Command and Scripting Interpreter,Execution,APT32|Molerats|Whitefly|Dragonfly 2.0|APT19|FIN7|OilRig|FIN5|Stealth Falcon|FIN6|Ke3chang
T1057,Process Discovery,Discovery,Rocke|Frankenstein|Inception|Darkhotel|MuddyWater|APT1|APT38|Tropic Trooper|APT37|Honeybee|OilRig|APT3|Magic Hound|APT28|Winnti Group|Stealth Falcon|Poseidon Group|Lazarus Group|Molerats|Turla|Deep Panda|Ke3chang
T1056,Input Capture,Collection|Credential Access,no
T1055,Process Injection,Defense Evasion|Privilege Escalation,APT32|Sharpshooter|Silence|APT41|Kimsuky|Cobalt Group|APT37|Turla|Honeybee|PLATINUM
T1055,Process Injection,Defense Evasion|Privilege Escalation,APT32|Sharpshooter|Silence|APT41|Kimsuky|Turla|Cobalt Group|APT37|Honeybee|PLATINUM
T1053,Scheduled Task/Job,Execution|Persistence|Privilege Escalation,no
T1052,Exfiltration Over Physical Medium,Exfiltration,no
T1051,Shared Webroot,Lateral Movement,no
T1049,System Network Connections Discovery,Discovery,Tropic Trooper|APT41|APT38|Soft Cell|APT32|APT1|OilRig|APT3|Threat Group-3390|menuPass|Poseidon Group|admin@338|Turla|Ke3chang
T1049,System Network Connections Discovery,Discovery,Tropic Trooper|APT41|APT38|Soft Cell|APT32|APT1|OilRig|APT3|menuPass|Threat Group-3390|Poseidon Group|admin@338|Turla|Ke3chang
T1048,Exfiltration Over Alternative Protocol,Exfiltration,no
T1047,Windows Management Instrumentation,Execution,UNC2452|Chimera|Blue Mockingbird|Wizard Spider|Frankenstein|APT41|FIN6|Soft Cell|APT32|MuddyWater|OilRig|Threat Group-3390|FIN8|Leviathan|menuPass|Stealth Falcon|Lazarus Group|APT29|Deep Panda
T1046,Network Service Scanning,Discovery,Rocke|DarkVishnya|APT41|Tropic Trooper|APT39|APT32|Cobalt Group|Leafminer|OilRig|menuPass|Suckfly|FIN6|Threat Group-3390
T1043,Commonly Used Port,Command And Control,OilRig|APT28|TEMP.Veles|Night Dragon|APT29|APT18|FIN7|Dragonfly 2.0|APT19|FIN8|APT37|APT3|Magic Hound|Lazarus Group|Threat Group-3390
T1047,Windows Management Instrumentation,Execution,Blue Mockingbird|Wizard Spider|Frankenstein|APT41|FIN6|Soft Cell|APT32|MuddyWater|OilRig|Threat Group-3390|FIN8|Leviathan|menuPass|Stealth Falcon|Lazarus Group|APT29|Deep Panda
T1046,Network Service Scanning,Discovery,Rocke|DarkVishnya|APT41|Tropic Trooper|APT39|APT32|Leafminer|OilRig|Cobalt Group|menuPass|Suckfly|FIN6|Threat Group-3390
T1043,Commonly Used Port,Command And Control,Machete|OilRig|APT28|TEMP.Veles|Night Dragon|APT29|APT18|APT19|Dragonfly 2.0|FIN7|FIN8|APT37|Magic Hound|APT3|Lazarus Group|Threat Group-3390
T1041,Exfiltration Over C2 Channel,Exfiltration,Sandworm Team|MuddyWater|Wizard Spider|Frankenstein|Kimsuky|Soft Cell|APT32|APT3|Gamaredon Group|Stealth Falcon|Lazarus Group|Ke3chang
T1040,Network Sniffing,Credential Access|Discovery,Sandworm Team|DarkVishnya|APT33|Stolen Pencil|APT28
T1039,Data from Network Shared Drive,Collection,Gamaredon Group|BRONZE BUTLER|Sowbug|menuPass
T1039,Data from Network Shared Drive,Collection,Sowbug|BRONZE BUTLER|menuPass
T1037,Boot or Logon Initialization Scripts,Persistence|Privilege Escalation,Rocke
T1036,Masquerading,Defense Evasion,UNC2452|Windshift|APT32|BRONZE BUTLER|menuPass|Dragonfly 2.0
T1036,Masquerading,Defense Evasion,Windshift|APT32|BRONZE BUTLER|menuPass|Dragonfly 2.0
T1034,Path Interception,Persistence|Privilege Escalation,no
T1033,System Owner/User Discovery,Discovery,Wizard Spider|Frankenstein|APT41|Soft Cell|Tropic Trooper|APT39|MuddyWater|APT32|APT37|APT19|Dragonfly 2.0|OilRig|Magic Hound|FIN10|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|APT3
T1033,System Owner/User Discovery,Discovery,Frankenstein|APT41|Soft Cell|Tropic Trooper|APT39|MuddyWater|APT32|APT37|APT19|Dragonfly 2.0|OilRig|Magic Hound|FIN10|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|APT3
T1030,Data Transfer Size Limits,Exfiltration,Threat Group-3390
T1029,Scheduled Transfer,Exfiltration,no
T1027,Obfuscated Files or Information,Defense Evasion,UNC2452|FIN6|Chimera|Gamaredon Group|Rocke|Sandworm Team|Blue Mockingbird|Whitefly|Molerats|Wizard Spider|Mofang|Frankenstein|Inception|APT-C-36|APT41|Machete|Soft Cell|Turla|TA505|Silence|APT33|Night Dragon|Darkhotel|Gallmaker|APT29|APT18|Tropic Trooper|menuPass|Honeybee|Patchwork|Threat Group-3390|APT19|Cobalt Group|Leafminer|APT37|Dark Caracal|FIN8|MuddyWater|FIN7|BlackOasis|Leviathan|Elderwood|OilRig|Magic Hound|APT3|APT32|Group5|Lazarus Group|Dust Storm|Putter Panda|APT28
T1027,Obfuscated Files or Information,Defense Evasion,Gamaredon Group|Rocke|Sandworm Team|Blue Mockingbird|Whitefly|Molerats|Wizard Spider|Mofang|Frankenstein|Inception|APT-C-36|APT41|Machete|Soft Cell|Turla|TA505|Silence|APT33|Night Dragon|Darkhotel|Gallmaker|APT29|APT18|Tropic Trooper|Cobalt Group|Patchwork|Leafminer|APT37|Threat Group-3390|Honeybee|Dark Caracal|menuPass|APT19|BlackOasis|FIN8|Leviathan|Elderwood|MuddyWater|FIN7|Magic Hound|OilRig|APT3|APT32|Group5|Dust Storm|Lazarus Group|Putter Panda|APT28
T1026,Multiband Communication,Command And Control,Lazarus Group
T1025,Data from Removable Media,Collection,Machete|Turla|Gamaredon Group|APT28
T1021,Remote Services,Lateral Movement,no
T1020,Automated Exfiltration,Exfiltration,Gamaredon Group|Tropic Trooper|Frankenstein|Honeybee
T1018,Remote System Discovery,Discovery,UNC2452|Sandworm Team|Rocke|Wizard Spider|Silence|Soft Cell|APT39|APT32|Threat Group-3390|Dragonfly 2.0|Ke3chang|Leafminer|Deep Panda|FIN8|FIN5|APT3|BRONZE BUTLER|menuPass|FIN6|Turla
T1016,System Network Configuration Discovery,Discovery,Wizard Spider|Sandworm Team|Tropic Trooper|Frankenstein|APT41|Soft Cell|APT32|Darkhotel|MuddyWater|APT1|Dragonfly 2.0|APT19|OilRig|Magic Hound|menuPass|Threat Group-3390|Stealth Falcon|Lazarus Group|APT3|Naikon|admin@338|Turla|Ke3chang
T1020,Automated Exfiltration,Exfiltration,Tropic Trooper|Frankenstein|Honeybee
T1018,Remote System Discovery,Discovery,Sandworm Team|Rocke|Wizard Spider|Silence|Soft Cell|APT39|APT32|Deep Panda|Threat Group-3390|Dragonfly 2.0|Leafminer|Ke3chang|FIN8|APT3|FIN5|BRONZE BUTLER|menuPass|FIN6|Turla
T1016,System Network Configuration Discovery,Discovery,Sandworm Team|Tropic Trooper|Frankenstein|APT41|Soft Cell|APT32|Darkhotel|MuddyWater|APT1|APT19|Dragonfly 2.0|Magic Hound|OilRig|menuPass|Threat Group-3390|Stealth Falcon|Lazarus Group|APT3|Naikon|admin@338|Turla|Ke3chang
T1014,Rootkit,Defense Evasion,Rocke|APT41|APT28|Winnti Group
T1012,Query Registry,Discovery,APT32|Threat Group-3390|Dragonfly 2.0|OilRig|Stealth Falcon|Lazarus Group|Turla
T1012,Query Registry,Discovery,APT32|Dragonfly 2.0|Threat Group-3390|OilRig|Stealth Falcon|Lazarus Group|Turla
T1011,Exfiltration Over Other Network Medium,Exfiltration,no
T1010,Application Window Discovery,Discovery,Lazarus Group
T1008,Fallback Channels,Command And Control,APT41|OilRig|Lazarus Group
T1007,System Service Discovery,Discovery,BRONZE BUTLER|APT1|OilRig|Poseidon Group|admin@338|Turla|Ke3chang
T1006,Direct Volume Access,Defense Evasion,no
T1005,Data from Local System,Collection,UNC2452|FIN6|Gamaredon Group|APT39|Frankenstein|Inception|Kimsuky|Soft Cell|Turla|menuPass|Dark Caracal|Dragonfly 2.0|Honeybee|APT28|APT37|APT3|BRONZE BUTLER|Patchwork|Stealth Falcon|Lazarus Group|Dust Storm|Threat Group-3390|APT1|Ke3chang
T1005,Data from Local System,Collection,Gamaredon Group|APT39|Frankenstein|Inception|Kimsuky|Soft Cell|Turla|menuPass|Dark Caracal|Dragonfly 2.0|Honeybee|APT37|APT28|APT3|BRONZE BUTLER|Patchwork|Stealth Falcon|Lazarus Group|Dust Storm|Threat Group-3390|APT1|Ke3chang
T1003,OS Credential Dumping,Credential Access,APT39|Frankenstein|APT32|APT28|Leviathan|Sowbug|Suckfly|Poseidon Group|Axiom
T1001,Data Obfuscation,Command And Control,Axiom
1 mitre_id technique tactics groups
2 T1484.002 T1205.001 Domain Trust Modification Port Knocking Defense Evasion|Privilege Escalation Defense Evasion|Persistence|Command And Control UNC2452 no
T1484.001 Group Policy Modification Defense Evasion|Privilege Escalation no
T1606.002 SAML Tokens Credential Access UNC2452
T1606.001 Web Cookies Credential Access UNC2452
T1606 Forge Web Credentials Credential Access no
T1059.008 Network Device CLI Execution no
T1602.002 Network Device Configuration Dump Collection no
T1542.005 TFTP Boot Defense Evasion|Persistence no
T1542.004 ROMMONkit Defense Evasion|Persistence no
T1602.001 SNMP (MIB Dump) Collection no
T1602 Data from Configuration Repository Collection no
T1601.002 Downgrade System Image Defense Evasion no
T1601.001 Patch System Image Defense Evasion no
T1601 Modify System Image Defense Evasion no
T1600.002 Disable Crypto Hardware Defense Evasion no
T1600.001 Reduce Key Space Defense Evasion no
T1600 Weaken Encryption Defense Evasion no
T1556.004 Network Device Authentication Credential Access|Defense Evasion no
T1599.001 Network Address Translation Traversal Defense Evasion no
T1599 Network Boundary Bridging Defense Evasion no
T1020.001 Traffic Duplication Exfiltration no
T1557.002 ARP Cache Poisoning Credential Access|Collection Cleaver
T1588.006 Vulnerabilities Resource Development no
T1053.006 Systemd Timers Execution|Persistence|Privilege Escalation no
T1562.008 Disable Cloud Logs Defense Evasion no
T1547.012 Print Processors Persistence|Privilege Escalation no
T1598.003 Spearphishing Link Reconnaissance no
T1598.002 Spearphishing Attachment Reconnaissance no
T1598.001 Spearphishing Service Reconnaissance no
T1598 Phishing for Information Reconnaissance no
T1597.002 Purchase Technical Data Reconnaissance no
T1597.001 Threat Intel Vendors Reconnaissance no
T1597 Search Closed Sources Reconnaissance no
T1596.005 Scan Databases Reconnaissance no
T1596.004 CDNs Reconnaissance no
T1596.003 Digital Certificates Reconnaissance no
T1596.001 DNS/Passive DNS Reconnaissance no
T1596.002 WHOIS Reconnaissance no
T1596 Search Open Technical Databases Reconnaissance no
T1595.002 Vulnerability Scanning Reconnaissance no
T1595.001 Scanning IP Blocks Reconnaissance no
T1595 Active Scanning Reconnaissance no
T1594 Search Victim-Owned Websites Reconnaissance no
T1593.002 Search Engines Reconnaissance no
T1593.001 Social Media Reconnaissance no
T1593 Search Open Websites/Domains Reconnaissance no
T1592.004 Client Configurations Reconnaissance no
T1592.003 Firmware Reconnaissance no
T1592.002 Software Reconnaissance no
T1592.001 Hardware Reconnaissance no
T1592 Gather Victim Host Information Reconnaissance no
T1591.004 Identify Roles Reconnaissance no
T1591.003 Identify Business Tempo Reconnaissance no
T1591.001 Determine Physical Locations Reconnaissance no
T1591.002 Business Relationships Reconnaissance no
T1591 Gather Victim Org Information Reconnaissance no
T1590.006 Network Security Appliances Reconnaissance no
T1590.005 IP Addresses Reconnaissance no
T1590.004 Network Topology Reconnaissance no
T1590.003 Network Trust Dependencies Reconnaissance no
T1590.002 DNS Reconnaissance no
T1590.001 Domain Properties Reconnaissance no
T1590 Gather Victim Network Information Reconnaissance no
T1589.003 Employee Names Reconnaissance no
T1589.002 Email Addresses Reconnaissance no
T1589.001 Credentials Reconnaissance no
T1589 Gather Victim Identity Information Reconnaissance no
T1588.005 Exploits Resource Development no
T1588.004 Digital Certificates Resource Development no
T1588.003 Code Signing Certificates Resource Development Wizard Spider
T1588.002 Tool Resource Development no
T1588.001 Malware Resource Development Turla|APT1
T1588 Obtain Capabilities Resource Development no
T1587.004 Exploits Resource Development no
T1587.003 Digital Certificates Resource Development APT29|PROMETHIUM
T1587.002 Code Signing Certificates Resource Development PROMETHIUM|Patchwork
T1587.001 Malware Resource Development UNC2452|Turla|FIN7|Night Dragon|Cleaver
T1587 Develop Capabilities Resource Development no
T1586.002 Email Accounts Resource Development no
T1586.001 Social Media Accounts Resource Development no
T1586 Compromise Accounts Resource Development no
T1585.002 Email Accounts Resource Development APT1
T1585.001 Social Media Accounts Resource Development Cleaver
T1585 Establish Accounts Resource Development APT17
T1584.006 Web Services Resource Development Turla
T1584.005 Botnet Resource Development no
T1584.004 Server Resource Development Turla|APT16
T1584.003 Virtual Private Server Resource Development Turla
T1584.002 DNS Server Resource Development no
T1584.001 Domains Resource Development APT1
T1583.006 Web Services Resource Development APT17|APT29
T1583.005 Botnet Resource Development no
T1583.004 Server Resource Development no
T1583.003 Virtual Private Server Resource Development TEMP.Veles
T1583.002 DNS Server Resource Development no
T1584 Compromise Infrastructure Resource Development no
T1583.001 Domains Resource Development APT1|APT28
T1583 Acquire Infrastructure Resource Development no
T1564.007 VBA Stomping Defense Evasion no
T1558.004 AS-REP Roasting Credential Access no
T1580 Cloud Infrastructure Discovery Discovery no
T1218.012 Verclsid Defense Evasion no
T1205.001 Port Knocking Defense Evasion|Persistence|Command And Control PROMETHIUM
3 T1564.006 Run Virtual Instance Defense Evasion no
4 T1564.005 Hidden File System Defense Evasion Strider|Equation
5 T1556.003 Pluggable Authentication Modules Credential Access|Defense Evasion no
7 T1562.007 Disable or Modify Cloud Firewall Defense Evasion no
8 T1098.004 SSH Authorized Keys Persistence no
9 T1480.001 Environmental Keying Defense Evasion APT41|Equation
10 T1059.007 JavaScript/JScript Execution FIN6|APT32|FIN7|Cobalt Group|Molerats|TA505|Silence|Leafminer APT32|FIN7|Cobalt Group|Molerats|TA505|Silence|Leafminer
11 T1578.004 Revert Cloud Instance Defense Evasion no
12 T1578.003 Delete Cloud Instance Defense Evasion no
13 T1578.001 Create Snapshot Defense Evasion no
24 T1071.004 DNS Command And Control APT39|Tropic Trooper|OilRig|Ke3chang|Cobalt Group|APT18|APT41|FIN7
25 T1071.003 Mail Protocols Command And Control APT32|SilverTerrier|APT28
26 T1071.002 File Transfer Protocols Command And Control APT41|SilverTerrier|Machete|Honeybee
27 T1071.001 Web Protocols Command And Control UNC2452|Sandworm Team|TA505|Rocke|APT39|Tropic Trooper|MuddyWater|Wizard Spider|Inception|APT41|SilverTerrier|Machete|APT28|WIRTE|APT33|FIN4|Night Dragon|APT18|APT38|Threat Group-3390|Ke3chang|Dark Caracal|APT19|Cobalt Group|Rancor|Orangeworm|APT37|Turla|Lazarus Group|APT32|Magic Hound|BRONZE BUTLER|OilRig|Gamaredon Group|Stealth Falcon Sandworm Team|TA505|Rocke|APT39|Tropic Trooper|MuddyWater|Wizard Spider|Inception|APT41|SilverTerrier|Machete|APT28|WIRTE|APT33|FIN4|Night Dragon|APT18|APT38|Cobalt Group|APT19|Threat Group-3390|Rancor|Orangeworm|APT37|Ke3chang|Dark Caracal|Turla|Lazarus Group|BRONZE BUTLER|APT32|OilRig|Magic Hound|Gamaredon Group|Stealth Falcon
28 T1572 Protocol Tunneling Command And Control OilRig|Cobalt Group|FIN6
29 T1048.003 Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol Exfiltration Wizard Spider|FIN6|APT32|APT33|Thrip|FIN8|OilRig|Lazarus Group APT32|APT33|Thrip|FIN8|OilRig|Lazarus Group
30 T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol Exfiltration UNC2452 no
31 T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol Exfiltration no
32 T1001.003 Protocol Impersonation Command And Control Lazarus Group
33 T1001.002 Steganography Command And Control APT29|Axiom Axiom
34 T1001.001 Junk Data Command And Control APT28
35 T1132.002 Non-Standard Encoding Command And Control no
36 T1132.001 Standard Encoding Command And Control Sandworm Team|Tropic Trooper|MuddyWater|APT33|APT19|Lazarus Group|BRONZE BUTLER|Patchwork
37 T1090.004 Domain Fronting Command And Control APT29
38 T1090.003 Multi-hop Proxy Command And Control Inception|FIN4|APT29
39 T1090.002 External Proxy Command And Control APT39|Silence|Soft Cell|MuddyWater|APT3|FIN5|Lazarus Group|menuPass|APT28
40 T1090.001 Internal Proxy Command And Control UNC2452|APT39|Strider APT39|Strider
41 T1102.003 One-Way Communication Command And Control Leviathan
42 T1102.002 Bidirectional Communication Command And Control APT29|Sandworm Team|APT39|APT12|Turla|FIN7|APT37|Magic Hound|Carbanak Sandworm Team|APT39|APT12|Turla|FIN7|APT37|Magic Hound|Carbanak
43 T1102.001 Dead Drop Resolver Command And Control Rocke|APT41|BRONZE BUTLER|RTM|Patchwork
44 T1571 Non-Standard Port Command And Control Sandworm Team|Rocke|DarkVishnya|Silence|APT-C-36|Magic Hound|APT33|APT32|TEMP.Veles|Lazarus Group|FIN7
45 T1074.002 Remote Data Staging Collection UNC2452|Threat Group-3390|menuPass|FIN6|Night Dragon|FIN8 Threat Group-3390|menuPass|FIN6|Night Dragon|FIN8
46 T1074.001 Local Data Staging Collection Machete|Soft Cell|TEMP.Veles|Honeybee|Dragonfly 2.0|Patchwork|Leviathan|APT3|FIN5|menuPass|Lazarus Group|Threat Group-3390|APT28 Machete|Soft Cell|TEMP.Veles|Patchwork|Dragonfly 2.0|Honeybee|Leviathan|APT3|FIN5|menuPass|FIN6|Lazarus Group|Threat Group-3390|APT28
47 T1078.004 Cloud Accounts Defense Evasion|Persistence|Privilege Escalation|Initial Access APT33
48 T1564.004 NTFS File Attributes Defense Evasion APT32
49 T1564.003 Hidden Window Defense Evasion Gorgon Group|Deep Panda|DarkHydrus|CopyKittens|APT19|APT32|APT28|APT3|Magic Hound
50 T1078.003 Local Accounts Defense Evasion|Persistence|Privilege Escalation|Initial Access PROMETHIUM|Tropic Trooper|FIN10|Stolen Pencil|APT32 Tropic Trooper|FIN10|Stolen Pencil|APT32
51 T1078.002 Domain Accounts Defense Evasion|Persistence|Privilege Escalation|Initial Access Wizard Spider|APT29|TA505|APT3|Threat Group-1314 TA505|APT3|Threat Group-1314
52 T1078.001 Default Accounts Defense Evasion|Persistence|Privilege Escalation|Initial Access no
53 T1564.002 Hidden Users Defense Evasion no
54 T1574.006 LD_PRELOAD Persistence|Privilege Escalation|Defense Evasion Rocke
64 T1069.001 Local Groups Discovery Turla|OilRig|admin@338
65 T1570 Lateral Tool Transfer Lateral Movement APT32|Wizard Spider|Turla|FIN10
66 T1568.003 DNS Calculation Command And Control APT12
67 T1204.002 Malicious File Execution FIN6|PROMETHIUM|APT30|Magic Hound|Windshift|APT33|Sandworm Team|Naikon|Whitefly|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Wizard Spider|Mofang|Frankenstein|RTM|Inception|BlackTech|APT-C-36|Machete|admin@338|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Dragonfly 2.0|Dark Caracal|FIN7|APT32|Cobalt Group|DarkHydrus|Patchwork|Rancor|MuddyWater|BRONZE BUTLER|APT19|Gorgon Group|OilRig|Lazarus Group|APT29|menuPass|TA459|FIN8|Elderwood|PLATINUM|Leviathan|APT37|APT28 Magic Hound|Windshift|APT33|Sandworm Team|Naikon|Whitefly|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Wizard Spider|Mofang|Frankenstein|RTM|Inception|BlackTech|APT-C-36|Machete|admin@338|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|APT19|Dragonfly 2.0|BRONZE BUTLER|Cobalt Group|DarkHydrus|Gorgon Group|Patchwork|OilRig|Dark Caracal|MuddyWater|Lazarus Group|FIN7|APT32|Rancor|APT37|FIN8|APT28|Elderwood|TA459|APT29|Leviathan|menuPass|PLATINUM
68 T1204.001 Malicious Link Execution Wizard Spider|Patchwork|Windshift|APT32|Molerats|Mofang|BlackTech|TA505|OilRig|Machete|Leviathan|FIN8|FIN4|Elderwood|Dragonfly 2.0|Cobalt Group|APT39|Night Dragon|APT33|Turla Patchwork|Windshift|APT32|Molerats|Mofang|BlackTech|TA505|OilRig|Machete|Leviathan|FIN8|FIN4|Elderwood|Dragonfly 2.0|Cobalt Group|APT39|Night Dragon|APT33|Turla
69 T1195.003 Compromise Hardware Supply Chain Initial Access no
70 T1195.002 Compromise Software Supply Chain Initial Access UNC2452|GOLD SOUTHFIELD|Dragonfly|Sandworm Team|APT41 Sandworm Team|APT41
71 T1195.001 Compromise Software Dependencies and Development Tools Initial Access no
72 T1568.001 Fast Flux DNS Command And Control Machete|TA505 TA505
73 T1052.001 Exfiltration over USB Exfiltration Tropic Trooper
74 T1569.002 Service Execution Execution Wizard Spider|Blue Mockingbird|APT39|APT41|Silence|FIN6|APT32|Ke3chang|Honeybee Blue Mockingbird|APT39|APT41|Silence|FIN6|APT32|Honeybee|Ke3chang
75 T1569.001 Launchctl Execution no
76 T1569 System Services Execution no
77 T1568.002 Domain Generation Algorithms Command And Control APT41
78 T1568 Dynamic Resolution Command And Control UNC2452 no
79 T1011.001 Exfiltration Over Bluetooth Exfiltration no
80 T1567.002 Exfiltration to Cloud Storage Exfiltration Leviathan|Turla
81 T1567.001 Exfiltration to Code Repository Exfiltration no
82 T1059.006 Python Execution APT29|Rocke|BRONZE BUTLER|APT39|Dragonfly 2.0|Machete Rocke|BRONZE BUTLER|APT39|Dragonfly 2.0|Machete
83 T1059.005 Visual Basic Execution Lazarus Group|APT33|Sandworm Team|Gamaredon Group|Sharpshooter|Molerats|Frankenstein|Inception|APT-C-36|Rancor|Patchwork|MuddyWater|Honeybee|FIN7|APT37|BRONZE BUTLER|APT32|Turla|TA505|Silence|WIRTE|FIN4|Gorgon Group|Cobalt Group|Leviathan|TA459|Magic Hound APT33|Sandworm Team|Gamaredon Group|Sharpshooter|Molerats|Frankenstein|Inception|APT-C-36|Rancor|Patchwork|MuddyWater|Honeybee|FIN7|APT37|BRONZE BUTLER|APT32|Turla|TA505|Silence|WIRTE|FIN4|Cobalt Group|Gorgon Group|Leviathan|TA459|Magic Hound
84 T1059.004 Unix Shell Execution Rocke|APT41
85 T1059.003 Windows Command Shell Execution UNC2452|Wizard Spider|FIN6|TA505|Blue Mockingbird|Tropic Trooper|Frankenstein|OilRig|Lazarus Group|Honeybee|Cobalt Group|FIN7|APT41|Soft Cell|Turla|Silence|APT32|Darkhotel|MuddyWater|APT18|APT38|Gorgon Group|Ke3chang|Dragonfly 2.0|Rancor|Dark Caracal|APT37|APT28|Leviathan|FIN8|Sowbug|Magic Hound|BRONZE BUTLER|menuPass|Threat Group-3390|FIN10|Gamaredon Group|Patchwork|Suckfly|Threat Group-1314|APT3|admin@338|APT1 TA505|Blue Mockingbird|Tropic Trooper|Frankenstein|OilRig|Lazarus Group|Honeybee|Cobalt Group|FIN7|APT41|Soft Cell|Turla|Silence|APT32|APT39|Darkhotel|MuddyWater|APT18|APT38|Dark Caracal|Gorgon Group|Dragonfly 2.0|Rancor|Ke3chang|APT37|Leviathan|FIN8|APT28|Magic Hound|Sowbug|BRONZE BUTLER|FIN10|Threat Group-3390|menuPass|Gamaredon Group|Suckfly|Patchwork|Threat Group-1314|APT3|admin@338|APT1
86 T1059.002 AppleScript Execution no
87 T1059.001 PowerShell Execution UNC2452|Lazarus Group|Chimera|Blue Mockingbird|APT39|DarkVishnya|Molerats|Wizard Spider|Frankenstein|Inception|Silence|APT41|Kimsuky|Soft Cell|TA505|WIRTE|TEMP.Veles|APT33|Gallmaker|Turla|APT19|DarkHydrus|APT28|Gorgon Group|Thrip|Cobalt Group|Dragonfly 2.0|Leviathan|TA459|MuddyWater|FIN8|Magic Hound|CopyKittens|BRONZE BUTLER|OilRig|FIN10|Threat Group-3390|APT32|FIN7|menuPass|Patchwork|Stealth Falcon|FIN6|Poseidon Group|APT3|APT29|Deep Panda Blue Mockingbird|APT39|DarkVishnya|Molerats|Wizard Spider|Frankenstein|Inception|Silence|APT41|Kimsuky|Soft Cell|TA505|WIRTE|TEMP.Veles|APT33|Gallmaker|Turla|APT19|DarkHydrus|APT28|Thrip|Gorgon Group|Cobalt Group|Dragonfly 2.0|Leviathan|TA459|FIN8|MuddyWater|Magic Hound|OilRig|BRONZE BUTLER|CopyKittens|APT32|FIN7|FIN10|Threat Group-3390|menuPass|Patchwork|Stealth Falcon|FIN6|Poseidon Group|APT3|APT29|Deep Panda
88 T1567 Exfiltration Over Web Service Exfiltration no
89 T1497.003 Time Based Evasion Defense Evasion|Discovery no
90 T1497.002 User Activity Based Checks Defense Evasion|Discovery FIN7
91 T1497.001 System Checks Defense Evasion|Discovery Frankenstein
92 T1498.002 Reflection Amplification Impact no
93 T1498.001 Direct Network Flood Impact no
94 T1566.003 Spearphishing via Service Initial Access Lazarus Group|Magic Hound|Windshift|FIN6|OilRig|Dark Caracal Magic Hound|Windshift|FIN6|OilRig|Dark Caracal
95 T1566.002 Spearphishing Link Initial Access Wizard Spider|APT1|Windshift|Molerats|Mofang|BlackTech|Machete|Kimsuky|TA505|Stolen Pencil|APT39|FIN4|APT32|Night Dragon|APT28|Cobalt Group|Dragonfly 2.0|Turla|OilRig|APT33|Leviathan|Patchwork|Elderwood|APT29|Magic Hound|FIN8 Windshift|Molerats|Mofang|BlackTech|Machete|Kimsuky|TA505|Stolen Pencil|APT39|FIN4|APT32|Night Dragon|Turla|APT28|Cobalt Group|Dragonfly 2.0|OilRig|APT33|Elderwood|Leviathan|Magic Hound|Patchwork|APT29|FIN8
96 T1566.001 Spearphishing Attachment Initial Access APT1|FIN6|APT30|Magic Hound|Windshift|APT33|Sandworm Team|Naikon|Gamaredon Group|Sharpshooter|Molerats|Mofang|Wizard Spider|RTM|Frankenstein|Inception|BlackTech|APT-C-36|APT41|Machete|admin@338|Kimsuky|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Tropic Trooper|Turla|Lazarus Group|Cobalt Group|FIN7|OilRig|BRONZE BUTLER|APT32|Gorgon Group|Rancor|DarkHydrus|APT19|Dragonfly 2.0|FIN8|PLATINUM|MuddyWater|TA459|Leviathan|Elderwood|APT29|APT37|menuPass|APT28|Patchwork Magic Hound|Windshift|APT33|Sandworm Team|Naikon|Gamaredon Group|Sharpshooter|Molerats|Mofang|Wizard Spider|RTM|Frankenstein|Inception|BlackTech|APT-C-36|APT41|Machete|admin@338|Kimsuky|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Tropic Trooper|Turla|Gorgon Group|Rancor|DarkHydrus|Cobalt Group|FIN7|OilRig|Lazarus Group|APT19|Dragonfly 2.0|BRONZE BUTLER|APT32|FIN8|MuddyWater|APT28|TA459|Leviathan|Patchwork|PLATINUM|Elderwood|APT29|APT37|menuPass
97 T1566 Phishing Initial Access GOLD SOUTHFIELD|Dragonfly no
98 T1565.003 Runtime Data Manipulation Impact APT38
99 T1565.002 Transmitted Data Manipulation Impact APT38
100 T1565.001 Stored Data Manipulation Impact FIN4|APT38
104 T1563.002 RDP Hijacking Lateral Movement no
105 T1563.001 SSH Hijacking Lateral Movement no
106 T1563 Remote Service Session Hijacking Lateral Movement no
107 T1518.001 Security Software Discovery Discovery Wizard Spider|Turla|Rocke|Frankenstein|The White Company|Cobalt Group|Darkhotel|MuddyWater|Tropic Trooper|FIN8|Patchwork|Naikon Turla|Rocke|Frankenstein|The White Company|Cobalt Group|Darkhotel|MuddyWater|Tropic Trooper|FIN8|Patchwork|Naikon
108 T1069.003 Cloud Groups Discovery no
109 T1069.002 Domain Groups Discovery Turla|Wizard Spider|Inception|OilRig|FIN6|Dragonfly 2.0|Ke3chang
110 T1087.004 Cloud Account Discovery no
111 T1087.003 Email Account Discovery Sandworm Team|TA505
112 T1087.002 Domain Account Discovery Wizard Spider|Chimera|Turla|Sandworm Team|Dragonfly 2.0|OilRig|BRONZE BUTLER|menuPass|FIN6|Poseidon Group|Ke3chang Turla|Sandworm Team|Dragonfly 2.0|OilRig|BRONZE BUTLER|menuPass|FIN6|Poseidon Group|Ke3chang
113 T1087.001 Local Account Discovery Turla|Poseidon Group|OilRig|Ke3chang|APT32|APT1|Threat Group-3390|APT3|admin@338
114 T1553.004 Install Root Certificate Defense Evasion no
115 T1562.004 Disable or Modify System Firewall Defense Evasion UNC2452|Rocke|Lazarus Group|Kimsuky|Dragonfly 2.0|Carbanak Rocke|Lazarus Group|Kimsuky|Dragonfly 2.0|Carbanak
116 T1562.003 Impair Command History Logging HISTCONTROL Defense Evasion no
117 T1562.002 Disable Windows Event Logging Defense Evasion UNC2452|Threat Group-3390 Threat Group-3390
118 T1562.001 Disable or Modify Tools Defense Evasion UNC2452|Wizard Spider|FIN6|Gamaredon Group|BRONZE BUTLER|Rocke|Kimsuky|Turla|Night Dragon|Gorgon Group|Lazarus Group|Putter Panda Gamaredon Group|BRONZE BUTLER|Rocke|Kimsuky|Turla|Night Dragon|Gorgon Group|Lazarus Group|Putter Panda
119 T1562 Impair Defenses Defense Evasion no
120 T1003.004 LSA Secrets Credential Access OilRig|MuddyWater|menuPass|Leafminer|Ke3chang|Dragonfly 2.0|APT33|Threat Group-3390
121 T1003.005 Cached Domain Credentials Credential Access OilRig|MuddyWater|Leafminer|APT33
124 T1561 Disk Wipe Impact no
125 T1560.003 Archive via Custom Method Collection Lazarus Group|Kimsuky|CopyKittens|FIN6
126 T1560.002 Archive via Library Collection Lazarus Group|Threat Group-3390
127 T1560.001 Archive via Utility Collection UNC2452|Chimera|APT41|Soft Cell|Turla|Gallmaker|APT33|APT39|MuddyWater|Magic Hound|FIN8|BRONZE BUTLER|CopyKittens|Sowbug|APT3|menuPass|APT1|Ke3chang APT41|Soft Cell|Turla|Gallmaker|APT33|APT39|MuddyWater|Magic Hound|FIN8|BRONZE BUTLER|CopyKittens|APT3|Sowbug|menuPass|APT1|Ke3chang
128 T1560 Archive Collected Data Collection menuPass|APT32|Patchwork|APT28|Dragonfly 2.0|Honeybee|FIN6|Lazarus Group|Ke3chang menuPass|APT32|Honeybee|Patchwork|APT28|Dragonfly 2.0|FIN6|Lazarus Group|Ke3chang
129 T1499.004 Application or System Exploitation Impact no
130 T1499.003 Application Exhaustion Flood Impact no
131 T1499.002 Service Exhaustion Flood Impact no
133 T1491.002 External Defacement Impact no
134 T1491.001 Internal Defacement Impact Lazarus Group
135 T1114.003 Email Forwarding Rule Collection no
136 T1114.002 Remote Email Collection Collection UNC2452|APT1|FIN4|Ke3chang|Leafminer|Dragonfly 2.0|APT28 APT1|FIN4|APT28|Dragonfly 2.0|Ke3chang|Leafminer
137 T1114.001 Local Email Collection Collection Magic Hound|APT1
138 T1134.005 SID-History Injection Defense Evasion|Privilege Escalation no
139 T1134.004 Parent PID Spoofing Defense Evasion|Privilege Escalation no
142 T1134.001 Token Impersonation/Theft Defense Evasion|Privilege Escalation APT28
143 T1213.002 Sharepoint Collection Ke3chang|APT28
144 T1213.001 Confluence Collection no
145 T1555.003 Credentials from Web Browsers Credential Access FIN6|Magic Hound|Sandworm Team|Inception|Stealth Falcon|OilRig|Leafminer|APT33|APT3|Kimsuky|TA505|Stolen Pencil|MuddyWater|APT37|Patchwork|Molerats Magic Hound|Sandworm Team|Inception|Stealth Falcon|OilRig|Leafminer|APT33|APT3|Kimsuky|TA505|Stolen Pencil|MuddyWater|APT37|Patchwork|Molerats
146 T1555.002 Securityd Memory Credential Access no
147 T1555.001 Keychain Credential Access no
148 T1559.002 Dynamic Data Exchange Execution Sharpshooter|TA505|MuddyWater|Gallmaker|Cobalt Group|Patchwork|APT37|FIN7|APT28 Sharpshooter|TA505|MuddyWater|Gallmaker|Patchwork|Cobalt Group|APT37|APT28|FIN7
149 T1559.001 Component Object Model Execution Gamaredon Group|MuddyWater
150 T1559 Inter-Process Communication Execution no
151 T1558.002 Silver Ticket Credential Access no
152 T1558.001 Golden Ticket Credential Access Ke3chang
153 T1558 Steal or Forge Kerberos Tickets Credential Access no
154 T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay Credential Access|Collection Wizard Spider no
155 T1557 Man-in-the-Middle Credential Access|Collection no
156 T1556.002 Password Filter DLL Credential Access|Defense Evasion Strider
157 T1556.001 Domain Controller Authentication Credential Access|Defense Evasion Chimera no
158 T1556 Modify Authentication Process Credential Access|Defense Evasion no
159 T1056.004 Credential API Hooking Collection|Credential Access PLATINUM
160 T1056.003 Web Portal Capture Collection|Credential Access no
161 T1056.002 GUI Input Capture Collection|Credential Access FIN4
162 T1056.001 Keylogging Collection|Credential Access APT32|Sandworm Team|APT39|APT41|Kimsuky|menuPass|Stolen Pencil|FIN4|APT38|OilRig|Ke3chang|PLATINUM|Sowbug|Magic Hound|Group5|Lazarus Group|Threat Group-3390|APT3|Darkhotel|APT28 APT32|Sandworm Team|APT39|APT41|Kimsuky|menuPass|Stolen Pencil|FIN4|APT38|Ke3chang|OilRig|PLATINUM|Sowbug|Magic Hound|Group5|Lazarus Group|Threat Group-3390|APT3|Darkhotel|APT28
163 T1555 Credentials from Password Stores Credential Access UNC2452|FIN6|APT39|OilRig|MuddyWater|Leafminer|APT33|Turla|Stealth Falcon APT39|OilRig|MuddyWater|Leafminer|APT33|Turla|Stealth Falcon
164 T1552.005 Cloud Instance Metadata API Credential Access no
165 T1003.008 /etc/passwd and /etc/shadow Credential Access no
166 T1003.007 Proc Filesystem Credential Access no
167 T1003.006 DCSync Credential Access UNC2452 no
168 T1558.003 Kerberoasting Credential Access UNC2452|Wizard Spider no
169 T1552.006 Group Policy Preferences Credential Access APT33
170 T1003.003 NTDS Credential Access Wizard Spider|Chimera|FIN6|Dragonfly 2.0 FIN6|Dragonfly 2.0
171 T1003.002 Security Account Manager Credential Access Wizard Spider|Threat Group-3390|Ke3chang|Soft Cell|Night Dragon|Dragonfly 2.0|menuPass Threat Group-3390|Ke3chang|Soft Cell|Night Dragon|Dragonfly 2.0|menuPass
172 T1003.001 LSASS Memory Credential Access Sandworm Team|Whitefly|Blue Mockingbird|Silence|Threat Group-3390|Leviathan|APT41|Soft Cell|TEMP.Veles|APT33|APT39|Stolen Pencil|APT32|Leafminer|Lazarus Group|Magic Hound|MuddyWater|FIN8|PLATINUM|OilRig|BRONZE BUTLER|FIN6|APT3|APT28|APT1|Ke3chang|Cleaver Sandworm Team|Whitefly|Blue Mockingbird|Silence|Threat Group-3390|Leviathan|APT41|Soft Cell|TEMP.Veles|APT33|APT39|Stolen Pencil|APT32|Lazarus Group|Leafminer|Magic Hound|MuddyWater|PLATINUM|FIN8|BRONZE BUTLER|OilRig|FIN6|APT3|APT28|APT1|Ke3chang|Cleaver
173 T1110.004 Credential Stuffing Credential Access no
174 T1110.003 Password Spraying Credential Access APT28|APT33|Leafminer|Lazarus Group APT33|Leafminer|Lazarus Group
175 T1110.002 Password Cracking Credential Access FIN6|APT41|Dragonfly 2.0|APT3 APT41|Dragonfly 2.0|APT3
176 T1110.001 Password Guessing Credential Access APT28 no
177 T1021.006 Windows Remote Management Lateral Movement UNC2452|Wizard Spider|Threat Group-3390 Threat Group-3390
178 T1021.005 VNC Lateral Movement GCMAN
179 T1021.004 SSH Lateral Movement Rocke|TEMP.Veles|Leviathan|APT39|OilRig|menuPass|GCMAN
180 T1021.003 Distributed Component Object Model Lateral Movement no
181 T1021.002 SMB/Windows Admin Shares Lateral Movement Wizard Spider|Chimera|Blue Mockingbird|APT39|APT32|Orangeworm|FIN8|APT3|Lazarus Group|Threat Group-1314|Turla|Deep Panda|Ke3chang Blue Mockingbird|APT39|APT32|Orangeworm|FIN8|APT3|Lazarus Group|Threat Group-1314|Turla|Deep Panda|Ke3chang
182 T1021.001 Remote Desktop Protocol Lateral Movement Chimera|Blue Mockingbird|Wizard Spider|Silence|APT41|TEMP.Veles|Leviathan|APT39|Stolen Pencil|Cobalt Group|Dragonfly 2.0|FIN8|APT3|OilRig|FIN10|menuPass|Patchwork|FIN6|Lazarus Group|APT1|Axiom Blue Mockingbird|Wizard Spider|Silence|APT41|TEMP.Veles|Leviathan|APT39|Stolen Pencil|Cobalt Group|Dragonfly 2.0|FIN8|APT3|OilRig|menuPass|FIN10|Patchwork|FIN6|Lazarus Group|APT1|Axiom
183 T1554 Compromise Client Software Binary Persistence no
184 T1036.006 Space after Filename Defense Evasion no
185 T1036.005 Match Legitimate Name or Location Defense Evasion UNC2452|Chimera|PROMETHIUM|Rocke|Sandworm Team|APT39|Blue Mockingbird|Whitefly|Tropic Trooper|Silence|APT41|menuPass|TEMP.Veles|MuddyWater|BRONZE BUTLER|Sowbug|APT32|Patchwork|Poseidon Group|admin@338|Carbanak|APT1 Rocke|Sandworm Team|APT39|Blue Mockingbird|Whitefly|Tropic Trooper|Silence|APT41|menuPass|TEMP.Veles|MuddyWater|BRONZE BUTLER|Sowbug|APT32|Patchwork|Poseidon Group|admin@338|Carbanak|APT1
186 T1036.004 Masquerade Task or Service Defense Evasion UNC2452|Lazarus Group|PROMETHIUM|Wizard Spider|APT-C-36|Carbanak|APT32|FIN6|FIN7 Wizard Spider|APT-C-36|Carbanak|APT32|FIN6|FIN7
187 T1036.003 Rename System Utilities Defense Evasion menuPass|APT32|Soft Cell|PLATINUM
188 T1036.002 Right-to-Left Override Defense Evasion BRONZE BUTLER|BlackTech|Ke3chang|Scarlet Mimic
189 T1036.001 Invalid Code Signature Defense Evasion Windshift|APT37 Windshift
190 T1553.003 SIP and Trust Provider Hijacking Defense Evasion no
191 T1553.002 Code Signing Defense Evasion UNC2452|Wizard Spider|PROMETHIUM|Patchwork|Silence|APT41|FIN6|TA505|FIN7|Honeybee|Leviathan|CopyKittens|Winnti Group|Suckfly|Molerats|Darkhotel Patchwork|Silence|APT41|FIN6|TA505|FIN7|Honeybee|Leviathan|APT37|CopyKittens|Winnti Group|Suckfly|Molerats|Darkhotel
192 T1553.001 Gatekeeper Bypass Defense Evasion no
193 T1553 Subvert Trust Controls Defense Evasion no
194 T1027.003 Steganography Defense Evasion BRONZE BUTLER|Tropic Trooper|MuddyWater|APT37
195 T1027.002 Software Packing Defense Evasion Lazarus Group|TA505|Rocke|Soft Cell|The White Company|APT39|APT38|Dark Caracal|Elderwood|APT3|Patchwork|APT29|Night Dragon TA505|Rocke|Soft Cell|The White Company|APT39|APT38|Dark Caracal|Elderwood|APT3|Patchwork|APT29|Night Dragon
196 T1027.001 Binary Padding Defense Evasion Gamaredon Group|APT32|Patchwork|Leviathan|BRONZE BUTLER|Moafee Gamaredon Group|Patchwork|APT32|Leviathan|BRONZE BUTLER|Moafee
197 T1222.002 Linux and Mac File and Directory Permissions Modification Defense Evasion Rocke|APT32
198 T1222.001 Windows File and Directory Permissions Modification Defense Evasion Wizard Spider no
199 T1552.004 Private Keys Credential Access UNC2452|Rocke Rocke
200 T1552.003 Bash History Credential Access no
201 T1552.002 Credentials in Registry Credential Access APT32
202 T1552.001 Credentials In Files Credential Access Leafminer|APT33|OilRig|TA505|Stolen Pencil|MuddyWater|APT3
203 T1552 Unsecured Credentials Credential Access no
204 T1216.001 PubPrn Defense Evasion APT32
205 T1070.006 Timestomp Defense Evasion UNC2452|Rocke|TEMP.Veles|APT32|Lazarus Group|APT28 Rocke|TEMP.Veles|APT32|Lazarus Group|APT28
206 T1070.005 Network Share Connection Removal Defense Evasion Threat Group-3390
207 T1070.004 File Deletion Defense Evasion UNC2452|FIN6|Sandworm Team|Rocke|Tropic Trooper|Gamaredon Group|Wizard Spider|APT41|Kimsuky|Silence|The White Company|TEMP.Veles|APT32|APT38|Honeybee|Patchwork|Cobalt Group|Dragonfly 2.0|menuPass|FIN8|BRONZE BUTLER|FIN5|APT3|OilRig|Magic Hound|FIN10|APT28|Threat Group-3390|Group5|Lazarus Group|APT18|APT29 Sandworm Team|Rocke|Tropic Trooper|Gamaredon Group|Wizard Spider|APT41|Kimsuky|Silence|The White Company|TEMP.Veles|APT32|APT38|Patchwork|Honeybee|Cobalt Group|Dragonfly 2.0|menuPass|FIN8|OilRig|FIN5|BRONZE BUTLER|Magic Hound|APT3|FIN10|APT28|Threat Group-3390|Group5|Lazarus Group|APT18|APT29
208 T1070.003 Clear Command History Defense Evasion APT41
209 T1550.004 Web Session Cookie Defense Evasion|Lateral Movement UNC2452 no
210 T1550.001 Application Access Token Defense Evasion|Lateral Movement APT28
211 T1550.003 Pass the Ticket Defense Evasion|Lateral Movement APT32|BRONZE BUTLER|APT29
212 T1550.002 Pass the Hash Defense Evasion|Lateral Movement Soft Cell|APT32|Night Dragon|APT28|APT1
213 T1550 Use Alternate Authentication Material Defense Evasion|Lateral Movement UNC2452 no
214 T1548.004 Elevated Execution with Prompt Privilege Escalation|Defense Evasion no
215 T1548.003 Sudo and Sudo Caching Privilege Escalation|Defense Evasion no
216 T1548.002 Bypass User Account Control Bypass User Access Control Privilege Escalation|Defense Evasion APT37|MuddyWater|Honeybee|Cobalt Group|Threat Group-3390|BRONZE BUTLER|Patchwork|APT29
217 T1548.001 Setuid and Setgid Privilege Escalation|Defense Evasion no
218 T1548 Abuse Elevation Control Mechanism Privilege Escalation|Defense Evasion no
219 T1136.003 Cloud Account Persistence no
220 T1070.002 Clear Linux or Mac System Logs Defense Evasion Rocke
221 T1070.001 Clear Windows Event Logs Defense Evasion APT41|APT38|Dragonfly 2.0|APT32|FIN8|FIN5|APT28
222 T1136.002 Domain Account Persistence Soft Cell
223 T1136.001 Local Account Persistence APT39|APT41|Leafminer|Dragonfly 2.0|APT3 APT39|APT41|Dragonfly 2.0|Leafminer|APT3
224 T1547.011 Plist Modification Persistence|Privilege Escalation no
225 T1547.010 Port Monitors Persistence|Privilege Escalation no
226 T1547.009 Shortcut Modification Persistence|Privilege Escalation APT39|Darkhotel|APT29|Gorgon Group|Dragonfly 2.0|Leviathan|Lazarus Group
227 T1547.008 LSASS Driver Persistence|Privilege Escalation no
228 T1547.007 Re-opened Applications Persistence|Privilege Escalation no
229 T1547.006 Kernel Modules and Extensions Persistence|Privilege Escalation no
230 T1547.005 Security Support Provider Persistence|Privilege Escalation Lazarus Group no
231 T1547.004 Winlogon Helper DLL Persistence|Privilege Escalation Wizard Spider|Tropic Trooper|Turla Tropic Trooper|Turla
232 T1547.003 Time Providers Persistence|Privilege Escalation no
233 T1546.014 Emond Privilege Escalation|Persistence no
234 T1546.013 PowerShell Profile Privilege Escalation|Persistence Turla
244 T1546.006 LC_LOAD_DYLIB Addition Privilege Escalation|Persistence no
245 T1546.005 Trap Privilege Escalation|Persistence no
246 T1546.004 .bash_profile and .bashrc Privilege Escalation|Persistence no
247 T1546.003 Windows Management Instrumentation Event Subscription Privilege Escalation|Persistence UNC2452|APT33|Blue Mockingbird|Turla|Leviathan|APT29 APT33|Blue Mockingbird|Turla|Leviathan|APT29
248 T1546.002 Screensaver Privilege Escalation|Persistence no
249 T1546.001 Change Default File Association Privilege Escalation|Persistence Kimsuky
250 T1547.001 Registry Run Keys / Startup Folder Persistence|Privilege Escalation Wizard Spider|PROMETHIUM|Rocke|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Silence|RTM|Inception|APT41|Machete|Kimsuky|APT33|APT39|APT32|APT18|Turla|Dark Caracal|Cobalt Group|Honeybee|APT19|Ke3chang|Threat Group-3390|Dragonfly 2.0|Gorgon Group|MuddyWater|APT37|Leviathan|BRONZE BUTLER|Magic Hound|APT3|FIN10|FIN7|Patchwork|FIN6|Lazarus Group|Putter Panda|APT29|Darkhotel Rocke|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Silence|RTM|Inception|APT41|Machete|Kimsuky|APT33|APT39|APT32|APT18|Turla|Dark Caracal|Cobalt Group|Honeybee|Threat Group-3390|Dragonfly 2.0|Gorgon Group|Ke3chang|APT19|Leviathan|MuddyWater|APT37|BRONZE BUTLER|Magic Hound|APT3|FIN10|FIN7|Patchwork|FIN6|Lazarus Group|Putter Panda|APT29|Darkhotel
251 T1218.002 Control Panel Defense Evasion no
252 T1218.010 Regsvr32 Defense Evasion Blue Mockingbird|Inception|WIRTE|APT19|Cobalt Group|Leviathan|APT32|Deep Panda Blue Mockingbird|Inception|WIRTE|Cobalt Group|APT19|Leviathan|APT32|Deep Panda
253 T1218.009 Regsvcs/Regasm Defense Evasion no
254 T1218.005 Mshta Defense Evasion Lazarus Group|Inception|Kimsuky|APT32|MuddyWater|FIN7 Inception|Kimsuky|APT32|MuddyWater|FIN7
255 T1218.004 InstallUtil Defense Evasion menuPass no
256 T1218.001 Compiled HTML File Defense Evasion APT41|Silence|OilRig|Lazarus Group|Dark Caracal APT41|Silence|Lazarus Group|Dark Caracal|OilRig
257 T1218.003 CMSTP Defense Evasion Cobalt Group|MuddyWater
258 T1218.011 Rundll32 Defense Evasion UNC2452|Gamaredon Group|APT32|Sandworm Team|Blue Mockingbird|TA505|MuddyWater|APT29|APT19|CopyKittens|APT3|Carbanak|APT28 APT32|Sandworm Team|Blue Mockingbird|TA505|MuddyWater|APT29|APT19|CopyKittens|APT3|Carbanak|APT28
259 T1547 Boot or Logon Autostart Execution Persistence|Privilege Escalation no
260 T1546 Event Triggered Execution Privilege Escalation|Persistence no
261 T1098.003 Add Office 365 Global Administrator Role Persistence no
262 T1098.002 Exchange Email Delegate Permissions Persistence UNC2452|Magic Hound Magic Hound
263 T1098.001 Additional Cloud Credentials Additional Azure Service Principal Credentials Persistence UNC2452 no
264 T1543.004 Launch Daemon Persistence|Privilege Escalation no
265 T1543.003 Windows Service Persistence|Privilege Escalation PROMETHIUM|Blue Mockingbird|DarkVishnya|Wizard Spider|APT32|APT41|Kimsuky|Tropic Trooper|Threat Group-3390|Honeybee|Cobalt Group|Ke3chang|FIN7|APT19|APT3|Lazarus Group|Carbanak Blue Mockingbird|DarkVishnya|Wizard Spider|APT32|APT41|Kimsuky|Tropic Trooper|Cobalt Group|Ke3chang|Honeybee|FIN7|Threat Group-3390|APT19|APT3|Lazarus Group|Carbanak
266 T1543.002 Systemd Service Persistence|Privilege Escalation Rocke
267 T1543.001 Launch Agent Persistence|Privilege Escalation no
268 T1037.005 Startup Items Persistence|Privilege Escalation no
269 T1037.004 Rc.common Persistence|Privilege Escalation no
270 T1055.012 Process Hollowing Defense Evasion|Privilege Escalation menuPass|Gorgon Group|Threat Group-3390|Patchwork Threat Group-3390|menuPass|Gorgon Group|Patchwork
271 T1055.013 Process Doppelgänging Defense Evasion|Privilege Escalation Leafminer
272 T1055.011 Extra Window Memory Injection Defense Evasion|Privilege Escalation no
273 T1055.014 VDSO Hijacking Defense Evasion|Privilege Escalation no
277 T1055.004 Asynchronous Procedure Call Defense Evasion|Privilege Escalation no
278 T1055.003 Thread Execution Hijacking Defense Evasion|Privilege Escalation no
279 T1055.002 Portable Executable Injection Defense Evasion|Privilege Escalation Rocke|Gorgon Group
280 T1055.001 Dynamic-link Library Injection Defense Evasion|Privilege Escalation Wizard Spider|TA505|Turla|Tropic Trooper|Lazarus Group|Putter Panda TA505|Turla|Tropic Trooper|Lazarus Group|Putter Panda
281 T1037.003 Network Logon Script Persistence|Privilege Escalation no
282 T1543 Create or Modify System Process Persistence|Privilege Escalation no
283 T1037.002 Logon Script (Mac) Persistence|Privilege Escalation no
291 T1053.003 Cron Execution|Persistence|Privilege Escalation Rocke
292 T1053.004 Launchd Execution|Persistence|Privilege Escalation no
293 T1053.001 At (Linux) Execution|Persistence|Privilege Escalation no
294 T1053.005 Scheduled Task Execution|Persistence|Privilege Escalation UNC2452|Chimera|Gamaredon Group|Blue Mockingbird|MuddyWater|Wizard Spider|Frankenstein|APT-C-36|BRONZE BUTLER|APT41|Machete|Soft Cell|Silence|TEMP.Veles|APT33|APT39|Cobalt Group|OilRig|Rancor|Dragonfly 2.0|Patchwork|FIN8|FIN7|APT32|menuPass|FIN10|Stealth Falcon|FIN6|APT3|APT29 Gamaredon Group|Blue Mockingbird|MuddyWater|Wizard Spider|Frankenstein|APT-C-36|BRONZE BUTLER|APT41|Machete|Soft Cell|Silence|TEMP.Veles|APT33|APT39|Dragonfly 2.0|Patchwork|OilRig|Rancor|Cobalt Group|FIN8|menuPass|FIN10|APT32|FIN7|Stealth Falcon|FIN6|APT3|APT29
295 T1053.002 At (Windows) Execution|Persistence|Privilege Escalation BRONZE BUTLER|Threat Group-3390|APT18
296 T1542 Pre-OS Boot Defense Evasion|Persistence no
297 T1137.001 Office Template Macros Persistence MuddyWater
316 T1505 Server Software Component Persistence no
317 T1499 Endpoint Denial of Service Impact no
318 T1497 Virtualization/Sandbox Evasion Defense Evasion|Discovery no
319 T1498 Network Denial of Service Impact APT28 no
320 T1496 Resource Hijacking Impact Blue Mockingbird|Rocke|APT41|Lazarus Group
321 T1495 Firmware Corruption Impact no
322 T1491 Defacement Impact no
323 T1490 Inhibit System Recovery Impact no
324 T1489 Service Stop Impact Wizard Spider|Lazarus Group Lazarus Group
325 T1486 Data Encrypted for Impact Impact APT41|TA505|APT38
326 T1485 Data Destruction Impact Sandworm Team|Lazarus Group|APT38
327 T1484 Domain Policy Modification Group Policy Modification Defense Evasion|Privilege Escalation no
328 T1482 Domain Trust Discovery Discovery UNC2452|Wizard Spider Wizard Spider
329 T1480 Execution Guardrails Defense Evasion no
T1220 XSL Script Processing Defense Evasion Cobalt Group
330 T1222 File and Directory Permissions Modification Defense Evasion no
331 T1221 Template Injection Defense Evasion Gamaredon Group|Frankenstein|Inception|APT28|Tropic Trooper|Dragonfly 2.0|DarkHydrus
332 T1203 T1220 Exploitation for Client Execution XSL Script Processing Execution Defense Evasion Sandworm Team|MuddyWater|Frankenstein|Inception|BlackTech|APT41|admin@338|Threat Group-3390|APT12|The White Company|APT33|APT32|APT28|Tropic Trooper|BRONZE BUTLER|Lazarus Group|Cobalt Group|APT29|Patchwork|Leviathan|APT37|Elderwood|TA459 Cobalt Group
T1200 Hardware Additions Initial Access DarkVishnya
T1202 Indirect Command Execution Defense Evasion no
T1213 Data from Information Repositories Collection FIN6|Turla
T1207 Rogue Domain Controller Defense Evasion no
T1204 User Execution Execution no
T1217 Browser Bookmark Discovery Discovery no
T1190 Exploit Public-Facing Application Initial Access UNC2452|APT28|APT29|GOLD SOUTHFIELD|Blue Mockingbird|Rocke|APT39|BlackTech|APT41|Soft Cell|Night Dragon|Axiom
T1210 Exploitation of Remote Services Lateral Movement Wizard Spider|Threat Group-3390|APT28
333 T1197 BITS Jobs Defense Evasion|Persistence Patchwork|APT41|Leviathan
334 T1217 Browser Bookmark Discovery Discovery no
335 T1213 Data from Information Repositories Collection Turla
336 T1189 Drive-by Compromise Initial Access Turla|Windshift|RTM|Darkhotel|APT38|Dragonfly 2.0|BRONZE BUTLER|Leafminer|Dark Caracal|APT19|APT32|Lazarus Group|Threat Group-3390|Elderwood|APT37|Patchwork|PLATINUM
337 T1203 Exploitation for Client Execution Execution Sandworm Team|MuddyWater|Frankenstein|Inception|BlackTech|APT41|admin@338|Threat Group-3390|APT12|The White Company|APT33|APT32|APT28|Tropic Trooper|Lazarus Group|BRONZE BUTLER|Cobalt Group|APT37|Patchwork|Leviathan|Elderwood|TA459|APT29
338 T1212 Exploitation for Credential Access Credential Access no
339 T1211 Exploitation for Defense Evasion Defense Evasion APT28
340 T1190 Exploit Public-Facing Application Initial Access Blue Mockingbird|Rocke|APT39|BlackTech|APT41|Soft Cell|Night Dragon|Axiom
341 T1210 Exploitation of Remote Services Lateral Movement Threat Group-3390|APT28
342 T1202 Indirect Command Execution Defense Evasion no
343 T1200 Hardware Additions Initial Access DarkVishnya
344 T1201 Password Policy Discovery Discovery Turla|OilRig
345 T1219 Remote Access Software Command And Control Sandworm Team|DarkVishnya|RTM|Kimsuky|Night Dragon|Thrip|Cobalt Group|Carbanak
346 T1207 Rogue Domain Controller Defense Evasion no
347 T1199 Trusted Relationship Initial Access APT28|menuPass
348 T1218 Signed Binary Proxy Execution Defense Evasion no
349 T1204 User Execution Execution no
350 T1216 Signed Script Proxy Execution Defense Evasion no
351 T1195 Supply Chain Compromise Initial Access Elderwood
352 T1205 Traffic Signaling Defense Evasion|Persistence|Command And Control no
T1189 Drive-by Compromise Initial Access Dragonfly|PROMETHIUM|Turla|Windshift|RTM|Darkhotel|APT38|Lazarus Group|APT32|Dark Caracal|Dragonfly 2.0|BRONZE BUTLER|Leafminer|APT19|Threat Group-3390|APT37|Patchwork|PLATINUM|Elderwood
T1212 Exploitation for Credential Access Credential Access no
T1219 Remote Access Software Command And Control Sandworm Team|DarkVishnya|RTM|Kimsuky|Night Dragon|Thrip|Cobalt Group|Carbanak
T1211 Exploitation for Defense Evasion Defense Evasion APT28
T1218 Signed Binary Proxy Execution Defense Evasion no
T1216 Signed Script Proxy Execution Defense Evasion no
T1199 Trusted Relationship Initial Access GOLD SOUTHFIELD|APT28|menuPass
353 T1176 Browser Extensions Persistence Kimsuky|Stolen Pencil
354 T1175 Component Object Model and Distributed COM Lateral Movement|Execution no
355 T1187 Forced Authentication Credential Access DarkHydrus|Dragonfly 2.0
356 T1185 Man in the Browser Collection no
357 T1187 T1134 Forced Authentication Access Token Manipulation Credential Access Defense Evasion|Privilege Escalation Dragonfly 2.0|DarkHydrus Blue Mockingbird
T1149 LC_MAIN Hijacking Defense Evasion no
358 T1136 Create Account Persistence no
359 T1134 T1140 Access Token Manipulation Deobfuscate/Decode Files or Information Defense Evasion|Privilege Escalation Defense Evasion FIN6|Blue Mockingbird Rocke|Sandworm Team|Gamaredon Group|Molerats|Frankenstein|Turla|WIRTE|Darkhotel|Tropic Trooper|menuPass|Honeybee|Threat Group-3390|APT19|Gorgon Group|Leviathan|MuddyWater|APT28|OilRig|BRONZE BUTLER
360 T1135 T1149 Network Share Discovery LC_MAIN Hijacking Discovery Defense Evasion Wizard Spider|APT32|APT39|DarkVishnya|APT41|Tropic Trooper|APT1|Dragonfly 2.0|Sowbug no
361 T1140 T1135 Deobfuscate/Decode Files or Information Network Share Discovery Defense Evasion Discovery UNC2452|Rocke|Sandworm Team|Gamaredon Group|Molerats|Frankenstein|Turla|WIRTE|Darkhotel|Tropic Trooper|menuPass|Threat Group-3390|Gorgon Group|APT19|Honeybee|Leviathan|MuddyWater|APT28|OilRig|BRONZE BUTLER APT32|APT39|DarkVishnya|APT41|Tropic Trooper|APT1|Dragonfly 2.0|Sowbug
362 T1137 Office Application Startup Persistence Gamaredon Group|APT32
363 T1153 Source Execution no
364 T1133 External Remote Services Persistence|Initial Access Wizard Spider|GOLD SOUTHFIELD|Chimera|Sandworm Team|APT41|Soft Cell|TEMP.Veles|Night Dragon|Ke3chang|OilRig|Dragonfly 2.0|FIN5|Threat Group-3390|APT18 Sandworm Team|APT41|Soft Cell|TEMP.Veles|Night Dragon|OilRig|Dragonfly 2.0|Ke3chang|FIN5|Threat Group-3390|APT18
365 T1132 Data Encoding Command And Control no
366 T1129 Shared Modules Execution no
367 T1127 Trusted Developer Utilities Proxy Execution Defense Evasion no
369 T1124 System Time Discovery Discovery The White Company|Lazarus Group|BRONZE BUTLER|Turla
370 T1123 Audio Capture Collection APT37
371 T1120 Peripheral Device Discovery Discovery Turla|APT37|Gamaredon Group|Equation|APT28
372 T1119 Automated Collection Collection Gamaredon Group|Tropic Trooper|Frankenstein|APT1|APT28|Patchwork|FIN5|OilRig|Threat Group-3390|FIN6 Tropic Trooper|Frankenstein|APT1|APT28|Patchwork|OilRig|FIN5|Threat Group-3390|FIN6
373 T1115 Clipboard Data Collection APT39|APT38
374 T1114 Email Collection Collection no
375 T1113 Screen Capture Collection Gamaredon Group|APT39|Silence|MuddyWater|OilRig|Dragonfly 2.0|FIN7|Dark Caracal|BRONZE BUTLER|Magic Hound|Group5|APT28 Gamaredon Group|APT39|Silence|MuddyWater|Dragonfly 2.0|OilRig|Dark Caracal|FIN7|BRONZE BUTLER|Magic Hound|Group5|APT28
376 T1112 Modify Registry Defense Evasion Lazarus Group|Gamaredon Group|Blue Mockingbird|Wizard Spider|Silence|APT41|Turla|APT32|APT38|Dragonfly 2.0|Patchwork|APT19|Gorgon Group|Threat Group-3390|Honeybee|FIN8 Gamaredon Group|Blue Mockingbird|Wizard Spider|Silence|APT41|Turla|APT32|APT38|Dragonfly 2.0|APT19|Threat Group-3390|Honeybee|Patchwork|Gorgon Group|FIN8
377 T1111 Two-Factor Authentication Interception Credential Access no
378 T1110 Brute Force Credential Access DarkVishnya|APT39|OilRig|FIN5|Turla
379 T1108 Redundant Access Defense Evasion|Persistence no
380 T1106 Native API Execution Chimera|Gamaredon Group|Tropic Trooper|Sharpshooter|Turla|Silence|APT37|Gorgon Group Gamaredon Group|Tropic Trooper|Sharpshooter|Turla|Silence|Gorgon Group|APT37
381 T1105 Ingress Tool Transfer Command And Control UNC2452|Chimera|Sandworm Team|Whitefly|Rocke|APT39|Tropic Trooper|Sharpshooter|Molerats|Frankenstein|Silence|APT-C-36|APT41|Soft Cell|TA505|WIRTE|APT33|MuddyWater|APT18|APT38|Rancor|OilRig|Dragonfly 2.0|Cobalt Group|Turla|Gorgon Group|APT37|Leviathan|Elderwood|PLATINUM|FIN8|Magic Hound|APT32|APT3|BRONZE BUTLER|menuPass|FIN7|Gamaredon Group|Patchwork|Lazarus Group|Threat Group-3390|APT28 Sandworm Team|Whitefly|Rocke|APT39|Tropic Trooper|Sharpshooter|Molerats|Frankenstein|Silence|APT-C-36|APT41|Soft Cell|TA505|WIRTE|APT33|MuddyWater|APT18|APT38|Rancor|Cobalt Group|Turla|Gorgon Group|OilRig|Dragonfly 2.0|APT37|FIN8|PLATINUM|Leviathan|Elderwood|Magic Hound|APT3|APT32|BRONZE BUTLER|menuPass|FIN7|Gamaredon Group|Patchwork|Lazarus Group|Threat Group-3390|APT28
382 T1104 Multi-Stage Channels Command And Control APT41|MuddyWater|APT3
383 T1102 Web Service Command And Control Chimera|Gamaredon Group|Rocke|Inception|FIN6 Gamaredon Group|Rocke|Inception|FIN6
384 T1098 Account Manipulation Persistence APT3|Dragonfly 2.0|Lazarus Group
385 T1095 Non-Application Layer Protocol Command And Control FIN6|APT29|PLATINUM|APT3 APT29|PLATINUM|APT3
386 T1092 Communication Through Removable Media Command And Control APT28
387 T1091 Replication Through Removable Media Lateral Movement|Initial Access Tropic Trooper|Darkhotel|APT28
388 T1090 Proxy Command And Control Sandworm Team|Blue Mockingbird|APT41|Turla Sandworm Team|Blue Mockingbird|Wizard Spider|APT41|Turla
389 T1087 Account Discovery Discovery UNC2452 no
390 T1083 File and Directory Discovery Discovery UNC2452|Gamaredon Group|Tropic Trooper|Inception|APT41|Kimsuky|APT32|MuddyWater|APT18|Dragonfly 2.0|Leafminer|Honeybee|Dark Caracal|APT3|BRONZE BUTLER|Sowbug|Magic Hound|APT28|Patchwork|Lazarus Group|Dust Storm|admin@338|Turla|Ke3chang Gamaredon Group|Tropic Trooper|Inception|APT41|Kimsuky|APT32|MuddyWater|APT18|Leafminer|Honeybee|Dark Caracal|Dragonfly 2.0|Magic Hound|Sowbug|BRONZE BUTLER|APT3|APT28|Patchwork|Lazarus Group|Dust Storm|admin@338|Turla|Ke3chang
391 T1082 System Information Discovery Discovery UNC2452|Wizard Spider|Rocke|Sandworm Team|Blue Mockingbird|Tropic Trooper|Frankenstein|Inception|Kimsuky|Darkhotel|MuddyWater|APT18|APT37|Honeybee|APT19|APT32|Magic Hound|Sowbug|OilRig|APT3|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|admin@338|Turla|Ke3chang Rocke|Sandworm Team|Blue Mockingbird|Tropic Trooper|Frankenstein|Inception|Kimsuky|Darkhotel|MuddyWater|APT18|Honeybee|APT19|APT37|APT32|Magic Hound|OilRig|APT3|Sowbug|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|admin@338|Turla|Ke3chang
392 T1080 Taint Shared Content Lateral Movement Gamaredon Group|BRONZE BUTLER|Darkhotel BRONZE BUTLER|Darkhotel
393 T1078 Valid Accounts Defense Evasion|Persistence|Privilege Escalation|Initial Access UNC2452|Chimera|Sandworm Team|Wizard Spider|Silence|APT41|Soft Cell|TEMP.Veles|APT39|FIN4|Night Dragon|Dragonfly 2.0|Leviathan|APT33|FIN8|FIN5|OilRig|APT28|FIN10|menuPass|Suckfly|FIN6|Threat Group-3390|APT18|PittyTiger|Carbanak Sandworm Team|Wizard Spider|Silence|APT41|Soft Cell|TEMP.Veles|APT39|FIN4|Night Dragon|Dragonfly 2.0|FIN8|Leviathan|APT33|OilRig|FIN5|menuPass|APT28|FIN10|Suckfly|FIN6|Threat Group-3390|APT18|PittyTiger|Carbanak
394 T1074 Data Staged Collection Wizard Spider
395 T1072 Software Deployment Tools Execution|Lateral Movement Silence|APT32|Threat Group-1314
396 T1071 Application Layer Protocol Command And Control Rocke|Magic Hound|Dragonfly 2.0
397 T1070 Indicator Removal on Host Defense Evasion UNC2452 no
398 T1069 Permission Groups Discovery Discovery UNC2452|TA505|APT3 TA505|APT3
399 T1068 Exploitation for Privilege Escalation Privilege Escalation Whitefly|APT33|Cobalt Group|PLATINUM|FIN8|APT32|Threat Group-3390|FIN6|APT28
400 T1064 Scripting Defense Evasion|Execution no
401 T1062 Hypervisor Persistence no
402 T1061 Graphical User Interface Execution no
403 T1059 Command and Scripting Interpreter Execution APT32|Molerats|Whitefly|APT39|APT19|FIN7|Dragonfly 2.0|OilRig|FIN5|Stealth Falcon|FIN6|Ke3chang APT32|Molerats|Whitefly|Dragonfly 2.0|APT19|FIN7|OilRig|FIN5|Stealth Falcon|FIN6|Ke3chang
404 T1057 Process Discovery Discovery UNC2452|Rocke|Frankenstein|Inception|Darkhotel|MuddyWater|APT1|APT38|Tropic Trooper|APT37|Honeybee|OilRig|APT3|Magic Hound|APT28|Winnti Group|Stealth Falcon|Poseidon Group|Lazarus Group|Molerats|Turla|Deep Panda|Ke3chang Rocke|Frankenstein|Inception|Darkhotel|MuddyWater|APT1|APT38|Tropic Trooper|APT37|Honeybee|OilRig|APT3|Magic Hound|APT28|Winnti Group|Stealth Falcon|Poseidon Group|Lazarus Group|Molerats|Turla|Deep Panda|Ke3chang
405 T1056 Input Capture Collection|Credential Access no
406 T1055 Process Injection Defense Evasion|Privilege Escalation APT32|Sharpshooter|Silence|APT41|Kimsuky|Cobalt Group|APT37|Turla|Honeybee|PLATINUM APT32|Sharpshooter|Silence|APT41|Kimsuky|Turla|Cobalt Group|APT37|Honeybee|PLATINUM
407 T1053 Scheduled Task/Job Execution|Persistence|Privilege Escalation no
408 T1052 Exfiltration Over Physical Medium Exfiltration no
409 T1051 Shared Webroot Lateral Movement no
410 T1049 System Network Connections Discovery Discovery Tropic Trooper|APT41|APT38|Soft Cell|APT32|APT1|OilRig|APT3|Threat Group-3390|menuPass|Poseidon Group|admin@338|Turla|Ke3chang Tropic Trooper|APT41|APT38|Soft Cell|APT32|APT1|OilRig|APT3|menuPass|Threat Group-3390|Poseidon Group|admin@338|Turla|Ke3chang
411 T1048 Exfiltration Over Alternative Protocol Exfiltration no
412 T1047 Windows Management Instrumentation Execution UNC2452|Chimera|Blue Mockingbird|Wizard Spider|Frankenstein|APT41|FIN6|Soft Cell|APT32|MuddyWater|OilRig|Threat Group-3390|FIN8|Leviathan|menuPass|Stealth Falcon|Lazarus Group|APT29|Deep Panda Blue Mockingbird|Wizard Spider|Frankenstein|APT41|FIN6|Soft Cell|APT32|MuddyWater|OilRig|Threat Group-3390|FIN8|Leviathan|menuPass|Stealth Falcon|Lazarus Group|APT29|Deep Panda
413 T1046 Network Service Scanning Discovery Rocke|DarkVishnya|APT41|Tropic Trooper|APT39|APT32|Cobalt Group|Leafminer|OilRig|menuPass|Suckfly|FIN6|Threat Group-3390 Rocke|DarkVishnya|APT41|Tropic Trooper|APT39|APT32|Leafminer|OilRig|Cobalt Group|menuPass|Suckfly|FIN6|Threat Group-3390
414 T1043 Commonly Used Port Command And Control OilRig|APT28|TEMP.Veles|Night Dragon|APT29|APT18|FIN7|Dragonfly 2.0|APT19|FIN8|APT37|APT3|Magic Hound|Lazarus Group|Threat Group-3390 Machete|OilRig|APT28|TEMP.Veles|Night Dragon|APT29|APT18|APT19|Dragonfly 2.0|FIN7|FIN8|APT37|Magic Hound|APT3|Lazarus Group|Threat Group-3390
415 T1041 Exfiltration Over C2 Channel Exfiltration Sandworm Team|MuddyWater|Wizard Spider|Frankenstein|Kimsuky|Soft Cell|APT32|APT3|Gamaredon Group|Stealth Falcon|Lazarus Group|Ke3chang
416 T1040 Network Sniffing Credential Access|Discovery Sandworm Team|DarkVishnya|APT33|Stolen Pencil|APT28
417 T1039 Data from Network Shared Drive Collection Gamaredon Group|BRONZE BUTLER|Sowbug|menuPass Sowbug|BRONZE BUTLER|menuPass
418 T1037 Boot or Logon Initialization Scripts Persistence|Privilege Escalation Rocke
419 T1036 Masquerading Defense Evasion UNC2452|Windshift|APT32|BRONZE BUTLER|menuPass|Dragonfly 2.0 Windshift|APT32|BRONZE BUTLER|menuPass|Dragonfly 2.0
420 T1034 Path Interception Persistence|Privilege Escalation no
421 T1033 System Owner/User Discovery Discovery Wizard Spider|Frankenstein|APT41|Soft Cell|Tropic Trooper|APT39|MuddyWater|APT32|APT37|APT19|Dragonfly 2.0|OilRig|Magic Hound|FIN10|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|APT3 Frankenstein|APT41|Soft Cell|Tropic Trooper|APT39|MuddyWater|APT32|APT37|APT19|Dragonfly 2.0|OilRig|Magic Hound|FIN10|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|APT3
422 T1030 Data Transfer Size Limits Exfiltration Threat Group-3390
423 T1029 Scheduled Transfer Exfiltration no
424 T1027 Obfuscated Files or Information Defense Evasion UNC2452|FIN6|Chimera|Gamaredon Group|Rocke|Sandworm Team|Blue Mockingbird|Whitefly|Molerats|Wizard Spider|Mofang|Frankenstein|Inception|APT-C-36|APT41|Machete|Soft Cell|Turla|TA505|Silence|APT33|Night Dragon|Darkhotel|Gallmaker|APT29|APT18|Tropic Trooper|menuPass|Honeybee|Patchwork|Threat Group-3390|APT19|Cobalt Group|Leafminer|APT37|Dark Caracal|FIN8|MuddyWater|FIN7|BlackOasis|Leviathan|Elderwood|OilRig|Magic Hound|APT3|APT32|Group5|Lazarus Group|Dust Storm|Putter Panda|APT28 Gamaredon Group|Rocke|Sandworm Team|Blue Mockingbird|Whitefly|Molerats|Wizard Spider|Mofang|Frankenstein|Inception|APT-C-36|APT41|Machete|Soft Cell|Turla|TA505|Silence|APT33|Night Dragon|Darkhotel|Gallmaker|APT29|APT18|Tropic Trooper|Cobalt Group|Patchwork|Leafminer|APT37|Threat Group-3390|Honeybee|Dark Caracal|menuPass|APT19|BlackOasis|FIN8|Leviathan|Elderwood|MuddyWater|FIN7|Magic Hound|OilRig|APT3|APT32|Group5|Dust Storm|Lazarus Group|Putter Panda|APT28
425 T1026 Multiband Communication Command And Control Lazarus Group
426 T1025 Data from Removable Media Collection Machete|Turla|Gamaredon Group|APT28
427 T1021 Remote Services Lateral Movement no
428 T1020 Automated Exfiltration Exfiltration Gamaredon Group|Tropic Trooper|Frankenstein|Honeybee Tropic Trooper|Frankenstein|Honeybee
429 T1018 Remote System Discovery Discovery UNC2452|Sandworm Team|Rocke|Wizard Spider|Silence|Soft Cell|APT39|APT32|Threat Group-3390|Dragonfly 2.0|Ke3chang|Leafminer|Deep Panda|FIN8|FIN5|APT3|BRONZE BUTLER|menuPass|FIN6|Turla Sandworm Team|Rocke|Wizard Spider|Silence|Soft Cell|APT39|APT32|Deep Panda|Threat Group-3390|Dragonfly 2.0|Leafminer|Ke3chang|FIN8|APT3|FIN5|BRONZE BUTLER|menuPass|FIN6|Turla
430 T1016 System Network Configuration Discovery Discovery Wizard Spider|Sandworm Team|Tropic Trooper|Frankenstein|APT41|Soft Cell|APT32|Darkhotel|MuddyWater|APT1|Dragonfly 2.0|APT19|OilRig|Magic Hound|menuPass|Threat Group-3390|Stealth Falcon|Lazarus Group|APT3|Naikon|admin@338|Turla|Ke3chang Sandworm Team|Tropic Trooper|Frankenstein|APT41|Soft Cell|APT32|Darkhotel|MuddyWater|APT1|APT19|Dragonfly 2.0|Magic Hound|OilRig|menuPass|Threat Group-3390|Stealth Falcon|Lazarus Group|APT3|Naikon|admin@338|Turla|Ke3chang
431 T1014 Rootkit Defense Evasion Rocke|APT41|APT28|Winnti Group
432 T1012 Query Registry Discovery APT32|Threat Group-3390|Dragonfly 2.0|OilRig|Stealth Falcon|Lazarus Group|Turla APT32|Dragonfly 2.0|Threat Group-3390|OilRig|Stealth Falcon|Lazarus Group|Turla
433 T1011 Exfiltration Over Other Network Medium Exfiltration no
434 T1010 Application Window Discovery Discovery Lazarus Group
435 T1008 Fallback Channels Command And Control APT41|OilRig|Lazarus Group
436 T1007 System Service Discovery Discovery BRONZE BUTLER|APT1|OilRig|Poseidon Group|admin@338|Turla|Ke3chang
437 T1006 Direct Volume Access Defense Evasion no
438 T1005 Data from Local System Collection UNC2452|FIN6|Gamaredon Group|APT39|Frankenstein|Inception|Kimsuky|Soft Cell|Turla|menuPass|Dark Caracal|Dragonfly 2.0|Honeybee|APT28|APT37|APT3|BRONZE BUTLER|Patchwork|Stealth Falcon|Lazarus Group|Dust Storm|Threat Group-3390|APT1|Ke3chang Gamaredon Group|APT39|Frankenstein|Inception|Kimsuky|Soft Cell|Turla|menuPass|Dark Caracal|Dragonfly 2.0|Honeybee|APT37|APT28|APT3|BRONZE BUTLER|Patchwork|Stealth Falcon|Lazarus Group|Dust Storm|Threat Group-3390|APT1|Ke3chang
439 T1003 OS Credential Dumping Credential Access APT39|Frankenstein|APT32|APT28|Leviathan|Sowbug|Suckfly|Poseidon Group|Axiom
440 T1001 Data Obfuscation Command And Control Axiom
+1 -1
View File
@@ -5,7 +5,7 @@
"id": {
"group": null,
"name": "DA-ESS_AmazonWebServices_Content",
"version": "3.18.0"
"version": "3.19.0"
},
"author": [
{
+14 -14
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-04-12T22:03:03 UTC
# On Date: 2021-04-22T21:35:56 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -14,8 +14,8 @@ modification_date = 2021-03-08
id = ced74200-8465-4bc3-bd2c-22782eec6750
version = 1
reference = ["https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/", "https://www.cyberark.com/resources/threat-research-blog/the-cloud-shadow-admin-threat-10-permissions-to-protect", "https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws"]
detection_searches = ["ESCU - AWS Create Policy Version to allow all resources - Rule", "ESCU - AWS CreateAccessKey - Rule", "ESCU - AWS CreateLoginProfile - Rule", "ESCU - AWS SetDefaultPolicyVersion - Rule", "ESCU - AWS UpdateLoginProfile - Rule"]
mappings = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004", "T1136.003"], "nist": ["DE.CM", "PR.AC", "PR.DS"]}
detection_searches = ["ESCU - AWS Create Policy Version to allow all resources - Rule", "ESCU - AWS CreateAccessKey - Rule", "ESCU - AWS CreateLoginProfile - Rule", "ESCU - AWS IAM Assume Role Policy Brute Force - Rule", "ESCU - AWS IAM Delete Policy - Rule", "ESCU - AWS IAM Failure Group Deletion - Rule", "ESCU - AWS IAM Successful Group Deletion - Rule", "ESCU - AWS SetDefaultPolicyVersion - Rule", "ESCU - AWS UpdateLoginProfile - Rule"]
mappings = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives", "Reconnaissance"], "mitre_attack": ["T1069.003", "T1078.004", "T1098", "T1110", "T1136.003", "T1580"], "nist": ["DE.CM", "PR.AC", "PR.DS"]}
investigative_searches = []
support_searches = []
data_models = []
@@ -34,7 +34,7 @@ version = 2
reference = ["https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_Appendix_NACLs.html", "https://aws.amazon.com/blogs/security/how-to-help-prepare-for-ddos-attacks-by-reducing-your-attack-surface/"]
detection_searches = ["ESCU - AWS Network Access Control List Created with All Open Ports - Rule", "ESCU - AWS Network Access Control List Deleted - Rule"]
mappings = {"cis20": ["CIS 11"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562.007"], "nist": ["DE.AE", "DE.DP"]}
investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task"]
investigative_searches = ["ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task"]
support_searches = []
data_models = []
providing_technologies = none
@@ -68,8 +68,8 @@ version = 1
reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"]
detection_searches = ["ESCU - Abnormally High Number Of Cloud Instances Launched - Rule", "ESCU - Cloud Compute Instance Created By Previously Unseen User - Rule", "ESCU - Cloud Compute Instance Created In Previously Unused Region - Rule", "ESCU - Cloud Compute Instance Created With Previously Unseen Image - Rule", "ESCU - Cloud Compute Instance Created With Previously Unseen Instance Type - Rule"]
mappings = {"cis20": ["CIS 1", "CIS 12", "CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004", "T1535"], "nist": ["DE.AE", "DE.DP", "ID.AM"]}
investigative_searches = ["ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Investigate AWS activities via region name - Response Task"]
support_searches = ["ESCU - Previously Seen Cloud Compute Images - Update", "ESCU - Previously Seen Cloud Compute Instance Types - Initial", "ESCU - Previously Seen Cloud Compute Instance Types - Update", "ESCU - Previously Seen Cloud Compute Images - Initial", "ESCU - Baseline Of Cloud Instances Destroyed", "ESCU - Previously Seen Cloud Regions - Initial", "ESCU - Previously Seen Cloud Regions - Update", "ESCU - Previously Seen Cloud Compute Creations By User - Initial", "ESCU - Baseline Of Cloud Instances Launched", "ESCU - Previously Seen Cloud Compute Creations By User - Update"]
investigative_searches = ["ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task"]
support_searches = ["ESCU - Baseline Of Cloud Instances Destroyed", "ESCU - Previously Seen Cloud Regions - Update", "ESCU - Previously Seen Cloud Compute Instance Types - Initial", "ESCU - Previously Seen Cloud Compute Creations By User - Update", "ESCU - Previously Seen Cloud Regions - Initial", "ESCU - Previously Seen Cloud Compute Instance Types - Update", "ESCU - Previously Seen Cloud Compute Images - Update", "ESCU - Previously Seen Cloud Compute Images - Initial", "ESCU - Baseline Of Cloud Instances Launched", "ESCU - Previously Seen Cloud Compute Creations By User - Initial"]
data_models = ["Change"]
providing_technologies = none
description = Monitor your cloud compute instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or compute instances started by previously unseen users are just a few examples of potentially malicious behavior.
@@ -156,7 +156,7 @@ version = 2
reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf", "https://www.tripwire.com/state-of-security/security-data-protection/cloud/public-aws-s3-buckets-writable/"]
detection_searches = ["ESCU - Detect New Open S3 Buckets over AWS CLI - Rule", "ESCU - Detect New Open S3 buckets - Rule"]
mappings = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1530"], "nist": ["DE.CM", "PR.AC", "PR.DS"]}
investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - AWS S3 Bucket details via bucketName - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Investigate AWS activities via region name - Response Task"]
investigative_searches = ["ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - AWS S3 Bucket details via bucketName - Response Task"]
support_searches = []
data_models = []
providing_technologies = none
@@ -176,7 +176,7 @@ reference = ["https://aws.amazon.com/blogs/security/aws-cloudtrail-now-tracks-cr
detection_searches = ["ESCU - AWS Cross Account Activity From Previously Unseen Account - Rule", "ESCU - Detect AWS Console Login by New User - Rule", "ESCU - Detect AWS Console Login by User from New City - Rule", "ESCU - Detect AWS Console Login by User from New Country - Rule", "ESCU - Detect AWS Console Login by User from New Region - Rule"]
mappings = {"cis20": ["CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1535"], "nist": ["DE.AE", "DE.DP", "PR.AC", "PR.DS"]}
investigative_searches = ["ESCU - Investigate AWS User Activities by user field - Response Task"]
support_searches = ["ESCU - Previously Seen AWS Cross Account Activity - Update", "ESCU - Previously Seen Users In CloudTrail - Update", "ESCU - Previously Seen Users in CloudTrail - Initial", "ESCU - Previously Seen AWS Cross Account Activity - Initial"]
support_searches = ["ESCU - Previously Seen AWS Cross Account Activity - Update", "ESCU - Previously Seen Users in CloudTrail - Initial", "ESCU - Previously Seen AWS Cross Account Activity - Initial", "ESCU - Previously Seen Users In CloudTrail - Update"]
data_models = ["Authentication"]
providing_technologies = none
description = Monitor your cloud authentication events. Searches within this Analytic Story leverage the recent cloud updates to the Authentication data model to help you stay aware of and investigate suspicious login activity.
@@ -193,8 +193,8 @@ version = 1
reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"]
detection_searches = ["ESCU - Abnormally High Number Of Cloud Instances Destroyed - Rule", "ESCU - Abnormally High Number Of Cloud Instances Launched - Rule", "ESCU - Cloud Instance Modified By Previously Unseen User - Rule"]
mappings = {"cis20": ["CIS 1", "CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004"], "nist": ["DE.AE", "DE.DP", "ID.AM"]}
investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task"]
support_searches = ["ESCU - Previously Seen Cloud Instance Modifications By User - Update", "ESCU - Baseline Of Cloud Instances Destroyed", "ESCU - Previously Seen Cloud Instance Modifications By User - Initial", "ESCU - Baseline Of Cloud Instances Launched"]
investigative_searches = ["ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task"]
support_searches = ["ESCU - Baseline Of Cloud Instances Destroyed", "ESCU - Baseline Of Cloud Instances Launched", "ESCU - Previously Seen Cloud Instance Modifications By User - Update", "ESCU - Previously Seen Cloud Instance Modifications By User - Initial"]
data_models = ["Change"]
providing_technologies = none
description = Monitor your cloud infrastructure provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your cloud environment.
@@ -211,7 +211,7 @@ reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.p
detection_searches = ["ESCU - Cloud Provisioning Activity From Previously Unseen City - Rule", "ESCU - Cloud Provisioning Activity From Previously Unseen Country - Rule", "ESCU - Cloud Provisioning Activity From Previously Unseen IP Address - Rule", "ESCU - Cloud Provisioning Activity From Previously Unseen Region - Rule"]
mappings = {"cis20": ["CIS 1"], "mitre_attack": ["T1078"], "nist": ["ID.AM"]}
investigative_searches = []
support_searches = ["ESCU - Previously Seen Cloud Provisioning Activity Sources - Initial", "ESCU - Previously Seen Cloud Provisioning Activity Sources - Update"]
support_searches = ["ESCU - Previously Seen Cloud Provisioning Activity Sources - Update", "ESCU - Previously Seen Cloud Provisioning Activity Sources - Initial"]
data_models = ["Change"]
providing_technologies = none
description = Monitor your cloud infrastructure provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your cloud environment.
@@ -226,10 +226,10 @@ modification_date = 2020-09-04
id = 1ed5ce7d-5469-4232-92af-89d1a3595b39
version = 1
reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf", "https://redlock.io/blog/cryptojacking-tesla"]
detection_searches = ["ESCU - Abnormally High Number Of Cloud Infrastructure API Calls - Rule", "ESCU - Abnormally High Number Of Cloud Security Group API Calls - Rule", "ESCU - Cloud API Calls From Previously Unseen User Roles - Rule"]
mappings = {"cis20": ["CIS 1", "CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078", "T1078.004"], "nist": ["DE.CM", "DE.DP", "ID.AM", "PR.AC"]}
detection_searches = ["ESCU - AWS IAM AccessDenied Discovery Events - Rule", "ESCU - Abnormally High Number Of Cloud Infrastructure API Calls - Rule", "ESCU - Abnormally High Number Of Cloud Security Group API Calls - Rule", "ESCU - Cloud API Calls From Previously Unseen User Roles - Rule"]
mappings = {"cis20": ["CIS 1", "CIS 16"], "kill_chain_phases": ["Actions on Objectives", "Reconnaissance"], "mitre_attack": ["T1078", "T1078.004", "T1580"], "nist": ["DE.CM", "DE.DP", "ID.AM", "PR.AC"]}
investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task"]
support_searches = ["ESCU - Previously Seen Cloud API Calls Per User Role - Initial", "ESCU - Baseline Of Cloud Security Group API Calls Per User", "ESCU - Previously Seen Cloud API Calls Per User Role - Update", "ESCU - Baseline Of Cloud Infrastructure API Calls Per User"]
support_searches = ["ESCU - Previously Seen Cloud API Calls Per User Role - Update", "ESCU - Baseline Of Cloud Security Group API Calls Per User", "ESCU - Baseline Of Cloud Infrastructure API Calls Per User", "ESCU - Previously Seen Cloud API Calls Per User Role - Initial"]
data_models = ["Change"]
providing_technologies = none
description = Detect and investigate suspicious activities by users and roles in your cloud environments.
+72 -4799
View File
File diff suppressed because it is too large Load Diff
+2 -2
View File
@@ -4,7 +4,7 @@
is_configured = false
state = enabled
state_change_requires_restart = false
build = 25386
build = 27110
[triggers]
reload.analytic_stories = simple
@@ -18,7 +18,7 @@ reload.content-version = simple
[launcher]
author = Splunk
version = 3.18.0
version = 3.19.0
description = Explore the Analytic Stories included with Splunk Security Analytics for AWS Content
[ui]
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-04-12T22:03:03 UTC
# On Date: 2021-04-22T21:35:56 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+1 -1
View File
@@ -1,2 +1,2 @@
[content-version]
version = 3.18.0
version = 3.19.0
+4 -4
View File
@@ -11,7 +11,7 @@ label = AWS Network ACL Activity
description = Monitor your AWS network infrastructure for bad configurations and malicious activity. Investigative searches help you probe deeper, when the facts warrant it.
disabled = 0
panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_aws_network_interface_details_via_resourceid___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_aws_network_acl_details_from_id___response_task"]
panels = ["panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_aws_network_interface_details_via_resourceid___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_aws_network_acl_details_from_id___response_task"]
[panel_group://workbench_panel_group_aws_security_hub_alerts]
label = AWS Security Hub Alerts
@@ -25,7 +25,7 @@ label = Cloud Cryptomining
description = Monitor your cloud compute instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or compute instances started by previously unseen users are just a few examples of potentially malicious behavior.
disabled = 0
panels = ["panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task", "panel://workbench_panel_get_ec2_launch_details___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task"]
panels = ["panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task", "panel://workbench_panel_get_ec2_launch_details___response_task", "panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task"]
[panel_group://workbench_panel_group_cloud_federated_credential_abuse]
label = Cloud Federated Credential Abuse
@@ -60,7 +60,7 @@ label = Suspicious AWS S3 Activities
description = Use the searches in this Analytic Story to monitor your AWS S3 buckets for evidence of anomalous activity and suspicious behaviors, such as detecting open S3 buckets and buckets being accessed from a new IP. The contextual and investigative searches will give you more information, when required.
disabled = 0
panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_aws_s3_bucket_details_via_bucketname___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task"]
panels = ["panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task", "panel://workbench_panel_aws_s3_bucket_details_via_bucketname___response_task"]
[panel_group://workbench_panel_group_suspicious_cloud_authentication_activities]
label = Suspicious Cloud Authentication Activities
@@ -74,7 +74,7 @@ label = Suspicious Cloud Instance Activities
description = Monitor your cloud infrastructure provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your cloud environment.
disabled = 0
panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task"]
panels = ["panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task"]
[panel_group://workbench_panel_group_suspicious_cloud_provisioning_activities]
label = Suspicious Cloud Provisioning Activities
+25 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-04-12T22:03:03 UTC
# On Date: 2021-04-22T21:35:56 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -315,6 +315,30 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[aws_excessive_security_scanning_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[aws_iam_accessdenied_discovery_events_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[aws_iam_assume_role_policy_brute_force_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[aws_iam_delete_policy_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[aws_iam_failure_group_deletion_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[aws_iam_successful_group_deletion_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[aws_network_access_control_list_created_with_all_open_ports_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
+210 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-04-12T22:03:03 UTC
# On Date: 2021-04-22T21:35:56 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -241,6 +241,215 @@ realtime_schedule = 0
is_visible = false
search = `cloudtrail` eventName=CopyObject requestParameters.x-amz-server-side-encryption="aws:kms" | rename requestParameters.bucketName AS bucket_name, requestParameters.x-amz-copy-source AS src_file, requestParameters.key AS dest_file | stats count min(_time) as firstTime max(_time) as lastTime values(src_file) AS src_file values(dest_file) AS dest_file values(userAgent) AS userAgent values(region) AS region values(src) AS src by user | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` |`aws_detect_users_with_kms_keys_performing_encryption_s3_filter`
[ESCU - AWS Excessive Security Scanning - Rule]
action.escu = 0
action.escu.enabled = 1
description = This search looks for CloudTrail events and analyse the amount of eventNames which starts with Describe by a single user. This indicates that this user scans the configuration of your AWS cloud environment.
action.escu.mappings = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1526"], "nist": ["PR.DS", "PR.AC", "DE.CM"]}
action.escu.data_models = []
action.escu.eli5 = This search looks for CloudTrail events and analyse the amount of eventNames which starts with Describe by a single user. This indicates that this user scans the configuration of your AWS cloud environment.
action.escu.how_to_implement = You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs.
action.escu.known_false_positives = While this search has no known false positives.
action.escu.creation_date = 2021-04-13
action.escu.modification_date = 2021-04-13
action.escu.confidence = high
action.escu.full_search_name = ESCU - AWS Excessive Security Scanning - Rule
action.escu.search_type = detection
action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"]
action.escu.providing_technologies = []
action.escu.analytic_story = ["AWS User Monitoring"]
action.risk = 1
action.risk.param._risk_object = src
action.risk.param._risk_object_type = system
action.risk.param._risk_score = 20
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
dispatch.latest_time = -10m@m
action.correlationsearch.enabled = 1
action.correlationsearch.label = ESCU - AWS Excessive Security Scanning - Rule
action.correlationsearch.annotations = {"analytic_story": ["AWS User Monitoring"], "cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1526"], "nist": ["PR.DS", "PR.AC", "DE.CM"]}
schedule_window = auto
alert.digest_mode = 1
disabled = false
enableSched = 1
counttype = number of events
relation = greater than
quantity = 0
realtime_schedule = 0
is_visible = false
search = `cloudtrail` eventName=Describe* OR eventName=List* OR eventName=Get* | stats dc(eventName) as dc_events min(_time) as firstTime max(_time) as lastTime values(eventName) as eventName values(src) as src values(userAgent) as userAgent by user userIdentity.arn | where dc_events > 50 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|`aws_excessive_security_scanning_filter`
[ESCU - AWS IAM AccessDenied Discovery Events - Rule]
action.escu = 0
action.escu.enabled = 1
description = The following detection identifies excessive AccessDenied events within an hour timeframe. It is possible that an access key to AWS may have been stolen and is being misused to perform discovery events. In these instances, the access is not available with the key stolen therefore these events will be generated.
action.escu.mappings = {"kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1580"]}
action.escu.data_models = []
action.escu.eli5 = The following detection identifies excessive AccessDenied events within an hour timeframe. It is possible that an access key to AWS may have been stolen and is being misused to perform discovery events. In these instances, the access is not available with the key stolen therefore these events will be generated.
action.escu.how_to_implement = The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs.
action.escu.known_false_positives = It is possible to start this detection will need to be tuned by source IP or user. In addition, change the count values to an upper threshold to restrict false positives.
action.escu.creation_date = 2021-04-05
action.escu.modification_date = 2021-04-05
action.escu.confidence = high
action.escu.full_search_name = ESCU - AWS IAM AccessDenied Discovery Events - Rule
action.escu.search_type = detection
action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud", "Splunk Security Analytics for AWS"]
action.escu.providing_technologies = []
action.escu.analytic_story = ["Suspicious Cloud User Activities"]
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
dispatch.latest_time = -10m@m
action.correlationsearch.enabled = 1
action.correlationsearch.label = ESCU - AWS IAM AccessDenied Discovery Events - Rule
action.correlationsearch.annotations = {"analytic_story": ["Suspicious Cloud User Activities"], "kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1580"]}
schedule_window = auto
alert.digest_mode = 1
disabled = false
enableSched = 1
counttype = number of events
relation = greater than
quantity = 0
realtime_schedule = 0
is_visible = false
search = `cloudtrail` (errorCode = "AccessDenied") user_type=IAMUser (userAgent!=*.amazonaws.com) | bucket _time span=1h | stats count as failures min(_time) as firstTime max(_time) as lastTime, dc(eventName) as methods, dc(eventSource) as sources values(userIdentity.arn) by src_ip, userIdentity.arn, _time | where failures >= 5 and methods >= 1 and sources >= 1 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_iam_accessdenied_discovery_events_filter`
[ESCU - AWS IAM Assume Role Policy Brute Force - Rule]
action.escu = 0
action.escu.enabled = 1
description = The following detection identifies any malformed policy document exceptions with a status of `failure`. A malformed policy document exception occurs in instances where roles are attempted to be assumed, or brute forced. In a brute force attempt, using a tool like CloudSploit or Pacu, an attempt will look like `arn:aws:iam::111111111111:role/aws-service-role/rds.amazonaws.com/AWSServiceRoleForRDS`. Meaning, when an adversary is attempting to identify a role name, multiple failures will occur. This detection focuses on the errors of a remote attempt that is failing.
action.escu.mappings = {"kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1580", "T1110"]}
action.escu.data_models = []
action.escu.eli5 = The following detection identifies any malformed policy document exceptions with a status of `failure`. A malformed policy document exception occurs in instances where roles are attempted to be assumed, or brute forced. In a brute force attempt, using a tool like CloudSploit or Pacu, an attempt will look like `arn:aws:iam::111111111111:role/aws-service-role/rds.amazonaws.com/AWSServiceRoleForRDS`. Meaning, when an adversary is attempting to identify a role name, multiple failures will occur. This detection focuses on the errors of a remote attempt that is failing.
action.escu.how_to_implement = The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs. Set the `where count` greater than a value to identify suspicious activity in your environment.
action.escu.known_false_positives = This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users.
action.escu.creation_date = 2021-04-01
action.escu.modification_date = 2021-04-01
action.escu.confidence = high
action.escu.full_search_name = ESCU - AWS IAM Assume Role Policy Brute Force - Rule
action.escu.search_type = detection
action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud", "Splunk Security Analytics for AWS"]
action.escu.providing_technologies = []
action.escu.analytic_story = ["AWS IAM Privilege Escalation"]
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
dispatch.latest_time = -10m@m
action.correlationsearch.enabled = 1
action.correlationsearch.label = ESCU - AWS IAM Assume Role Policy Brute Force - Rule
action.correlationsearch.annotations = {"analytic_story": ["AWS IAM Privilege Escalation"], "kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1580", "T1110"]}
schedule_window = auto
alert.digest_mode = 1
disabled = false
enableSched = 1
counttype = number of events
relation = greater than
quantity = 0
realtime_schedule = 0
is_visible = false
search = `cloudtrail` (errorCode=MalformedPolicyDocumentException) status=failure (userAgent!=*.amazonaws.com) | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.policyName) as policy_name by src eventName eventSource aws_account_id errorCode requestParameters.policyDocument userAgent eventID awsRegion userIdentity.principalId user_arn | where count >= 2 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_iam_assume_role_policy_brute_force_filter`
[ESCU - AWS IAM Delete Policy - Rule]
action.escu = 0
action.escu.enabled = 1
description = The following detection identifes when a policy is deleted on AWS. This does not identify whether successful or failed, but the error messages tell a story of suspicious attempts. There is a specific process to follow when deleting a policy. First, detach the policy from all users, groups, and roles that the policy is attached to, using DetachUserPolicy , DetachGroupPolicy , or DetachRolePolicy.
action.escu.mappings = {"kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1098"]}
action.escu.data_models = []
action.escu.eli5 = The following detection identifes when a policy is deleted on AWS. This does not identify whether successful or failed, but the error messages tell a story of suspicious attempts. There is a specific process to follow when deleting a policy. First, detach the policy from all users, groups, and roles that the policy is attached to, using DetachUserPolicy , DetachGroupPolicy , or DetachRolePolicy.
action.escu.how_to_implement = The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs.
action.escu.known_false_positives = This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users. Not every user with AWS access should have permission to delete policies (least privilege). In addition, this may be saved seperately and tuned for failed or success attempts only.
action.escu.creation_date = 2021-04-01
action.escu.modification_date = 2021-04-01
action.escu.confidence = high
action.escu.full_search_name = ESCU - AWS IAM Delete Policy - Rule
action.escu.search_type = detection
action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud", "Splunk Security Analytics for AWS"]
action.escu.providing_technologies = []
action.escu.analytic_story = ["AWS IAM Privilege Escalation"]
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
dispatch.latest_time = -10m@m
action.correlationsearch.enabled = 1
action.correlationsearch.label = ESCU - AWS IAM Delete Policy - Rule
action.correlationsearch.annotations = {"analytic_story": ["AWS IAM Privilege Escalation"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1098"]}
schedule_window = auto
alert.digest_mode = 1
disabled = false
enableSched = 1
counttype = number of events
relation = greater than
quantity = 0
realtime_schedule = 0
is_visible = false
search = `cloudtrail` eventName=DeletePolicy (userAgent!=*.amazonaws.com) | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.policyArn) as policyArn by src eventName eventSource aws_account_id errorCode errorMessage userAgent eventID awsRegion userIdentity.principalId userIdentity.arn | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_iam_delete_policy_filter`
[ESCU - AWS IAM Failure Group Deletion - Rule]
action.escu = 0
action.escu.enabled = 1
description = This detection identifies failure attempts to delete groups. We want to identify when a group is attempting to be deleted, but either access is denied, there is a conflict or there is no group. This is indicative of administrators performing an action, but also could be suspicious behavior occurring. Review parallel IAM events - recently added users, new groups and so forth.
action.escu.mappings = {"kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1098"]}
action.escu.data_models = []
action.escu.eli5 = This detection identifies failure attempts to delete groups. We want to identify when a group is attempting to be deleted, but either access is denied, there is a conflict or there is no group. This is indicative of administrators performing an action, but also could be suspicious behavior occurring. Review parallel IAM events - recently added users, new groups and so forth.
action.escu.how_to_implement = The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs.
action.escu.known_false_positives = This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users. Not every user with AWS access should have permission to delete groups (least privilege).
action.escu.creation_date = 2021-04-01
action.escu.modification_date = 2021-04-01
action.escu.confidence = high
action.escu.full_search_name = ESCU - AWS IAM Failure Group Deletion - Rule
action.escu.search_type = detection
action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud", "Splunk Security Analytics for AWS"]
action.escu.providing_technologies = []
action.escu.analytic_story = ["AWS IAM Privilege Escalation"]
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
dispatch.latest_time = -10m@m
action.correlationsearch.enabled = 1
action.correlationsearch.label = ESCU - AWS IAM Failure Group Deletion - Rule
action.correlationsearch.annotations = {"analytic_story": ["AWS IAM Privilege Escalation"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1098"]}
schedule_window = auto
alert.digest_mode = 1
disabled = false
enableSched = 1
counttype = number of events
relation = greater than
quantity = 0
realtime_schedule = 0
is_visible = false
search = `cloudtrail` eventSource=iam.amazonaws.com eventName=DeleteGroup errorCode IN (NoSuchEntityException,DeleteConflictException, AccessDenied) (userAgent!=*.amazonaws.com) | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.groupName) as group_name by src eventName eventSource aws_account_id errorCode errorMessage userAgent eventID awsRegion userIdentity.principalId user_arn | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_iam_failure_group_deletion_filter`
[ESCU - AWS IAM Successful Group Deletion - Rule]
action.escu = 0
action.escu.enabled = 1
description = The following query uses IAM events to track the success of a group being deleted on AWS. This is typically not indicative of malicious behavior, but a precurser to additional events thay may unfold. Review parallel IAM events - recently added users, new groups and so forth. Inversely, review failed attempts in a similar manner.
action.escu.mappings = {"kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1069.003", "T1098"]}
action.escu.data_models = []
action.escu.eli5 = The following query uses IAM events to track the success of a group being deleted on AWS. This is typically not indicative of malicious behavior, but a precurser to additional events thay may unfold. Review parallel IAM events - recently added users, new groups and so forth. Inversely, review failed attempts in a similar manner.
action.escu.how_to_implement = The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs.
action.escu.known_false_positives = This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users. Not every user with AWS access should have permission to delete groups (least privilege).
action.escu.creation_date = 2021-03-31
action.escu.modification_date = 2021-03-31
action.escu.confidence = high
action.escu.full_search_name = ESCU - AWS IAM Successful Group Deletion - Rule
action.escu.search_type = detection
action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud", "Splunk Security Analytics for AWS"]
action.escu.providing_technologies = []
action.escu.analytic_story = ["AWS IAM Privilege Escalation"]
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
dispatch.latest_time = -10m@m
action.correlationsearch.enabled = 1
action.correlationsearch.label = ESCU - AWS IAM Successful Group Deletion - Rule
action.correlationsearch.annotations = {"analytic_story": ["AWS IAM Privilege Escalation"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1069.003", "T1098"]}
schedule_window = auto
alert.digest_mode = 1
disabled = false
enableSched = 1
counttype = number of events
relation = greater than
quantity = 0
realtime_schedule = 0
is_visible = false
search = `cloudtrail` eventSource=iam.amazonaws.com eventName=DeleteGroup errorCode=success (userAgent!=*.amazonaws.com) | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.groupName) by src eventName eventSource errorCode user_agent awsRegion userIdentity.principalId user_arn | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_iam_successful_group_deletion_filter`
[ESCU - AWS Network Access Control List Created with All Open Ports - Rule]
action.escu = 0
action.escu.enabled = 1
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-04-12T22:03:03 UTC
# On Date: 2021-04-22T21:35:56 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+71 -11
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-04-12T22:03:03 UTC
# On Date: 2021-04-22T21:35:56 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -14,7 +14,7 @@ version = 1
references = ["https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/", "https://www.cyberark.com/resources/threat-research-blog/the-cloud-shadow-admin-threat-10-permissions-to-protect", "https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws"]
maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}]
spec_version = 3
searches = ["ESCU - AWS Create Policy Version to allow all resources - Rule", "ESCU - AWS UpdateLoginProfile - Rule", "ESCU - AWS SetDefaultPolicyVersion - Rule", "ESCU - AWS CreateAccessKey - Rule", "ESCU - AWS CreateLoginProfile - Rule"]
searches = ["ESCU - AWS IAM Failure Group Deletion - Rule", "ESCU - AWS CreateLoginProfile - Rule", "ESCU - AWS Create Policy Version to allow all resources - Rule", "ESCU - AWS IAM Delete Policy - Rule", "ESCU - AWS SetDefaultPolicyVersion - Rule", "ESCU - AWS UpdateLoginProfile - Rule", "ESCU - AWS IAM Successful Group Deletion - Rule", "ESCU - AWS IAM Assume Role Policy Brute Force - Rule", "ESCU - AWS CreateAccessKey - Rule"]
description = This analytic story contains detections that query your AWS Cloudtrail for activities related to privilege escalation.
narrative = Amazon Web Services provides a neat feature called Identity and Access Management (IAM) that enables organizations to manage various AWS services and resources in a secure way. All IAM users have roles, groups and policies associated with them which governs and sets permissions to allow a user to access specific restrictions.\
However, if these IAM policies are misconfigured and have specific combinations of weak permissions; it can allow attackers to escalate their privileges and further compromise the organization. Rhino Security Labs have published comprehensive blogs detailing various AWS Escalation methods. By using this as an inspiration, Splunks research team wants to highlight how these attack vectors look in AWS Cloudtrail logs and provide you with detection queries to uncover these potentially malicious events via this Analytic Story. \
@@ -26,7 +26,7 @@ version = 2
references = ["https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_Appendix_NACLs.html", "https://aws.amazon.com/blogs/security/how-to-help-prepare-for-ddos-attacks-by-reducing-your-attack-surface/"]
maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}]
spec_version = 3
searches = ["ESCU - AWS Network Access Control List Created with All Open Ports - Rule", "ESCU - AWS Network Access Control List Deleted - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task"]
searches = ["ESCU - AWS Network Access Control List Deleted - Rule", "ESCU - AWS Network Access Control List Created with All Open Ports - Rule", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task"]
description = Monitor your AWS network infrastructure for bad configurations and malicious activity. Investigative searches help you probe deeper, when the facts warrant it.
narrative = AWS CloudTrail is an AWS service that helps you enable governance, compliance, and operational/risk auditing of your AWS account. Actions taken by a user, role, or an AWS service are recorded as events in CloudTrail. It is crucial for a company to monitor events and actions taken in the AWS Management Console, AWS Command Line Interface, and AWS SDKs and APIs to ensure that your servers are not vulnerable to attacks. This analytic story contains detection searches that leverage CloudTrail logs from AWS to check for bad configurations and malicious activity in your AWS network access controls.
@@ -48,7 +48,7 @@ version = 1
references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"]
maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}]
spec_version = 3
searches = ["ESCU - Cloud Compute Instance Created By Previously Unseen User - Rule", "ESCU - Cloud Compute Instance Created In Previously Unused Region - Rule", "ESCU - Cloud Compute Instance Created With Previously Unseen Instance Type - Rule", "ESCU - Cloud Compute Instance Created With Previously Unseen Image - Rule", "ESCU - Abnormally High Number Of Cloud Instances Launched - Rule", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Investigate AWS activities via region name - Response Task"]
searches = ["ESCU - Cloud Compute Instance Created With Previously Unseen Instance Type - Rule", "ESCU - Cloud Compute Instance Created In Previously Unused Region - Rule", "ESCU - Abnormally High Number Of Cloud Instances Launched - Rule", "ESCU - Cloud Compute Instance Created By Previously Unseen User - Rule", "ESCU - Cloud Compute Instance Created With Previously Unseen Image - Rule", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task"]
description = Monitor your cloud compute instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or compute instances started by previously unseen users are just a few examples of potentially malicious behavior.
narrative = Cryptomining is an intentionally difficult, resource-intensive business. Its complexity was designed into the process to ensure that the number of blocks mined each day would remain steady. So, it's par for the course that ambitious, but unscrupulous, miners make amassing the computing power of large enterprises--a practice known as cryptojacking--a top priority. \
Cryptojacking has attracted an increasing amount of media attention since its explosion in popularity in the fall of 2017. The attacks have moved from in-browser exploits and mobile phones to enterprise cloud services, such as Amazon Web Services (AWS), Google Cloud Platform (GCP), and Azure. It's difficult to determine exactly how widespread the practice has become, since bad actors continually evolve their ability to escape detection, including employing unlisted endpoints, moderating their CPU usage, and hiding the mining pool's IP address behind a free CDN. \
@@ -62,7 +62,7 @@ version = 1
references = ["https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps", "https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf", "https://us-cert.cisa.gov/ncas/alerts/aa21-008a"]
maintainers = [{"company": "Splunk", "email": "-", "name": "Rod Soto"}]
spec_version = 3
searches = ["ESCU - O365 Excessive SSO logon errors - Rule", "ESCU - AWS SAML Update identity provider - Rule", "ESCU - O365 New Federated Domain Added - Rule", "ESCU - O365 Add App Role Assignment Grant User - Rule", "ESCU - O365 Added Service Principal - Rule", "ESCU - AWS SAML Access by Provider User and Principal - Rule"]
searches = ["ESCU - O365 Excessive SSO logon errors - Rule", "ESCU - O365 Add App Role Assignment Grant User - Rule", "ESCU - AWS SAML Access by Provider User and Principal - Rule", "ESCU - O365 Added Service Principal - Rule", "ESCU - AWS SAML Update identity provider - Rule", "ESCU - O365 New Federated Domain Added - Rule"]
description = This analytical story addresses events that indicate abuse of cloud federated credentials. These credentials are usually extracted from endpoint desktop or servers specially those servers that provide federation services such as Windows Active Directory Federation Services. Identity Federation relies on objects such as Oauth2 tokens, cookies or SAML assertions in order to provide seamless access between cloud and perimeter environments. If these objects are either hijacked or forged then attackers will be able to pivot into victim's cloud environements.
narrative = This story is composed of detection searches based on endpoint that addresses the use of Mimikatz, Escalation of Privileges and Abnormal processes that may indicate the extraction of Federated directory objects such as passwords, Oauth2 tokens, certificates and keys. Cloud environment (AWS, Azure) related events are also addressed in specific cloud environment detection searches.
@@ -73,7 +73,7 @@ version = 1
references = ["https://i.blackhat.com/USA-20/Thursday/us-20-Bienstock-My-Cloud-Is-APTs-Cloud-Investigating-And-Defending-Office-365.pdf"]
maintainers = [{"company": "Splunk", "email": "-", "name": "Patrick Bareiss"}]
spec_version = 3
searches = ["ESCU - O365 Disable MFA - Rule", "ESCU - O365 Excessive SSO logon errors - Rule", "ESCU - O365 Excessive Authentication Failures Alert - Rule", "ESCU - O365 Suspicious Admin Email Forwarding - Rule", "ESCU - O365 Bypass MFA via Trusted IP - Rule", "ESCU - O365 PST export alert - Rule", "ESCU - O365 Suspicious Rights Delegation - Rule", "ESCU - O365 New Federated Domain Added - Rule", "ESCU - O365 Add App Role Assignment Grant User - Rule", "ESCU - O365 Suspicious User Email Forwarding - Rule", "ESCU - O365 Added Service Principal - Rule"]
searches = ["ESCU - O365 Excessive SSO logon errors - Rule", "ESCU - O365 Suspicious Rights Delegation - Rule", "ESCU - O365 Add App Role Assignment Grant User - Rule", "ESCU - O365 PST export alert - Rule", "ESCU - O365 Excessive Authentication Failures Alert - Rule", "ESCU - O365 Bypass MFA via Trusted IP - Rule", "ESCU - O365 Disable MFA - Rule", "ESCU - O365 Added Service Principal - Rule", "ESCU - O365 Suspicious User Email Forwarding - Rule", "ESCU - O365 New Federated Domain Added - Rule", "ESCU - O365 Suspicious Admin Email Forwarding - Rule"]
description = This story is focused around detecting Office 365 Attacks.
narrative = More and more companies are using Microsofts Office 365 cloud offering. Therefore, we see more and more attacks against Office 365. This story provides various detections for Office 365 attacks.
@@ -95,7 +95,7 @@ version = 1
references = ["https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-integration.html"]
maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}]
spec_version = 3
searches = ["ESCU - Detect AWS Console Login by User from New City - Rule", "ESCU - Detect AWS Console Login by User from New Region - Rule", "ESCU - Detect AWS Console Login by User from New Country - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task"]
searches = ["ESCU - Detect AWS Console Login by User from New Region - Rule", "ESCU - Detect AWS Console Login by User from New City - Rule", "ESCU - Detect AWS Console Login by User from New Country - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task"]
description = Monitor your AWS authentication events using your CloudTrail logs. Searches within this Analytic Story will help you stay aware of and investigate suspicious logins.
narrative = It is important to monitor and control who has access to your AWS infrastructure. Detecting suspicious logins to your AWS infrastructure will provide good starting points for investigations. Abusive behaviors caused by compromised credentials can lead to direct monetary costs, as you will be billed for any EC2 instances created by the attacker.
@@ -106,7 +106,7 @@ version = 2
references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf", "https://www.tripwire.com/state-of-security/security-data-protection/cloud/public-aws-s3-buckets-writable/"]
maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}]
spec_version = 3
searches = ["ESCU - Detect New Open S3 buckets - Rule", "ESCU - Detect New Open S3 Buckets over AWS CLI - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - AWS S3 Bucket details via bucketName - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Investigate AWS activities via region name - Response Task"]
searches = ["ESCU - Detect New Open S3 Buckets over AWS CLI - Rule", "ESCU - Detect New Open S3 buckets - Rule", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - AWS S3 Bucket details via bucketName - Response Task"]
description = Use the searches in this Analytic Story to monitor your AWS S3 buckets for evidence of anomalous activity and suspicious behaviors, such as detecting open S3 buckets and buckets being accessed from a new IP. The contextual and investigative searches will give you more information, when required.
narrative = As cloud computing has exploded, so has the number of creative attacks on virtual environments. And as the number-two cloud-service provider, Amazon Web Services (AWS) has certainly had its share.\
Amazon's "shared responsibility" model dictates that the company has responsibility for the environment outside of the VM and the customer is responsible for the security inside of the S3 container. As such, it's important to stay vigilant for activities that may belie suspicious behavior inside of your environment.\
@@ -119,7 +119,7 @@ version = 1
references = ["https://aws.amazon.com/blogs/security/aws-cloudtrail-now-tracks-cross-account-activity-to-its-origin/", "https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-integration.html"]
maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}]
spec_version = 3
searches = ["ESCU - AWS Cross Account Activity From Previously Unseen Account - Rule", "ESCU - Detect AWS Console Login by User from New Region - Rule", "ESCU - Detect AWS Console Login by User from New City - Rule", "ESCU - Detect AWS Console Login by User from New Country - Rule", "ESCU - Detect AWS Console Login by New User - Rule", "ESCU - Investigate AWS User Activities by user field - Response Task"]
searches = ["ESCU - Detect AWS Console Login by User from New Country - Rule", "ESCU - Detect AWS Console Login by User from New Region - Rule", "ESCU - Detect AWS Console Login by User from New City - Rule", "ESCU - AWS Cross Account Activity From Previously Unseen Account - Rule", "ESCU - Detect AWS Console Login by New User - Rule", "ESCU - Investigate AWS User Activities by user field - Response Task"]
description = Monitor your cloud authentication events. Searches within this Analytic Story leverage the recent cloud updates to the Authentication data model to help you stay aware of and investigate suspicious login activity.
narrative = It is important to monitor and control who has access to your cloud infrastructure. Detecting suspicious logins will provide good starting points for investigations. Abusive behaviors caused by compromised credentials can lead to direct monetary costs, as you will be billed for any compute activity whether legitimate or otherwise.\
This Analytic Story has data model versions of cloud searches leveraging Authentication data, including those looking for suspicious login activity, and cross-account activity for AWS.
@@ -131,7 +131,7 @@ version = 1
references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"]
maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}]
spec_version = 3
searches = ["ESCU - Abnormally High Number Of Cloud Instances Launched - Rule", "ESCU - Cloud Instance Modified By Previously Unseen User - Rule", "ESCU - Abnormally High Number Of Cloud Instances Destroyed - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task"]
searches = ["ESCU - Abnormally High Number Of Cloud Instances Launched - Rule", "ESCU - Abnormally High Number Of Cloud Instances Destroyed - Rule", "ESCU - Cloud Instance Modified By Previously Unseen User - Rule", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task"]
description = Monitor your cloud infrastructure provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your cloud environment.
narrative = Monitoring your cloud infrastructure logs allows you enable governance, compliance, and risk auditing. It is crucial for a company to monitor events and actions taken in the their cloud environments to ensure that your instances are not vulnerable to attacks. This Analytic Story identifies suspicious activities in your cloud compute instances and helps you respond and investigate those activities.
@@ -154,7 +154,7 @@ version = 1
references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf", "https://redlock.io/blog/cryptojacking-tesla"]
maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}]
spec_version = 3
searches = ["ESCU - Abnormally High Number Of Cloud Infrastructure API Calls - Rule", "ESCU - Cloud API Calls From Previously Unseen User Roles - Rule", "ESCU - Abnormally High Number Of Cloud Security Group API Calls - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task"]
searches = ["ESCU - AWS IAM AccessDenied Discovery Events - Rule", "ESCU - Abnormally High Number Of Cloud Infrastructure API Calls - Rule", "ESCU - Cloud API Calls From Previously Unseen User Roles - Rule", "ESCU - Abnormally High Number Of Cloud Security Group API Calls - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task"]
description = Detect and investigate suspicious activities by users and roles in your cloud environments.
narrative = It seems obvious that it is critical to monitor and control the users who have access to your cloud infrastructure. Nevertheless, it's all too common for enterprises to lose track of ad-hoc accounts, leaving their servers vulnerable to attack. In fact, this was the very oversight that led to Tesla's cryptojacking attack in February, 2018.\
In addition to compromising the security of your data, when bad actors leverage your compute resources, it can incur monumental costs, since you will be billed for any new instances and increased bandwidth usage.
@@ -223,6 +223,66 @@ annotations = {"mitre_attack": ["T1486"]}
known_false_positives = bucket with S3 encryption
providing_technologies = []
[savedsearch://ESCU - AWS Excessive Security Scanning - Rule]
type = detection
asset_type = AWS Account
confidence = medium
explanation = This search looks for CloudTrail events and analyse the amount of eventNames which starts with Describe by a single user. This indicates that this user scans the configuration of your AWS cloud environment.
how_to_implement = You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs.
annotations = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1526"], "nist": ["PR.DS", "PR.AC", "DE.CM"]}
known_false_positives = While this search has no known false positives.
providing_technologies = []
[savedsearch://ESCU - AWS IAM AccessDenied Discovery Events - Rule]
type = detection
asset_type =
confidence = medium
explanation = The following detection identifies excessive AccessDenied events within an hour timeframe. It is possible that an access key to AWS may have been stolen and is being misused to perform discovery events. In these instances, the access is not available with the key stolen therefore these events will be generated.
how_to_implement = The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs.
annotations = {"kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1580"]}
known_false_positives = It is possible to start this detection will need to be tuned by source IP or user. In addition, change the count values to an upper threshold to restrict false positives.
providing_technologies = []
[savedsearch://ESCU - AWS IAM Assume Role Policy Brute Force - Rule]
type = detection
asset_type =
confidence = medium
explanation = The following detection identifies any malformed policy document exceptions with a status of `failure`. A malformed policy document exception occurs in instances where roles are attempted to be assumed, or brute forced. In a brute force attempt, using a tool like CloudSploit or Pacu, an attempt will look like `arn:aws:iam::111111111111:role/aws-service-role/rds.amazonaws.com/AWSServiceRoleForRDS`. Meaning, when an adversary is attempting to identify a role name, multiple failures will occur. This detection focuses on the errors of a remote attempt that is failing.
how_to_implement = The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs. Set the `where count` greater than a value to identify suspicious activity in your environment.
annotations = {"kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1580", "T1110"]}
known_false_positives = This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users.
providing_technologies = []
[savedsearch://ESCU - AWS IAM Delete Policy - Rule]
type = detection
asset_type =
confidence = medium
explanation = The following detection identifes when a policy is deleted on AWS. This does not identify whether successful or failed, but the error messages tell a story of suspicious attempts. There is a specific process to follow when deleting a policy. First, detach the policy from all users, groups, and roles that the policy is attached to, using DetachUserPolicy , DetachGroupPolicy , or DetachRolePolicy.
how_to_implement = The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs.
annotations = {"kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1098"]}
known_false_positives = This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users. Not every user with AWS access should have permission to delete policies (least privilege). In addition, this may be saved seperately and tuned for failed or success attempts only.
providing_technologies = []
[savedsearch://ESCU - AWS IAM Failure Group Deletion - Rule]
type = detection
asset_type =
confidence = medium
explanation = This detection identifies failure attempts to delete groups. We want to identify when a group is attempting to be deleted, but either access is denied, there is a conflict or there is no group. This is indicative of administrators performing an action, but also could be suspicious behavior occurring. Review parallel IAM events - recently added users, new groups and so forth.
how_to_implement = The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs.
annotations = {"kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1098"]}
known_false_positives = This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users. Not every user with AWS access should have permission to delete groups (least privilege).
providing_technologies = []
[savedsearch://ESCU - AWS IAM Successful Group Deletion - Rule]
type = detection
asset_type =
confidence = medium
explanation = The following query uses IAM events to track the success of a group being deleted on AWS. This is typically not indicative of malicious behavior, but a precurser to additional events thay may unfold. Review parallel IAM events - recently added users, new groups and so forth. Inversely, review failed attempts in a similar manner.
how_to_implement = The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs.
annotations = {"kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1069.003", "T1098"]}
known_false_positives = This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users. Not every user with AWS access should have permission to delete groups (least privilege).
providing_technologies = []
[savedsearch://ESCU - AWS Network Access Control List Created with All Open Ports - Rule]
type = detection
asset_type = AWS Instance
+139 -241
View File
@@ -1,107 +1,5 @@
mitre_id,technique,tactics,groups
T1484.002,Domain Trust Modification,Defense Evasion|Privilege Escalation,UNC2452
T1484.001,Group Policy Modification,Defense Evasion|Privilege Escalation,no
T1606.002,SAML Tokens,Credential Access,UNC2452
T1606.001,Web Cookies,Credential Access,UNC2452
T1606,Forge Web Credentials,Credential Access,no
T1059.008,Network Device CLI,Execution,no
T1602.002,Network Device Configuration Dump,Collection,no
T1542.005,TFTP Boot,Defense Evasion|Persistence,no
T1542.004,ROMMONkit,Defense Evasion|Persistence,no
T1602.001,SNMP (MIB Dump),Collection,no
T1602,Data from Configuration Repository,Collection,no
T1601.002,Downgrade System Image,Defense Evasion,no
T1601.001,Patch System Image,Defense Evasion,no
T1601,Modify System Image,Defense Evasion,no
T1600.002,Disable Crypto Hardware,Defense Evasion,no
T1600.001,Reduce Key Space,Defense Evasion,no
T1600,Weaken Encryption,Defense Evasion,no
T1556.004,Network Device Authentication,Credential Access|Defense Evasion,no
T1599.001,Network Address Translation Traversal,Defense Evasion,no
T1599,Network Boundary Bridging,Defense Evasion,no
T1020.001,Traffic Duplication,Exfiltration,no
T1557.002,ARP Cache Poisoning,Credential Access|Collection,Cleaver
T1588.006,Vulnerabilities,Resource Development,no
T1053.006,Systemd Timers,Execution|Persistence|Privilege Escalation,no
T1562.008,Disable Cloud Logs,Defense Evasion,no
T1547.012,Print Processors,Persistence|Privilege Escalation,no
T1598.003,Spearphishing Link,Reconnaissance,no
T1598.002,Spearphishing Attachment,Reconnaissance,no
T1598.001,Spearphishing Service,Reconnaissance,no
T1598,Phishing for Information,Reconnaissance,no
T1597.002,Purchase Technical Data,Reconnaissance,no
T1597.001,Threat Intel Vendors,Reconnaissance,no
T1597,Search Closed Sources,Reconnaissance,no
T1596.005,Scan Databases,Reconnaissance,no
T1596.004,CDNs,Reconnaissance,no
T1596.003,Digital Certificates,Reconnaissance,no
T1596.001,DNS/Passive DNS,Reconnaissance,no
T1596.002,WHOIS,Reconnaissance,no
T1596,Search Open Technical Databases,Reconnaissance,no
T1595.002,Vulnerability Scanning,Reconnaissance,no
T1595.001,Scanning IP Blocks,Reconnaissance,no
T1595,Active Scanning,Reconnaissance,no
T1594,Search Victim-Owned Websites,Reconnaissance,no
T1593.002,Search Engines,Reconnaissance,no
T1593.001,Social Media,Reconnaissance,no
T1593,Search Open Websites/Domains,Reconnaissance,no
T1592.004,Client Configurations,Reconnaissance,no
T1592.003,Firmware,Reconnaissance,no
T1592.002,Software,Reconnaissance,no
T1592.001,Hardware,Reconnaissance,no
T1592,Gather Victim Host Information,Reconnaissance,no
T1591.004,Identify Roles,Reconnaissance,no
T1591.003,Identify Business Tempo,Reconnaissance,no
T1591.001,Determine Physical Locations,Reconnaissance,no
T1591.002,Business Relationships,Reconnaissance,no
T1591,Gather Victim Org Information,Reconnaissance,no
T1590.006,Network Security Appliances,Reconnaissance,no
T1590.005,IP Addresses,Reconnaissance,no
T1590.004,Network Topology,Reconnaissance,no
T1590.003,Network Trust Dependencies,Reconnaissance,no
T1590.002,DNS,Reconnaissance,no
T1590.001,Domain Properties,Reconnaissance,no
T1590,Gather Victim Network Information,Reconnaissance,no
T1589.003,Employee Names,Reconnaissance,no
T1589.002,Email Addresses,Reconnaissance,no
T1589.001,Credentials,Reconnaissance,no
T1589,Gather Victim Identity Information,Reconnaissance,no
T1588.005,Exploits,Resource Development,no
T1588.004,Digital Certificates,Resource Development,no
T1588.003,Code Signing Certificates,Resource Development,Wizard Spider
T1588.002,Tool,Resource Development,no
T1588.001,Malware,Resource Development,Turla|APT1
T1588,Obtain Capabilities,Resource Development,no
T1587.004,Exploits,Resource Development,no
T1587.003,Digital Certificates,Resource Development,APT29|PROMETHIUM
T1587.002,Code Signing Certificates,Resource Development,PROMETHIUM|Patchwork
T1587.001,Malware,Resource Development,UNC2452|Turla|FIN7|Night Dragon|Cleaver
T1587,Develop Capabilities,Resource Development,no
T1586.002,Email Accounts,Resource Development,no
T1586.001,Social Media Accounts,Resource Development,no
T1586,Compromise Accounts,Resource Development,no
T1585.002,Email Accounts,Resource Development,APT1
T1585.001,Social Media Accounts,Resource Development,Cleaver
T1585,Establish Accounts,Resource Development,APT17
T1584.006,Web Services,Resource Development,Turla
T1584.005,Botnet,Resource Development,no
T1584.004,Server,Resource Development,Turla|APT16
T1584.003,Virtual Private Server,Resource Development,Turla
T1584.002,DNS Server,Resource Development,no
T1584.001,Domains,Resource Development,APT1
T1583.006,Web Services,Resource Development,APT17|APT29
T1583.005,Botnet,Resource Development,no
T1583.004,Server,Resource Development,no
T1583.003,Virtual Private Server,Resource Development,TEMP.Veles
T1583.002,DNS Server,Resource Development,no
T1584,Compromise Infrastructure,Resource Development,no
T1583.001,Domains,Resource Development,APT1|APT28
T1583,Acquire Infrastructure,Resource Development,no
T1564.007,VBA Stomping,Defense Evasion,no
T1558.004,AS-REP Roasting,Credential Access,no
T1580,Cloud Infrastructure Discovery,Discovery,no
T1218.012,Verclsid,Defense Evasion,no
T1205.001,Port Knocking,Defense Evasion|Persistence|Command And Control,PROMETHIUM
T1205.001,Port Knocking,Defense Evasion|Persistence|Command And Control,no
T1564.006,Run Virtual Instance,Defense Evasion,no
T1564.005,Hidden File System,Defense Evasion,Strider|Equation
T1556.003,Pluggable Authentication Modules,Credential Access|Defense Evasion,no
@@ -109,7 +7,7 @@ T1574.012,COR_PROFILER,Persistence|Privilege Escalation|Defense Evasion,Blue Moc
T1562.007,Disable or Modify Cloud Firewall,Defense Evasion,no
T1098.004,SSH Authorized Keys,Persistence,no
T1480.001,Environmental Keying,Defense Evasion,APT41|Equation
T1059.007,JavaScript/JScript,Execution,FIN6|APT32|FIN7|Cobalt Group|Molerats|TA505|Silence|Leafminer
T1059.007,JavaScript/JScript,Execution,APT32|FIN7|Cobalt Group|Molerats|TA505|Silence|Leafminer
T1578.004,Revert Cloud Instance,Defense Evasion,no
T1578.003,Delete Cloud Instance,Defense Evasion,no
T1578.001,Create Snapshot,Defense Evasion,no
@@ -126,31 +24,31 @@ T1546.015,Component Object Model Hijacking,Privilege Escalation|Persistence,APT2
T1071.004,DNS,Command And Control,APT39|Tropic Trooper|OilRig|Ke3chang|Cobalt Group|APT18|APT41|FIN7
T1071.003,Mail Protocols,Command And Control,APT32|SilverTerrier|APT28
T1071.002,File Transfer Protocols,Command And Control,APT41|SilverTerrier|Machete|Honeybee
T1071.001,Web Protocols,Command And Control,UNC2452|Sandworm Team|TA505|Rocke|APT39|Tropic Trooper|MuddyWater|Wizard Spider|Inception|APT41|SilverTerrier|Machete|APT28|WIRTE|APT33|FIN4|Night Dragon|APT18|APT38|Threat Group-3390|Ke3chang|Dark Caracal|APT19|Cobalt Group|Rancor|Orangeworm|APT37|Turla|Lazarus Group|APT32|Magic Hound|BRONZE BUTLER|OilRig|Gamaredon Group|Stealth Falcon
T1071.001,Web Protocols,Command And Control,Sandworm Team|TA505|Rocke|APT39|Tropic Trooper|MuddyWater|Wizard Spider|Inception|APT41|SilverTerrier|Machete|APT28|WIRTE|APT33|FIN4|Night Dragon|APT18|APT38|Cobalt Group|APT19|Threat Group-3390|Rancor|Orangeworm|APT37|Ke3chang|Dark Caracal|Turla|Lazarus Group|BRONZE BUTLER|APT32|OilRig|Magic Hound|Gamaredon Group|Stealth Falcon
T1572,Protocol Tunneling,Command And Control,OilRig|Cobalt Group|FIN6
T1048.003,Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol,Exfiltration,Wizard Spider|FIN6|APT32|APT33|Thrip|FIN8|OilRig|Lazarus Group
T1048.002,Exfiltration Over Asymmetric Encrypted Non-C2 Protocol,Exfiltration,UNC2452
T1048.003,Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol,Exfiltration,APT32|APT33|Thrip|FIN8|OilRig|Lazarus Group
T1048.002,Exfiltration Over Asymmetric Encrypted Non-C2 Protocol,Exfiltration,no
T1048.001,Exfiltration Over Symmetric Encrypted Non-C2 Protocol,Exfiltration,no
T1001.003,Protocol Impersonation,Command And Control,Lazarus Group
T1001.002,Steganography,Command And Control,APT29|Axiom
T1001.002,Steganography,Command And Control,Axiom
T1001.001,Junk Data,Command And Control,APT28
T1132.002,Non-Standard Encoding,Command And Control,no
T1132.001,Standard Encoding,Command And Control,Sandworm Team|Tropic Trooper|MuddyWater|APT33|APT19|Lazarus Group|BRONZE BUTLER|Patchwork
T1090.004,Domain Fronting,Command And Control,APT29
T1090.003,Multi-hop Proxy,Command And Control,Inception|FIN4|APT29
T1090.002,External Proxy,Command And Control,APT39|Silence|Soft Cell|MuddyWater|APT3|FIN5|Lazarus Group|menuPass|APT28
T1090.001,Internal Proxy,Command And Control,UNC2452|APT39|Strider
T1090.001,Internal Proxy,Command And Control,APT39|Strider
T1102.003,One-Way Communication,Command And Control,Leviathan
T1102.002,Bidirectional Communication,Command And Control,APT29|Sandworm Team|APT39|APT12|Turla|FIN7|APT37|Magic Hound|Carbanak
T1102.002,Bidirectional Communication,Command And Control,Sandworm Team|APT39|APT12|Turla|FIN7|APT37|Magic Hound|Carbanak
T1102.001,Dead Drop Resolver,Command And Control,Rocke|APT41|BRONZE BUTLER|RTM|Patchwork
T1571,Non-Standard Port,Command And Control,Sandworm Team|Rocke|DarkVishnya|Silence|APT-C-36|Magic Hound|APT33|APT32|TEMP.Veles|Lazarus Group|FIN7
T1074.002,Remote Data Staging,Collection,UNC2452|Threat Group-3390|menuPass|FIN6|Night Dragon|FIN8
T1074.001,Local Data Staging,Collection,Machete|Soft Cell|TEMP.Veles|Honeybee|Dragonfly 2.0|Patchwork|Leviathan|APT3|FIN5|menuPass|Lazarus Group|Threat Group-3390|APT28
T1074.002,Remote Data Staging,Collection,Threat Group-3390|menuPass|FIN6|Night Dragon|FIN8
T1074.001,Local Data Staging,Collection,Machete|Soft Cell|TEMP.Veles|Patchwork|Dragonfly 2.0|Honeybee|Leviathan|APT3|FIN5|menuPass|FIN6|Lazarus Group|Threat Group-3390|APT28
T1078.004,Cloud Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,APT33
T1564.004,NTFS File Attributes,Defense Evasion,APT32
T1564.003,Hidden Window,Defense Evasion,Gorgon Group|Deep Panda|DarkHydrus|CopyKittens|APT19|APT32|APT28|APT3|Magic Hound
T1078.003,Local Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,PROMETHIUM|Tropic Trooper|FIN10|Stolen Pencil|APT32
T1078.002,Domain Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,Wizard Spider|APT29|TA505|APT3|Threat Group-1314
T1078.003,Local Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,Tropic Trooper|FIN10|Stolen Pencil|APT32
T1078.002,Domain Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,TA505|APT3|Threat Group-1314
T1078.001,Default Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,no
T1564.002,Hidden Users,Defense Evasion,no
T1574.006,LD_PRELOAD,Persistence|Privilege Escalation|Defense Evasion,Rocke
@@ -166,37 +64,37 @@ T1574,Hijack Execution Flow,Persistence|Privilege Escalation|Defense Evasion,no
T1069.001,Local Groups,Discovery,Turla|OilRig|admin@338
T1570,Lateral Tool Transfer,Lateral Movement,APT32|Wizard Spider|Turla|FIN10
T1568.003,DNS Calculation,Command And Control,APT12
T1204.002,Malicious File,Execution,FIN6|PROMETHIUM|APT30|Magic Hound|Windshift|APT33|Sandworm Team|Naikon|Whitefly|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Wizard Spider|Mofang|Frankenstein|RTM|Inception|BlackTech|APT-C-36|Machete|admin@338|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Dragonfly 2.0|Dark Caracal|FIN7|APT32|Cobalt Group|DarkHydrus|Patchwork|Rancor|MuddyWater|BRONZE BUTLER|APT19|Gorgon Group|OilRig|Lazarus Group|APT29|menuPass|TA459|FIN8|Elderwood|PLATINUM|Leviathan|APT37|APT28
T1204.001,Malicious Link,Execution,Wizard Spider|Patchwork|Windshift|APT32|Molerats|Mofang|BlackTech|TA505|OilRig|Machete|Leviathan|FIN8|FIN4|Elderwood|Dragonfly 2.0|Cobalt Group|APT39|Night Dragon|APT33|Turla
T1204.002,Malicious File,Execution,Magic Hound|Windshift|APT33|Sandworm Team|Naikon|Whitefly|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Wizard Spider|Mofang|Frankenstein|RTM|Inception|BlackTech|APT-C-36|Machete|admin@338|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|APT19|Dragonfly 2.0|BRONZE BUTLER|Cobalt Group|DarkHydrus|Gorgon Group|Patchwork|OilRig|Dark Caracal|MuddyWater|Lazarus Group|FIN7|APT32|Rancor|APT37|FIN8|APT28|Elderwood|TA459|APT29|Leviathan|menuPass|PLATINUM
T1204.001,Malicious Link,Execution,Patchwork|Windshift|APT32|Molerats|Mofang|BlackTech|TA505|OilRig|Machete|Leviathan|FIN8|FIN4|Elderwood|Dragonfly 2.0|Cobalt Group|APT39|Night Dragon|APT33|Turla
T1195.003,Compromise Hardware Supply Chain,Initial Access,no
T1195.002,Compromise Software Supply Chain,Initial Access,UNC2452|GOLD SOUTHFIELD|Dragonfly|Sandworm Team|APT41
T1195.002,Compromise Software Supply Chain,Initial Access,Sandworm Team|APT41
T1195.001,Compromise Software Dependencies and Development Tools,Initial Access,no
T1568.001,Fast Flux DNS,Command And Control,Machete|TA505
T1568.001,Fast Flux DNS,Command And Control,TA505
T1052.001,Exfiltration over USB,Exfiltration,Tropic Trooper
T1569.002,Service Execution,Execution,Wizard Spider|Blue Mockingbird|APT39|APT41|Silence|FIN6|APT32|Ke3chang|Honeybee
T1569.002,Service Execution,Execution,Blue Mockingbird|APT39|APT41|Silence|FIN6|APT32|Honeybee|Ke3chang
T1569.001,Launchctl,Execution,no
T1569,System Services,Execution,no
T1568.002,Domain Generation Algorithms,Command And Control,APT41
T1568,Dynamic Resolution,Command And Control,UNC2452
T1568,Dynamic Resolution,Command And Control,no
T1011.001,Exfiltration Over Bluetooth,Exfiltration,no
T1567.002,Exfiltration to Cloud Storage,Exfiltration,Leviathan|Turla
T1567.001,Exfiltration to Code Repository,Exfiltration,no
T1059.006,Python,Execution,APT29|Rocke|BRONZE BUTLER|APT39|Dragonfly 2.0|Machete
T1059.005,Visual Basic,Execution,Lazarus Group|APT33|Sandworm Team|Gamaredon Group|Sharpshooter|Molerats|Frankenstein|Inception|APT-C-36|Rancor|Patchwork|MuddyWater|Honeybee|FIN7|APT37|BRONZE BUTLER|APT32|Turla|TA505|Silence|WIRTE|FIN4|Gorgon Group|Cobalt Group|Leviathan|TA459|Magic Hound
T1059.006,Python,Execution,Rocke|BRONZE BUTLER|APT39|Dragonfly 2.0|Machete
T1059.005,Visual Basic,Execution,APT33|Sandworm Team|Gamaredon Group|Sharpshooter|Molerats|Frankenstein|Inception|APT-C-36|Rancor|Patchwork|MuddyWater|Honeybee|FIN7|APT37|BRONZE BUTLER|APT32|Turla|TA505|Silence|WIRTE|FIN4|Cobalt Group|Gorgon Group|Leviathan|TA459|Magic Hound
T1059.004,Unix Shell,Execution,Rocke|APT41
T1059.003,Windows Command Shell,Execution,UNC2452|Wizard Spider|FIN6|TA505|Blue Mockingbird|Tropic Trooper|Frankenstein|OilRig|Lazarus Group|Honeybee|Cobalt Group|FIN7|APT41|Soft Cell|Turla|Silence|APT32|Darkhotel|MuddyWater|APT18|APT38|Gorgon Group|Ke3chang|Dragonfly 2.0|Rancor|Dark Caracal|APT37|APT28|Leviathan|FIN8|Sowbug|Magic Hound|BRONZE BUTLER|menuPass|Threat Group-3390|FIN10|Gamaredon Group|Patchwork|Suckfly|Threat Group-1314|APT3|admin@338|APT1
T1059.003,Windows Command Shell,Execution,TA505|Blue Mockingbird|Tropic Trooper|Frankenstein|OilRig|Lazarus Group|Honeybee|Cobalt Group|FIN7|APT41|Soft Cell|Turla|Silence|APT32|APT39|Darkhotel|MuddyWater|APT18|APT38|Dark Caracal|Gorgon Group|Dragonfly 2.0|Rancor|Ke3chang|APT37|Leviathan|FIN8|APT28|Magic Hound|Sowbug|BRONZE BUTLER|FIN10|Threat Group-3390|menuPass|Gamaredon Group|Suckfly|Patchwork|Threat Group-1314|APT3|admin@338|APT1
T1059.002,AppleScript,Execution,no
T1059.001,PowerShell,Execution,UNC2452|Lazarus Group|Chimera|Blue Mockingbird|APT39|DarkVishnya|Molerats|Wizard Spider|Frankenstein|Inception|Silence|APT41|Kimsuky|Soft Cell|TA505|WIRTE|TEMP.Veles|APT33|Gallmaker|Turla|APT19|DarkHydrus|APT28|Gorgon Group|Thrip|Cobalt Group|Dragonfly 2.0|Leviathan|TA459|MuddyWater|FIN8|Magic Hound|CopyKittens|BRONZE BUTLER|OilRig|FIN10|Threat Group-3390|APT32|FIN7|menuPass|Patchwork|Stealth Falcon|FIN6|Poseidon Group|APT3|APT29|Deep Panda
T1059.001,PowerShell,Execution,Blue Mockingbird|APT39|DarkVishnya|Molerats|Wizard Spider|Frankenstein|Inception|Silence|APT41|Kimsuky|Soft Cell|TA505|WIRTE|TEMP.Veles|APT33|Gallmaker|Turla|APT19|DarkHydrus|APT28|Thrip|Gorgon Group|Cobalt Group|Dragonfly 2.0|Leviathan|TA459|FIN8|MuddyWater|Magic Hound|OilRig|BRONZE BUTLER|CopyKittens|APT32|FIN7|FIN10|Threat Group-3390|menuPass|Patchwork|Stealth Falcon|FIN6|Poseidon Group|APT3|APT29|Deep Panda
T1567,Exfiltration Over Web Service,Exfiltration,no
T1497.003,Time Based Evasion,Defense Evasion|Discovery,no
T1497.002,User Activity Based Checks,Defense Evasion|Discovery,FIN7
T1497.001,System Checks,Defense Evasion|Discovery,Frankenstein
T1498.002,Reflection Amplification,Impact,no
T1498.001,Direct Network Flood,Impact,no
T1566.003,Spearphishing via Service,Initial Access,Lazarus Group|Magic Hound|Windshift|FIN6|OilRig|Dark Caracal
T1566.002,Spearphishing Link,Initial Access,Wizard Spider|APT1|Windshift|Molerats|Mofang|BlackTech|Machete|Kimsuky|TA505|Stolen Pencil|APT39|FIN4|APT32|Night Dragon|APT28|Cobalt Group|Dragonfly 2.0|Turla|OilRig|APT33|Leviathan|Patchwork|Elderwood|APT29|Magic Hound|FIN8
T1566.001,Spearphishing Attachment,Initial Access,APT1|FIN6|APT30|Magic Hound|Windshift|APT33|Sandworm Team|Naikon|Gamaredon Group|Sharpshooter|Molerats|Mofang|Wizard Spider|RTM|Frankenstein|Inception|BlackTech|APT-C-36|APT41|Machete|admin@338|Kimsuky|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Tropic Trooper|Turla|Lazarus Group|Cobalt Group|FIN7|OilRig|BRONZE BUTLER|APT32|Gorgon Group|Rancor|DarkHydrus|APT19|Dragonfly 2.0|FIN8|PLATINUM|MuddyWater|TA459|Leviathan|Elderwood|APT29|APT37|menuPass|APT28|Patchwork
T1566,Phishing,Initial Access,GOLD SOUTHFIELD|Dragonfly
T1566.003,Spearphishing via Service,Initial Access,Magic Hound|Windshift|FIN6|OilRig|Dark Caracal
T1566.002,Spearphishing Link,Initial Access,Windshift|Molerats|Mofang|BlackTech|Machete|Kimsuky|TA505|Stolen Pencil|APT39|FIN4|APT32|Night Dragon|Turla|APT28|Cobalt Group|Dragonfly 2.0|OilRig|APT33|Elderwood|Leviathan|Magic Hound|Patchwork|APT29|FIN8
T1566.001,Spearphishing Attachment,Initial Access,Magic Hound|Windshift|APT33|Sandworm Team|Naikon|Gamaredon Group|Sharpshooter|Molerats|Mofang|Wizard Spider|RTM|Frankenstein|Inception|BlackTech|APT-C-36|APT41|Machete|admin@338|Kimsuky|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Tropic Trooper|Turla|Gorgon Group|Rancor|DarkHydrus|Cobalt Group|FIN7|OilRig|Lazarus Group|APT19|Dragonfly 2.0|BRONZE BUTLER|APT32|FIN8|MuddyWater|APT28|TA459|Leviathan|Patchwork|PLATINUM|Elderwood|APT29|APT37|menuPass
T1566,Phishing,Initial Access,no
T1565.003,Runtime Data Manipulation,Impact,APT38
T1565.002,Transmitted Data Manipulation,Impact,APT38
T1565.001,Stored Data Manipulation,Impact,FIN4|APT38
@@ -206,18 +104,18 @@ T1564,Hide Artifacts,Defense Evasion,no
T1563.002,RDP Hijacking,Lateral Movement,no
T1563.001,SSH Hijacking,Lateral Movement,no
T1563,Remote Service Session Hijacking,Lateral Movement,no
T1518.001,Security Software Discovery,Discovery,Wizard Spider|Turla|Rocke|Frankenstein|The White Company|Cobalt Group|Darkhotel|MuddyWater|Tropic Trooper|FIN8|Patchwork|Naikon
T1518.001,Security Software Discovery,Discovery,Turla|Rocke|Frankenstein|The White Company|Cobalt Group|Darkhotel|MuddyWater|Tropic Trooper|FIN8|Patchwork|Naikon
T1069.003,Cloud Groups,Discovery,no
T1069.002,Domain Groups,Discovery,Turla|Wizard Spider|Inception|OilRig|FIN6|Dragonfly 2.0|Ke3chang
T1087.004,Cloud Account,Discovery,no
T1087.003,Email Account,Discovery,Sandworm Team|TA505
T1087.002,Domain Account,Discovery,Wizard Spider|Chimera|Turla|Sandworm Team|Dragonfly 2.0|OilRig|BRONZE BUTLER|menuPass|FIN6|Poseidon Group|Ke3chang
T1087.002,Domain Account,Discovery,Turla|Sandworm Team|Dragonfly 2.0|OilRig|BRONZE BUTLER|menuPass|FIN6|Poseidon Group|Ke3chang
T1087.001,Local Account,Discovery,Turla|Poseidon Group|OilRig|Ke3chang|APT32|APT1|Threat Group-3390|APT3|admin@338
T1553.004,Install Root Certificate,Defense Evasion,no
T1562.004,Disable or Modify System Firewall,Defense Evasion,UNC2452|Rocke|Lazarus Group|Kimsuky|Dragonfly 2.0|Carbanak
T1562.003,Impair Command History Logging,Defense Evasion,no
T1562.002,Disable Windows Event Logging,Defense Evasion,UNC2452|Threat Group-3390
T1562.001,Disable or Modify Tools,Defense Evasion,UNC2452|Wizard Spider|FIN6|Gamaredon Group|BRONZE BUTLER|Rocke|Kimsuky|Turla|Night Dragon|Gorgon Group|Lazarus Group|Putter Panda
T1562.004,Disable or Modify System Firewall,Defense Evasion,Rocke|Lazarus Group|Kimsuky|Dragonfly 2.0|Carbanak
T1562.003,HISTCONTROL,Defense Evasion,no
T1562.002,Disable Windows Event Logging,Defense Evasion,Threat Group-3390
T1562.001,Disable or Modify Tools,Defense Evasion,Gamaredon Group|BRONZE BUTLER|Rocke|Kimsuky|Turla|Night Dragon|Gorgon Group|Lazarus Group|Putter Panda
T1562,Impair Defenses,Defense Evasion,no
T1003.004,LSA Secrets,Credential Access,OilRig|MuddyWater|menuPass|Leafminer|Ke3chang|Dragonfly 2.0|APT33|Threat Group-3390
T1003.005,Cached Domain Credentials,Credential Access,OilRig|MuddyWater|Leafminer|APT33
@@ -226,8 +124,8 @@ T1561.001,Disk Content Wipe,Impact,Lazarus Group
T1561,Disk Wipe,Impact,no
T1560.003,Archive via Custom Method,Collection,Lazarus Group|Kimsuky|CopyKittens|FIN6
T1560.002,Archive via Library,Collection,Lazarus Group|Threat Group-3390
T1560.001,Archive via Utility,Collection,UNC2452|Chimera|APT41|Soft Cell|Turla|Gallmaker|APT33|APT39|MuddyWater|Magic Hound|FIN8|BRONZE BUTLER|CopyKittens|Sowbug|APT3|menuPass|APT1|Ke3chang
T1560,Archive Collected Data,Collection,menuPass|APT32|Patchwork|APT28|Dragonfly 2.0|Honeybee|FIN6|Lazarus Group|Ke3chang
T1560.001,Archive via Utility,Collection,APT41|Soft Cell|Turla|Gallmaker|APT33|APT39|MuddyWater|Magic Hound|FIN8|BRONZE BUTLER|CopyKittens|APT3|Sowbug|menuPass|APT1|Ke3chang
T1560,Archive Collected Data,Collection,menuPass|APT32|Honeybee|Patchwork|APT28|Dragonfly 2.0|FIN6|Lazarus Group|Ke3chang
T1499.004,Application or System Exploitation,Impact,no
T1499.003,Application Exhaustion Flood,Impact,no
T1499.002,Service Exhaustion Flood,Impact,no
@@ -235,7 +133,7 @@ T1499.001,OS Exhaustion Flood,Impact,no
T1491.002,External Defacement,Impact,no
T1491.001,Internal Defacement,Impact,Lazarus Group
T1114.003,Email Forwarding Rule,Collection,no
T1114.002,Remote Email Collection,Collection,UNC2452|APT1|FIN4|Ke3chang|Leafminer|Dragonfly 2.0|APT28
T1114.002,Remote Email Collection,Collection,APT1|FIN4|APT28|Dragonfly 2.0|Ke3chang|Leafminer
T1114.001,Local Email Collection,Collection,Magic Hound|APT1
T1134.005,SID-History Injection,Defense Evasion|Privilege Escalation,no
T1134.004,Parent PID Spoofing,Defense Evasion|Privilege Escalation,no
@@ -244,93 +142,93 @@ T1134.002,Create Process with Token,Defense Evasion|Privilege Escalation,Turla|L
T1134.001,Token Impersonation/Theft,Defense Evasion|Privilege Escalation,APT28
T1213.002,Sharepoint,Collection,Ke3chang|APT28
T1213.001,Confluence,Collection,no
T1555.003,Credentials from Web Browsers,Credential Access,FIN6|Magic Hound|Sandworm Team|Inception|Stealth Falcon|OilRig|Leafminer|APT33|APT3|Kimsuky|TA505|Stolen Pencil|MuddyWater|APT37|Patchwork|Molerats
T1555.003,Credentials from Web Browsers,Credential Access,Magic Hound|Sandworm Team|Inception|Stealth Falcon|OilRig|Leafminer|APT33|APT3|Kimsuky|TA505|Stolen Pencil|MuddyWater|APT37|Patchwork|Molerats
T1555.002,Securityd Memory,Credential Access,no
T1555.001,Keychain,Credential Access,no
T1559.002,Dynamic Data Exchange,Execution,Sharpshooter|TA505|MuddyWater|Gallmaker|Cobalt Group|Patchwork|APT37|FIN7|APT28
T1559.002,Dynamic Data Exchange,Execution,Sharpshooter|TA505|MuddyWater|Gallmaker|Patchwork|Cobalt Group|APT37|APT28|FIN7
T1559.001,Component Object Model,Execution,Gamaredon Group|MuddyWater
T1559,Inter-Process Communication,Execution,no
T1558.002,Silver Ticket,Credential Access,no
T1558.001,Golden Ticket,Credential Access,Ke3chang
T1558,Steal or Forge Kerberos Tickets,Credential Access,no
T1557.001,LLMNR/NBT-NS Poisoning and SMB Relay,Credential Access|Collection,Wizard Spider
T1557.001,LLMNR/NBT-NS Poisoning and SMB Relay,Credential Access|Collection,no
T1557,Man-in-the-Middle,Credential Access|Collection,no
T1556.002,Password Filter DLL,Credential Access|Defense Evasion,Strider
T1556.001,Domain Controller Authentication,Credential Access|Defense Evasion,Chimera
T1556.001,Domain Controller Authentication,Credential Access|Defense Evasion,no
T1556,Modify Authentication Process,Credential Access|Defense Evasion,no
T1056.004,Credential API Hooking,Collection|Credential Access,PLATINUM
T1056.003,Web Portal Capture,Collection|Credential Access,no
T1056.002,GUI Input Capture,Collection|Credential Access,FIN4
T1056.001,Keylogging,Collection|Credential Access,APT32|Sandworm Team|APT39|APT41|Kimsuky|menuPass|Stolen Pencil|FIN4|APT38|OilRig|Ke3chang|PLATINUM|Sowbug|Magic Hound|Group5|Lazarus Group|Threat Group-3390|APT3|Darkhotel|APT28
T1555,Credentials from Password Stores,Credential Access,UNC2452|FIN6|APT39|OilRig|MuddyWater|Leafminer|APT33|Turla|Stealth Falcon
T1056.001,Keylogging,Collection|Credential Access,APT32|Sandworm Team|APT39|APT41|Kimsuky|menuPass|Stolen Pencil|FIN4|APT38|Ke3chang|OilRig|PLATINUM|Sowbug|Magic Hound|Group5|Lazarus Group|Threat Group-3390|APT3|Darkhotel|APT28
T1555,Credentials from Password Stores,Credential Access,APT39|OilRig|MuddyWater|Leafminer|APT33|Turla|Stealth Falcon
T1552.005,Cloud Instance Metadata API,Credential Access,no
T1003.008,/etc/passwd and /etc/shadow,Credential Access,no
T1003.007,Proc Filesystem,Credential Access,no
T1003.006,DCSync,Credential Access,UNC2452
T1558.003,Kerberoasting,Credential Access,UNC2452|Wizard Spider
T1003.006,DCSync,Credential Access,no
T1558.003,Kerberoasting,Credential Access,no
T1552.006,Group Policy Preferences,Credential Access,APT33
T1003.003,NTDS,Credential Access,Wizard Spider|Chimera|FIN6|Dragonfly 2.0
T1003.002,Security Account Manager,Credential Access,Wizard Spider|Threat Group-3390|Ke3chang|Soft Cell|Night Dragon|Dragonfly 2.0|menuPass
T1003.001,LSASS Memory,Credential Access,Sandworm Team|Whitefly|Blue Mockingbird|Silence|Threat Group-3390|Leviathan|APT41|Soft Cell|TEMP.Veles|APT33|APT39|Stolen Pencil|APT32|Leafminer|Lazarus Group|Magic Hound|MuddyWater|FIN8|PLATINUM|OilRig|BRONZE BUTLER|FIN6|APT3|APT28|APT1|Ke3chang|Cleaver
T1003.003,NTDS,Credential Access,FIN6|Dragonfly 2.0
T1003.002,Security Account Manager,Credential Access,Threat Group-3390|Ke3chang|Soft Cell|Night Dragon|Dragonfly 2.0|menuPass
T1003.001,LSASS Memory,Credential Access,Sandworm Team|Whitefly|Blue Mockingbird|Silence|Threat Group-3390|Leviathan|APT41|Soft Cell|TEMP.Veles|APT33|APT39|Stolen Pencil|APT32|Lazarus Group|Leafminer|Magic Hound|MuddyWater|PLATINUM|FIN8|BRONZE BUTLER|OilRig|FIN6|APT3|APT28|APT1|Ke3chang|Cleaver
T1110.004,Credential Stuffing,Credential Access,no
T1110.003,Password Spraying,Credential Access,APT28|APT33|Leafminer|Lazarus Group
T1110.002,Password Cracking,Credential Access,FIN6|APT41|Dragonfly 2.0|APT3
T1110.001,Password Guessing,Credential Access,APT28
T1021.006,Windows Remote Management,Lateral Movement,UNC2452|Wizard Spider|Threat Group-3390
T1110.003,Password Spraying,Credential Access,APT33|Leafminer|Lazarus Group
T1110.002,Password Cracking,Credential Access,APT41|Dragonfly 2.0|APT3
T1110.001,Password Guessing,Credential Access,no
T1021.006,Windows Remote Management,Lateral Movement,Threat Group-3390
T1021.005,VNC,Lateral Movement,GCMAN
T1021.004,SSH,Lateral Movement,Rocke|TEMP.Veles|Leviathan|APT39|OilRig|menuPass|GCMAN
T1021.003,Distributed Component Object Model,Lateral Movement,no
T1021.002,SMB/Windows Admin Shares,Lateral Movement,Wizard Spider|Chimera|Blue Mockingbird|APT39|APT32|Orangeworm|FIN8|APT3|Lazarus Group|Threat Group-1314|Turla|Deep Panda|Ke3chang
T1021.001,Remote Desktop Protocol,Lateral Movement,Chimera|Blue Mockingbird|Wizard Spider|Silence|APT41|TEMP.Veles|Leviathan|APT39|Stolen Pencil|Cobalt Group|Dragonfly 2.0|FIN8|APT3|OilRig|FIN10|menuPass|Patchwork|FIN6|Lazarus Group|APT1|Axiom
T1021.002,SMB/Windows Admin Shares,Lateral Movement,Blue Mockingbird|APT39|APT32|Orangeworm|FIN8|APT3|Lazarus Group|Threat Group-1314|Turla|Deep Panda|Ke3chang
T1021.001,Remote Desktop Protocol,Lateral Movement,Blue Mockingbird|Wizard Spider|Silence|APT41|TEMP.Veles|Leviathan|APT39|Stolen Pencil|Cobalt Group|Dragonfly 2.0|FIN8|APT3|OilRig|menuPass|FIN10|Patchwork|FIN6|Lazarus Group|APT1|Axiom
T1554,Compromise Client Software Binary,Persistence,no
T1036.006,Space after Filename,Defense Evasion,no
T1036.005,Match Legitimate Name or Location,Defense Evasion,UNC2452|Chimera|PROMETHIUM|Rocke|Sandworm Team|APT39|Blue Mockingbird|Whitefly|Tropic Trooper|Silence|APT41|menuPass|TEMP.Veles|MuddyWater|BRONZE BUTLER|Sowbug|APT32|Patchwork|Poseidon Group|admin@338|Carbanak|APT1
T1036.004,Masquerade Task or Service,Defense Evasion,UNC2452|Lazarus Group|PROMETHIUM|Wizard Spider|APT-C-36|Carbanak|APT32|FIN6|FIN7
T1036.005,Match Legitimate Name or Location,Defense Evasion,Rocke|Sandworm Team|APT39|Blue Mockingbird|Whitefly|Tropic Trooper|Silence|APT41|menuPass|TEMP.Veles|MuddyWater|BRONZE BUTLER|Sowbug|APT32|Patchwork|Poseidon Group|admin@338|Carbanak|APT1
T1036.004,Masquerade Task or Service,Defense Evasion,Wizard Spider|APT-C-36|Carbanak|APT32|FIN6|FIN7
T1036.003,Rename System Utilities,Defense Evasion,menuPass|APT32|Soft Cell|PLATINUM
T1036.002,Right-to-Left Override,Defense Evasion,BRONZE BUTLER|BlackTech|Ke3chang|Scarlet Mimic
T1036.001,Invalid Code Signature,Defense Evasion,Windshift|APT37
T1036.001,Invalid Code Signature,Defense Evasion,Windshift
T1553.003,SIP and Trust Provider Hijacking,Defense Evasion,no
T1553.002,Code Signing,Defense Evasion,UNC2452|Wizard Spider|PROMETHIUM|Patchwork|Silence|APT41|FIN6|TA505|FIN7|Honeybee|Leviathan|CopyKittens|Winnti Group|Suckfly|Molerats|Darkhotel
T1553.002,Code Signing,Defense Evasion,Patchwork|Silence|APT41|FIN6|TA505|FIN7|Honeybee|Leviathan|APT37|CopyKittens|Winnti Group|Suckfly|Molerats|Darkhotel
T1553.001,Gatekeeper Bypass,Defense Evasion,no
T1553,Subvert Trust Controls,Defense Evasion,no
T1027.003,Steganography,Defense Evasion,BRONZE BUTLER|Tropic Trooper|MuddyWater|APT37
T1027.002,Software Packing,Defense Evasion,Lazarus Group|TA505|Rocke|Soft Cell|The White Company|APT39|APT38|Dark Caracal|Elderwood|APT3|Patchwork|APT29|Night Dragon
T1027.001,Binary Padding,Defense Evasion,Gamaredon Group|APT32|Patchwork|Leviathan|BRONZE BUTLER|Moafee
T1027.002,Software Packing,Defense Evasion,TA505|Rocke|Soft Cell|The White Company|APT39|APT38|Dark Caracal|Elderwood|APT3|Patchwork|APT29|Night Dragon
T1027.001,Binary Padding,Defense Evasion,Gamaredon Group|Patchwork|APT32|Leviathan|BRONZE BUTLER|Moafee
T1222.002,Linux and Mac File and Directory Permissions Modification,Defense Evasion,Rocke|APT32
T1222.001,Windows File and Directory Permissions Modification,Defense Evasion,Wizard Spider
T1552.004,Private Keys,Credential Access,UNC2452|Rocke
T1222.001,Windows File and Directory Permissions Modification,Defense Evasion,no
T1552.004,Private Keys,Credential Access,Rocke
T1552.003,Bash History,Credential Access,no
T1552.002,Credentials in Registry,Credential Access,APT32
T1552.001,Credentials In Files,Credential Access,Leafminer|APT33|OilRig|TA505|Stolen Pencil|MuddyWater|APT3
T1552,Unsecured Credentials,Credential Access,no
T1216.001,PubPrn,Defense Evasion,APT32
T1070.006,Timestomp,Defense Evasion,UNC2452|Rocke|TEMP.Veles|APT32|Lazarus Group|APT28
T1070.006,Timestomp,Defense Evasion,Rocke|TEMP.Veles|APT32|Lazarus Group|APT28
T1070.005,Network Share Connection Removal,Defense Evasion,Threat Group-3390
T1070.004,File Deletion,Defense Evasion,UNC2452|FIN6|Sandworm Team|Rocke|Tropic Trooper|Gamaredon Group|Wizard Spider|APT41|Kimsuky|Silence|The White Company|TEMP.Veles|APT32|APT38|Honeybee|Patchwork|Cobalt Group|Dragonfly 2.0|menuPass|FIN8|BRONZE BUTLER|FIN5|APT3|OilRig|Magic Hound|FIN10|APT28|Threat Group-3390|Group5|Lazarus Group|APT18|APT29
T1070.004,File Deletion,Defense Evasion,Sandworm Team|Rocke|Tropic Trooper|Gamaredon Group|Wizard Spider|APT41|Kimsuky|Silence|The White Company|TEMP.Veles|APT32|APT38|Patchwork|Honeybee|Cobalt Group|Dragonfly 2.0|menuPass|FIN8|OilRig|FIN5|BRONZE BUTLER|Magic Hound|APT3|FIN10|APT28|Threat Group-3390|Group5|Lazarus Group|APT18|APT29
T1070.003,Clear Command History,Defense Evasion,APT41
T1550.004,Web Session Cookie,Defense Evasion|Lateral Movement,UNC2452
T1550.004,Web Session Cookie,Defense Evasion|Lateral Movement,no
T1550.001,Application Access Token,Defense Evasion|Lateral Movement,APT28
T1550.003,Pass the Ticket,Defense Evasion|Lateral Movement,APT32|BRONZE BUTLER|APT29
T1550.002,Pass the Hash,Defense Evasion|Lateral Movement,Soft Cell|APT32|Night Dragon|APT28|APT1
T1550,Use Alternate Authentication Material,Defense Evasion|Lateral Movement,UNC2452
T1550,Use Alternate Authentication Material,Defense Evasion|Lateral Movement,no
T1548.004,Elevated Execution with Prompt,Privilege Escalation|Defense Evasion,no
T1548.003,Sudo and Sudo Caching,Privilege Escalation|Defense Evasion,no
T1548.002,Bypass User Account Control,Privilege Escalation|Defense Evasion,APT37|MuddyWater|Honeybee|Cobalt Group|Threat Group-3390|BRONZE BUTLER|Patchwork|APT29
T1548.002,Bypass User Access Control,Privilege Escalation|Defense Evasion,APT37|MuddyWater|Honeybee|Cobalt Group|Threat Group-3390|BRONZE BUTLER|Patchwork|APT29
T1548.001,Setuid and Setgid,Privilege Escalation|Defense Evasion,no
T1548,Abuse Elevation Control Mechanism,Privilege Escalation|Defense Evasion,no
T1136.003,Cloud Account,Persistence,no
T1070.002,Clear Linux or Mac System Logs,Defense Evasion,Rocke
T1070.001,Clear Windows Event Logs,Defense Evasion,APT41|APT38|Dragonfly 2.0|APT32|FIN8|FIN5|APT28
T1136.002,Domain Account,Persistence,Soft Cell
T1136.001,Local Account,Persistence,APT39|APT41|Leafminer|Dragonfly 2.0|APT3
T1136.001,Local Account,Persistence,APT39|APT41|Dragonfly 2.0|Leafminer|APT3
T1547.011,Plist Modification,Persistence|Privilege Escalation,no
T1547.010,Port Monitors,Persistence|Privilege Escalation,no
T1547.009,Shortcut Modification,Persistence|Privilege Escalation,APT39|Darkhotel|APT29|Gorgon Group|Dragonfly 2.0|Leviathan|Lazarus Group
T1547.008,LSASS Driver,Persistence|Privilege Escalation,no
T1547.007,Re-opened Applications,Persistence|Privilege Escalation,no
T1547.006,Kernel Modules and Extensions,Persistence|Privilege Escalation,no
T1547.005,Security Support Provider,Persistence|Privilege Escalation,Lazarus Group
T1547.004,Winlogon Helper DLL,Persistence|Privilege Escalation,Wizard Spider|Tropic Trooper|Turla
T1547.005,Security Support Provider,Persistence|Privilege Escalation,no
T1547.004,Winlogon Helper DLL,Persistence|Privilege Escalation,Tropic Trooper|Turla
T1547.003,Time Providers,Persistence|Privilege Escalation,no
T1546.014,Emond,Privilege Escalation|Persistence,no
T1546.013,PowerShell Profile,Privilege Escalation|Persistence,Turla
@@ -346,30 +244,30 @@ T1546.007,Netsh Helper DLL,Privilege Escalation|Persistence,no
T1546.006,LC_LOAD_DYLIB Addition,Privilege Escalation|Persistence,no
T1546.005,Trap,Privilege Escalation|Persistence,no
T1546.004,.bash_profile and .bashrc,Privilege Escalation|Persistence,no
T1546.003,Windows Management Instrumentation Event Subscription,Privilege Escalation|Persistence,UNC2452|APT33|Blue Mockingbird|Turla|Leviathan|APT29
T1546.003,Windows Management Instrumentation Event Subscription,Privilege Escalation|Persistence,APT33|Blue Mockingbird|Turla|Leviathan|APT29
T1546.002,Screensaver,Privilege Escalation|Persistence,no
T1546.001,Change Default File Association,Privilege Escalation|Persistence,Kimsuky
T1547.001,Registry Run Keys / Startup Folder,Persistence|Privilege Escalation,Wizard Spider|PROMETHIUM|Rocke|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Silence|RTM|Inception|APT41|Machete|Kimsuky|APT33|APT39|APT32|APT18|Turla|Dark Caracal|Cobalt Group|Honeybee|APT19|Ke3chang|Threat Group-3390|Dragonfly 2.0|Gorgon Group|MuddyWater|APT37|Leviathan|BRONZE BUTLER|Magic Hound|APT3|FIN10|FIN7|Patchwork|FIN6|Lazarus Group|Putter Panda|APT29|Darkhotel
T1547.001,Registry Run Keys / Startup Folder,Persistence|Privilege Escalation,Rocke|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Silence|RTM|Inception|APT41|Machete|Kimsuky|APT33|APT39|APT32|APT18|Turla|Dark Caracal|Cobalt Group|Honeybee|Threat Group-3390|Dragonfly 2.0|Gorgon Group|Ke3chang|APT19|Leviathan|MuddyWater|APT37|BRONZE BUTLER|Magic Hound|APT3|FIN10|FIN7|Patchwork|FIN6|Lazarus Group|Putter Panda|APT29|Darkhotel
T1218.002,Control Panel,Defense Evasion,no
T1218.010,Regsvr32,Defense Evasion,Blue Mockingbird|Inception|WIRTE|APT19|Cobalt Group|Leviathan|APT32|Deep Panda
T1218.010,Regsvr32,Defense Evasion,Blue Mockingbird|Inception|WIRTE|Cobalt Group|APT19|Leviathan|APT32|Deep Panda
T1218.009,Regsvcs/Regasm,Defense Evasion,no
T1218.005,Mshta,Defense Evasion,Lazarus Group|Inception|Kimsuky|APT32|MuddyWater|FIN7
T1218.004,InstallUtil,Defense Evasion,menuPass
T1218.001,Compiled HTML File,Defense Evasion,APT41|Silence|OilRig|Lazarus Group|Dark Caracal
T1218.005,Mshta,Defense Evasion,Inception|Kimsuky|APT32|MuddyWater|FIN7
T1218.004,InstallUtil,Defense Evasion,no
T1218.001,Compiled HTML File,Defense Evasion,APT41|Silence|Lazarus Group|Dark Caracal|OilRig
T1218.003,CMSTP,Defense Evasion,Cobalt Group|MuddyWater
T1218.011,Rundll32,Defense Evasion,UNC2452|Gamaredon Group|APT32|Sandworm Team|Blue Mockingbird|TA505|MuddyWater|APT29|APT19|CopyKittens|APT3|Carbanak|APT28
T1218.011,Rundll32,Defense Evasion,APT32|Sandworm Team|Blue Mockingbird|TA505|MuddyWater|APT29|APT19|CopyKittens|APT3|Carbanak|APT28
T1547,Boot or Logon Autostart Execution,Persistence|Privilege Escalation,no
T1546,Event Triggered Execution,Privilege Escalation|Persistence,no
T1098.003,Add Office 365 Global Administrator Role,Persistence,no
T1098.002,Exchange Email Delegate Permissions,Persistence,UNC2452|Magic Hound
T1098.001,Additional Cloud Credentials,Persistence,UNC2452
T1098.002,Exchange Email Delegate Permissions,Persistence,Magic Hound
T1098.001,Additional Azure Service Principal Credentials,Persistence,no
T1543.004,Launch Daemon,Persistence|Privilege Escalation,no
T1543.003,Windows Service,Persistence|Privilege Escalation,PROMETHIUM|Blue Mockingbird|DarkVishnya|Wizard Spider|APT32|APT41|Kimsuky|Tropic Trooper|Threat Group-3390|Honeybee|Cobalt Group|Ke3chang|FIN7|APT19|APT3|Lazarus Group|Carbanak
T1543.003,Windows Service,Persistence|Privilege Escalation,Blue Mockingbird|DarkVishnya|Wizard Spider|APT32|APT41|Kimsuky|Tropic Trooper|Cobalt Group|Ke3chang|Honeybee|FIN7|Threat Group-3390|APT19|APT3|Lazarus Group|Carbanak
T1543.002,Systemd Service,Persistence|Privilege Escalation,Rocke
T1543.001,Launch Agent,Persistence|Privilege Escalation,no
T1037.005,Startup Items,Persistence|Privilege Escalation,no
T1037.004,Rc.common,Persistence|Privilege Escalation,no
T1055.012,Process Hollowing,Defense Evasion|Privilege Escalation,menuPass|Gorgon Group|Threat Group-3390|Patchwork
T1055.012,Process Hollowing,Defense Evasion|Privilege Escalation,Threat Group-3390|menuPass|Gorgon Group|Patchwork
T1055.013,Process Doppelgänging,Defense Evasion|Privilege Escalation,Leafminer
T1055.011,Extra Window Memory Injection,Defense Evasion|Privilege Escalation,no
T1055.014,VDSO Hijacking,Defense Evasion|Privilege Escalation,no
@@ -379,7 +277,7 @@ T1055.005,Thread Local Storage,Defense Evasion|Privilege Escalation,no
T1055.004,Asynchronous Procedure Call,Defense Evasion|Privilege Escalation,no
T1055.003,Thread Execution Hijacking,Defense Evasion|Privilege Escalation,no
T1055.002,Portable Executable Injection,Defense Evasion|Privilege Escalation,Rocke|Gorgon Group
T1055.001,Dynamic-link Library Injection,Defense Evasion|Privilege Escalation,Wizard Spider|TA505|Turla|Tropic Trooper|Lazarus Group|Putter Panda
T1055.001,Dynamic-link Library Injection,Defense Evasion|Privilege Escalation,TA505|Turla|Tropic Trooper|Lazarus Group|Putter Panda
T1037.003,Network Logon Script,Persistence|Privilege Escalation,no
T1543,Create or Modify System Process,Persistence|Privilege Escalation,no
T1037.002,Logon Script (Mac),Persistence|Privilege Escalation,no
@@ -393,7 +291,7 @@ T1505.001,SQL Stored Procedures,Persistence,no
T1053.003,Cron,Execution|Persistence|Privilege Escalation,Rocke
T1053.004,Launchd,Execution|Persistence|Privilege Escalation,no
T1053.001,At (Linux),Execution|Persistence|Privilege Escalation,no
T1053.005,Scheduled Task,Execution|Persistence|Privilege Escalation,UNC2452|Chimera|Gamaredon Group|Blue Mockingbird|MuddyWater|Wizard Spider|Frankenstein|APT-C-36|BRONZE BUTLER|APT41|Machete|Soft Cell|Silence|TEMP.Veles|APT33|APT39|Cobalt Group|OilRig|Rancor|Dragonfly 2.0|Patchwork|FIN8|FIN7|APT32|menuPass|FIN10|Stealth Falcon|FIN6|APT3|APT29
T1053.005,Scheduled Task,Execution|Persistence|Privilege Escalation,Gamaredon Group|Blue Mockingbird|MuddyWater|Wizard Spider|Frankenstein|APT-C-36|BRONZE BUTLER|APT41|Machete|Soft Cell|Silence|TEMP.Veles|APT33|APT39|Dragonfly 2.0|Patchwork|OilRig|Rancor|Cobalt Group|FIN8|menuPass|FIN10|APT32|FIN7|Stealth Falcon|FIN6|APT3|APT29
T1053.002,At (Windows),Execution|Persistence|Privilege Escalation,BRONZE BUTLER|Threat Group-3390|APT18
T1542,Pre-OS Boot,Defense Evasion|Persistence,no
T1137.001,Office Template Macros,Persistence,MuddyWater
@@ -418,52 +316,52 @@ T1526,Cloud Service Discovery,Discovery,no
T1505,Server Software Component,Persistence,no
T1499,Endpoint Denial of Service,Impact,no
T1497,Virtualization/Sandbox Evasion,Defense Evasion|Discovery,no
T1498,Network Denial of Service,Impact,APT28
T1498,Network Denial of Service,Impact,no
T1496,Resource Hijacking,Impact,Blue Mockingbird|Rocke|APT41|Lazarus Group
T1495,Firmware Corruption,Impact,no
T1491,Defacement,Impact,no
T1490,Inhibit System Recovery,Impact,no
T1489,Service Stop,Impact,Wizard Spider|Lazarus Group
T1489,Service Stop,Impact,Lazarus Group
T1486,Data Encrypted for Impact,Impact,APT41|TA505|APT38
T1485,Data Destruction,Impact,Sandworm Team|Lazarus Group|APT38
T1484,Domain Policy Modification,Defense Evasion|Privilege Escalation,no
T1482,Domain Trust Discovery,Discovery,UNC2452|Wizard Spider
T1484,Group Policy Modification,Defense Evasion|Privilege Escalation,no
T1482,Domain Trust Discovery,Discovery,Wizard Spider
T1480,Execution Guardrails,Defense Evasion,no
T1220,XSL Script Processing,Defense Evasion,Cobalt Group
T1222,File and Directory Permissions Modification,Defense Evasion,no
T1221,Template Injection,Defense Evasion,Gamaredon Group|Frankenstein|Inception|APT28|Tropic Trooper|Dragonfly 2.0|DarkHydrus
T1203,Exploitation for Client Execution,Execution,Sandworm Team|MuddyWater|Frankenstein|Inception|BlackTech|APT41|admin@338|Threat Group-3390|APT12|The White Company|APT33|APT32|APT28|Tropic Trooper|BRONZE BUTLER|Lazarus Group|Cobalt Group|APT29|Patchwork|Leviathan|APT37|Elderwood|TA459
T1200,Hardware Additions,Initial Access,DarkVishnya
T1202,Indirect Command Execution,Defense Evasion,no
T1213,Data from Information Repositories,Collection,FIN6|Turla
T1207,Rogue Domain Controller,Defense Evasion,no
T1204,User Execution,Execution,no
T1217,Browser Bookmark Discovery,Discovery,no
T1190,Exploit Public-Facing Application,Initial Access,UNC2452|APT28|APT29|GOLD SOUTHFIELD|Blue Mockingbird|Rocke|APT39|BlackTech|APT41|Soft Cell|Night Dragon|Axiom
T1210,Exploitation of Remote Services,Lateral Movement,Wizard Spider|Threat Group-3390|APT28
T1220,XSL Script Processing,Defense Evasion,Cobalt Group
T1197,BITS Jobs,Defense Evasion|Persistence,Patchwork|APT41|Leviathan
T1217,Browser Bookmark Discovery,Discovery,no
T1213,Data from Information Repositories,Collection,Turla
T1189,Drive-by Compromise,Initial Access,Turla|Windshift|RTM|Darkhotel|APT38|Dragonfly 2.0|BRONZE BUTLER|Leafminer|Dark Caracal|APT19|APT32|Lazarus Group|Threat Group-3390|Elderwood|APT37|Patchwork|PLATINUM
T1203,Exploitation for Client Execution,Execution,Sandworm Team|MuddyWater|Frankenstein|Inception|BlackTech|APT41|admin@338|Threat Group-3390|APT12|The White Company|APT33|APT32|APT28|Tropic Trooper|Lazarus Group|BRONZE BUTLER|Cobalt Group|APT37|Patchwork|Leviathan|Elderwood|TA459|APT29
T1212,Exploitation for Credential Access,Credential Access,no
T1211,Exploitation for Defense Evasion,Defense Evasion,APT28
T1190,Exploit Public-Facing Application,Initial Access,Blue Mockingbird|Rocke|APT39|BlackTech|APT41|Soft Cell|Night Dragon|Axiom
T1210,Exploitation of Remote Services,Lateral Movement,Threat Group-3390|APT28
T1202,Indirect Command Execution,Defense Evasion,no
T1200,Hardware Additions,Initial Access,DarkVishnya
T1201,Password Policy Discovery,Discovery,Turla|OilRig
T1219,Remote Access Software,Command And Control,Sandworm Team|DarkVishnya|RTM|Kimsuky|Night Dragon|Thrip|Cobalt Group|Carbanak
T1207,Rogue Domain Controller,Defense Evasion,no
T1199,Trusted Relationship,Initial Access,APT28|menuPass
T1218,Signed Binary Proxy Execution,Defense Evasion,no
T1204,User Execution,Execution,no
T1216,Signed Script Proxy Execution,Defense Evasion,no
T1195,Supply Chain Compromise,Initial Access,Elderwood
T1205,Traffic Signaling,Defense Evasion|Persistence|Command And Control,no
T1189,Drive-by Compromise,Initial Access,Dragonfly|PROMETHIUM|Turla|Windshift|RTM|Darkhotel|APT38|Lazarus Group|APT32|Dark Caracal|Dragonfly 2.0|BRONZE BUTLER|Leafminer|APT19|Threat Group-3390|APT37|Patchwork|PLATINUM|Elderwood
T1212,Exploitation for Credential Access,Credential Access,no
T1219,Remote Access Software,Command And Control,Sandworm Team|DarkVishnya|RTM|Kimsuky|Night Dragon|Thrip|Cobalt Group|Carbanak
T1211,Exploitation for Defense Evasion,Defense Evasion,APT28
T1218,Signed Binary Proxy Execution,Defense Evasion,no
T1216,Signed Script Proxy Execution,Defense Evasion,no
T1199,Trusted Relationship,Initial Access,GOLD SOUTHFIELD|APT28|menuPass
T1176,Browser Extensions,Persistence,Kimsuky|Stolen Pencil
T1175,Component Object Model and Distributed COM,Lateral Movement|Execution,no
T1187,Forced Authentication,Credential Access,DarkHydrus|Dragonfly 2.0
T1185,Man in the Browser,Collection,no
T1187,Forced Authentication,Credential Access,Dragonfly 2.0|DarkHydrus
T1149,LC_MAIN Hijacking,Defense Evasion,no
T1134,Access Token Manipulation,Defense Evasion|Privilege Escalation,Blue Mockingbird
T1136,Create Account,Persistence,no
T1134,Access Token Manipulation,Defense Evasion|Privilege Escalation,FIN6|Blue Mockingbird
T1135,Network Share Discovery,Discovery,Wizard Spider|APT32|APT39|DarkVishnya|APT41|Tropic Trooper|APT1|Dragonfly 2.0|Sowbug
T1140,Deobfuscate/Decode Files or Information,Defense Evasion,UNC2452|Rocke|Sandworm Team|Gamaredon Group|Molerats|Frankenstein|Turla|WIRTE|Darkhotel|Tropic Trooper|menuPass|Threat Group-3390|Gorgon Group|APT19|Honeybee|Leviathan|MuddyWater|APT28|OilRig|BRONZE BUTLER
T1140,Deobfuscate/Decode Files or Information,Defense Evasion,Rocke|Sandworm Team|Gamaredon Group|Molerats|Frankenstein|Turla|WIRTE|Darkhotel|Tropic Trooper|menuPass|Honeybee|Threat Group-3390|APT19|Gorgon Group|Leviathan|MuddyWater|APT28|OilRig|BRONZE BUTLER
T1149,LC_MAIN Hijacking,Defense Evasion,no
T1135,Network Share Discovery,Discovery,APT32|APT39|DarkVishnya|APT41|Tropic Trooper|APT1|Dragonfly 2.0|Sowbug
T1137,Office Application Startup,Persistence,Gamaredon Group|APT32
T1153,Source,Execution,no
T1133,External Remote Services,Persistence|Initial Access,Wizard Spider|GOLD SOUTHFIELD|Chimera|Sandworm Team|APT41|Soft Cell|TEMP.Veles|Night Dragon|Ke3chang|OilRig|Dragonfly 2.0|FIN5|Threat Group-3390|APT18
T1133,External Remote Services,Persistence|Initial Access,Sandworm Team|APT41|Soft Cell|TEMP.Veles|Night Dragon|OilRig|Dragonfly 2.0|Ke3chang|FIN5|Threat Group-3390|APT18
T1132,Data Encoding,Command And Control,no
T1129,Shared Modules,Execution,no
T1127,Trusted Developer Utilities Proxy Execution,Defense Evasion,no
@@ -471,72 +369,72 @@ T1125,Video Capture,Collection,Silence|FIN7
T1124,System Time Discovery,Discovery,The White Company|Lazarus Group|BRONZE BUTLER|Turla
T1123,Audio Capture,Collection,APT37
T1120,Peripheral Device Discovery,Discovery,Turla|APT37|Gamaredon Group|Equation|APT28
T1119,Automated Collection,Collection,Gamaredon Group|Tropic Trooper|Frankenstein|APT1|APT28|Patchwork|FIN5|OilRig|Threat Group-3390|FIN6
T1119,Automated Collection,Collection,Tropic Trooper|Frankenstein|APT1|APT28|Patchwork|OilRig|FIN5|Threat Group-3390|FIN6
T1115,Clipboard Data,Collection,APT39|APT38
T1114,Email Collection,Collection,no
T1113,Screen Capture,Collection,Gamaredon Group|APT39|Silence|MuddyWater|OilRig|Dragonfly 2.0|FIN7|Dark Caracal|BRONZE BUTLER|Magic Hound|Group5|APT28
T1112,Modify Registry,Defense Evasion,Lazarus Group|Gamaredon Group|Blue Mockingbird|Wizard Spider|Silence|APT41|Turla|APT32|APT38|Dragonfly 2.0|Patchwork|APT19|Gorgon Group|Threat Group-3390|Honeybee|FIN8
T1113,Screen Capture,Collection,Gamaredon Group|APT39|Silence|MuddyWater|Dragonfly 2.0|OilRig|Dark Caracal|FIN7|BRONZE BUTLER|Magic Hound|Group5|APT28
T1112,Modify Registry,Defense Evasion,Gamaredon Group|Blue Mockingbird|Wizard Spider|Silence|APT41|Turla|APT32|APT38|Dragonfly 2.0|APT19|Threat Group-3390|Honeybee|Patchwork|Gorgon Group|FIN8
T1111,Two-Factor Authentication Interception,Credential Access,no
T1110,Brute Force,Credential Access,DarkVishnya|APT39|OilRig|FIN5|Turla
T1108,Redundant Access,Defense Evasion|Persistence,no
T1106,Native API,Execution,Chimera|Gamaredon Group|Tropic Trooper|Sharpshooter|Turla|Silence|APT37|Gorgon Group
T1105,Ingress Tool Transfer,Command And Control,UNC2452|Chimera|Sandworm Team|Whitefly|Rocke|APT39|Tropic Trooper|Sharpshooter|Molerats|Frankenstein|Silence|APT-C-36|APT41|Soft Cell|TA505|WIRTE|APT33|MuddyWater|APT18|APT38|Rancor|OilRig|Dragonfly 2.0|Cobalt Group|Turla|Gorgon Group|APT37|Leviathan|Elderwood|PLATINUM|FIN8|Magic Hound|APT32|APT3|BRONZE BUTLER|menuPass|FIN7|Gamaredon Group|Patchwork|Lazarus Group|Threat Group-3390|APT28
T1106,Native API,Execution,Gamaredon Group|Tropic Trooper|Sharpshooter|Turla|Silence|Gorgon Group|APT37
T1105,Ingress Tool Transfer,Command And Control,Sandworm Team|Whitefly|Rocke|APT39|Tropic Trooper|Sharpshooter|Molerats|Frankenstein|Silence|APT-C-36|APT41|Soft Cell|TA505|WIRTE|APT33|MuddyWater|APT18|APT38|Rancor|Cobalt Group|Turla|Gorgon Group|OilRig|Dragonfly 2.0|APT37|FIN8|PLATINUM|Leviathan|Elderwood|Magic Hound|APT3|APT32|BRONZE BUTLER|menuPass|FIN7|Gamaredon Group|Patchwork|Lazarus Group|Threat Group-3390|APT28
T1104,Multi-Stage Channels,Command And Control,APT41|MuddyWater|APT3
T1102,Web Service,Command And Control,Chimera|Gamaredon Group|Rocke|Inception|FIN6
T1102,Web Service,Command And Control,Gamaredon Group|Rocke|Inception|FIN6
T1098,Account Manipulation,Persistence,APT3|Dragonfly 2.0|Lazarus Group
T1095,Non-Application Layer Protocol,Command And Control,FIN6|APT29|PLATINUM|APT3
T1095,Non-Application Layer Protocol,Command And Control,APT29|PLATINUM|APT3
T1092,Communication Through Removable Media,Command And Control,APT28
T1091,Replication Through Removable Media,Lateral Movement|Initial Access,Tropic Trooper|Darkhotel|APT28
T1090,Proxy,Command And Control,Sandworm Team|Blue Mockingbird|APT41|Turla
T1087,Account Discovery,Discovery,UNC2452
T1083,File and Directory Discovery,Discovery,UNC2452|Gamaredon Group|Tropic Trooper|Inception|APT41|Kimsuky|APT32|MuddyWater|APT18|Dragonfly 2.0|Leafminer|Honeybee|Dark Caracal|APT3|BRONZE BUTLER|Sowbug|Magic Hound|APT28|Patchwork|Lazarus Group|Dust Storm|admin@338|Turla|Ke3chang
T1082,System Information Discovery,Discovery,UNC2452|Wizard Spider|Rocke|Sandworm Team|Blue Mockingbird|Tropic Trooper|Frankenstein|Inception|Kimsuky|Darkhotel|MuddyWater|APT18|APT37|Honeybee|APT19|APT32|Magic Hound|Sowbug|OilRig|APT3|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|admin@338|Turla|Ke3chang
T1080,Taint Shared Content,Lateral Movement,Gamaredon Group|BRONZE BUTLER|Darkhotel
T1078,Valid Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,UNC2452|Chimera|Sandworm Team|Wizard Spider|Silence|APT41|Soft Cell|TEMP.Veles|APT39|FIN4|Night Dragon|Dragonfly 2.0|Leviathan|APT33|FIN8|FIN5|OilRig|APT28|FIN10|menuPass|Suckfly|FIN6|Threat Group-3390|APT18|PittyTiger|Carbanak
T1090,Proxy,Command And Control,Sandworm Team|Blue Mockingbird|Wizard Spider|APT41|Turla
T1087,Account Discovery,Discovery,no
T1083,File and Directory Discovery,Discovery,Gamaredon Group|Tropic Trooper|Inception|APT41|Kimsuky|APT32|MuddyWater|APT18|Leafminer|Honeybee|Dark Caracal|Dragonfly 2.0|Magic Hound|Sowbug|BRONZE BUTLER|APT3|APT28|Patchwork|Lazarus Group|Dust Storm|admin@338|Turla|Ke3chang
T1082,System Information Discovery,Discovery,Rocke|Sandworm Team|Blue Mockingbird|Tropic Trooper|Frankenstein|Inception|Kimsuky|Darkhotel|MuddyWater|APT18|Honeybee|APT19|APT37|APT32|Magic Hound|OilRig|APT3|Sowbug|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|admin@338|Turla|Ke3chang
T1080,Taint Shared Content,Lateral Movement,BRONZE BUTLER|Darkhotel
T1078,Valid Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,Sandworm Team|Wizard Spider|Silence|APT41|Soft Cell|TEMP.Veles|APT39|FIN4|Night Dragon|Dragonfly 2.0|FIN8|Leviathan|APT33|OilRig|FIN5|menuPass|APT28|FIN10|Suckfly|FIN6|Threat Group-3390|APT18|PittyTiger|Carbanak
T1074,Data Staged,Collection,Wizard Spider
T1072,Software Deployment Tools,Execution|Lateral Movement,Silence|APT32|Threat Group-1314
T1071,Application Layer Protocol,Command And Control,Rocke|Magic Hound|Dragonfly 2.0
T1070,Indicator Removal on Host,Defense Evasion,UNC2452
T1069,Permission Groups Discovery,Discovery,UNC2452|TA505|APT3
T1070,Indicator Removal on Host,Defense Evasion,no
T1069,Permission Groups Discovery,Discovery,TA505|APT3
T1068,Exploitation for Privilege Escalation,Privilege Escalation,Whitefly|APT33|Cobalt Group|PLATINUM|FIN8|APT32|Threat Group-3390|FIN6|APT28
T1064,Scripting,Defense Evasion|Execution,no
T1062,Hypervisor,Persistence,no
T1061,Graphical User Interface,Execution,no
T1059,Command and Scripting Interpreter,Execution,APT32|Molerats|Whitefly|APT39|APT19|FIN7|Dragonfly 2.0|OilRig|FIN5|Stealth Falcon|FIN6|Ke3chang
T1057,Process Discovery,Discovery,UNC2452|Rocke|Frankenstein|Inception|Darkhotel|MuddyWater|APT1|APT38|Tropic Trooper|APT37|Honeybee|OilRig|APT3|Magic Hound|APT28|Winnti Group|Stealth Falcon|Poseidon Group|Lazarus Group|Molerats|Turla|Deep Panda|Ke3chang
T1059,Command and Scripting Interpreter,Execution,APT32|Molerats|Whitefly|Dragonfly 2.0|APT19|FIN7|OilRig|FIN5|Stealth Falcon|FIN6|Ke3chang
T1057,Process Discovery,Discovery,Rocke|Frankenstein|Inception|Darkhotel|MuddyWater|APT1|APT38|Tropic Trooper|APT37|Honeybee|OilRig|APT3|Magic Hound|APT28|Winnti Group|Stealth Falcon|Poseidon Group|Lazarus Group|Molerats|Turla|Deep Panda|Ke3chang
T1056,Input Capture,Collection|Credential Access,no
T1055,Process Injection,Defense Evasion|Privilege Escalation,APT32|Sharpshooter|Silence|APT41|Kimsuky|Cobalt Group|APT37|Turla|Honeybee|PLATINUM
T1055,Process Injection,Defense Evasion|Privilege Escalation,APT32|Sharpshooter|Silence|APT41|Kimsuky|Turla|Cobalt Group|APT37|Honeybee|PLATINUM
T1053,Scheduled Task/Job,Execution|Persistence|Privilege Escalation,no
T1052,Exfiltration Over Physical Medium,Exfiltration,no
T1051,Shared Webroot,Lateral Movement,no
T1049,System Network Connections Discovery,Discovery,Tropic Trooper|APT41|APT38|Soft Cell|APT32|APT1|OilRig|APT3|Threat Group-3390|menuPass|Poseidon Group|admin@338|Turla|Ke3chang
T1049,System Network Connections Discovery,Discovery,Tropic Trooper|APT41|APT38|Soft Cell|APT32|APT1|OilRig|APT3|menuPass|Threat Group-3390|Poseidon Group|admin@338|Turla|Ke3chang
T1048,Exfiltration Over Alternative Protocol,Exfiltration,no
T1047,Windows Management Instrumentation,Execution,UNC2452|Chimera|Blue Mockingbird|Wizard Spider|Frankenstein|APT41|FIN6|Soft Cell|APT32|MuddyWater|OilRig|Threat Group-3390|FIN8|Leviathan|menuPass|Stealth Falcon|Lazarus Group|APT29|Deep Panda
T1046,Network Service Scanning,Discovery,Rocke|DarkVishnya|APT41|Tropic Trooper|APT39|APT32|Cobalt Group|Leafminer|OilRig|menuPass|Suckfly|FIN6|Threat Group-3390
T1043,Commonly Used Port,Command And Control,OilRig|APT28|TEMP.Veles|Night Dragon|APT29|APT18|FIN7|Dragonfly 2.0|APT19|FIN8|APT37|APT3|Magic Hound|Lazarus Group|Threat Group-3390
T1047,Windows Management Instrumentation,Execution,Blue Mockingbird|Wizard Spider|Frankenstein|APT41|FIN6|Soft Cell|APT32|MuddyWater|OilRig|Threat Group-3390|FIN8|Leviathan|menuPass|Stealth Falcon|Lazarus Group|APT29|Deep Panda
T1046,Network Service Scanning,Discovery,Rocke|DarkVishnya|APT41|Tropic Trooper|APT39|APT32|Leafminer|OilRig|Cobalt Group|menuPass|Suckfly|FIN6|Threat Group-3390
T1043,Commonly Used Port,Command And Control,Machete|OilRig|APT28|TEMP.Veles|Night Dragon|APT29|APT18|APT19|Dragonfly 2.0|FIN7|FIN8|APT37|Magic Hound|APT3|Lazarus Group|Threat Group-3390
T1041,Exfiltration Over C2 Channel,Exfiltration,Sandworm Team|MuddyWater|Wizard Spider|Frankenstein|Kimsuky|Soft Cell|APT32|APT3|Gamaredon Group|Stealth Falcon|Lazarus Group|Ke3chang
T1040,Network Sniffing,Credential Access|Discovery,Sandworm Team|DarkVishnya|APT33|Stolen Pencil|APT28
T1039,Data from Network Shared Drive,Collection,Gamaredon Group|BRONZE BUTLER|Sowbug|menuPass
T1039,Data from Network Shared Drive,Collection,Sowbug|BRONZE BUTLER|menuPass
T1037,Boot or Logon Initialization Scripts,Persistence|Privilege Escalation,Rocke
T1036,Masquerading,Defense Evasion,UNC2452|Windshift|APT32|BRONZE BUTLER|menuPass|Dragonfly 2.0
T1036,Masquerading,Defense Evasion,Windshift|APT32|BRONZE BUTLER|menuPass|Dragonfly 2.0
T1034,Path Interception,Persistence|Privilege Escalation,no
T1033,System Owner/User Discovery,Discovery,Wizard Spider|Frankenstein|APT41|Soft Cell|Tropic Trooper|APT39|MuddyWater|APT32|APT37|APT19|Dragonfly 2.0|OilRig|Magic Hound|FIN10|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|APT3
T1033,System Owner/User Discovery,Discovery,Frankenstein|APT41|Soft Cell|Tropic Trooper|APT39|MuddyWater|APT32|APT37|APT19|Dragonfly 2.0|OilRig|Magic Hound|FIN10|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|APT3
T1030,Data Transfer Size Limits,Exfiltration,Threat Group-3390
T1029,Scheduled Transfer,Exfiltration,no
T1027,Obfuscated Files or Information,Defense Evasion,UNC2452|FIN6|Chimera|Gamaredon Group|Rocke|Sandworm Team|Blue Mockingbird|Whitefly|Molerats|Wizard Spider|Mofang|Frankenstein|Inception|APT-C-36|APT41|Machete|Soft Cell|Turla|TA505|Silence|APT33|Night Dragon|Darkhotel|Gallmaker|APT29|APT18|Tropic Trooper|menuPass|Honeybee|Patchwork|Threat Group-3390|APT19|Cobalt Group|Leafminer|APT37|Dark Caracal|FIN8|MuddyWater|FIN7|BlackOasis|Leviathan|Elderwood|OilRig|Magic Hound|APT3|APT32|Group5|Lazarus Group|Dust Storm|Putter Panda|APT28
T1027,Obfuscated Files or Information,Defense Evasion,Gamaredon Group|Rocke|Sandworm Team|Blue Mockingbird|Whitefly|Molerats|Wizard Spider|Mofang|Frankenstein|Inception|APT-C-36|APT41|Machete|Soft Cell|Turla|TA505|Silence|APT33|Night Dragon|Darkhotel|Gallmaker|APT29|APT18|Tropic Trooper|Cobalt Group|Patchwork|Leafminer|APT37|Threat Group-3390|Honeybee|Dark Caracal|menuPass|APT19|BlackOasis|FIN8|Leviathan|Elderwood|MuddyWater|FIN7|Magic Hound|OilRig|APT3|APT32|Group5|Dust Storm|Lazarus Group|Putter Panda|APT28
T1026,Multiband Communication,Command And Control,Lazarus Group
T1025,Data from Removable Media,Collection,Machete|Turla|Gamaredon Group|APT28
T1021,Remote Services,Lateral Movement,no
T1020,Automated Exfiltration,Exfiltration,Gamaredon Group|Tropic Trooper|Frankenstein|Honeybee
T1018,Remote System Discovery,Discovery,UNC2452|Sandworm Team|Rocke|Wizard Spider|Silence|Soft Cell|APT39|APT32|Threat Group-3390|Dragonfly 2.0|Ke3chang|Leafminer|Deep Panda|FIN8|FIN5|APT3|BRONZE BUTLER|menuPass|FIN6|Turla
T1016,System Network Configuration Discovery,Discovery,Wizard Spider|Sandworm Team|Tropic Trooper|Frankenstein|APT41|Soft Cell|APT32|Darkhotel|MuddyWater|APT1|Dragonfly 2.0|APT19|OilRig|Magic Hound|menuPass|Threat Group-3390|Stealth Falcon|Lazarus Group|APT3|Naikon|admin@338|Turla|Ke3chang
T1020,Automated Exfiltration,Exfiltration,Tropic Trooper|Frankenstein|Honeybee
T1018,Remote System Discovery,Discovery,Sandworm Team|Rocke|Wizard Spider|Silence|Soft Cell|APT39|APT32|Deep Panda|Threat Group-3390|Dragonfly 2.0|Leafminer|Ke3chang|FIN8|APT3|FIN5|BRONZE BUTLER|menuPass|FIN6|Turla
T1016,System Network Configuration Discovery,Discovery,Sandworm Team|Tropic Trooper|Frankenstein|APT41|Soft Cell|APT32|Darkhotel|MuddyWater|APT1|APT19|Dragonfly 2.0|Magic Hound|OilRig|menuPass|Threat Group-3390|Stealth Falcon|Lazarus Group|APT3|Naikon|admin@338|Turla|Ke3chang
T1014,Rootkit,Defense Evasion,Rocke|APT41|APT28|Winnti Group
T1012,Query Registry,Discovery,APT32|Threat Group-3390|Dragonfly 2.0|OilRig|Stealth Falcon|Lazarus Group|Turla
T1012,Query Registry,Discovery,APT32|Dragonfly 2.0|Threat Group-3390|OilRig|Stealth Falcon|Lazarus Group|Turla
T1011,Exfiltration Over Other Network Medium,Exfiltration,no
T1010,Application Window Discovery,Discovery,Lazarus Group
T1008,Fallback Channels,Command And Control,APT41|OilRig|Lazarus Group
T1007,System Service Discovery,Discovery,BRONZE BUTLER|APT1|OilRig|Poseidon Group|admin@338|Turla|Ke3chang
T1006,Direct Volume Access,Defense Evasion,no
T1005,Data from Local System,Collection,UNC2452|FIN6|Gamaredon Group|APT39|Frankenstein|Inception|Kimsuky|Soft Cell|Turla|menuPass|Dark Caracal|Dragonfly 2.0|Honeybee|APT28|APT37|APT3|BRONZE BUTLER|Patchwork|Stealth Falcon|Lazarus Group|Dust Storm|Threat Group-3390|APT1|Ke3chang
T1005,Data from Local System,Collection,Gamaredon Group|APT39|Frankenstein|Inception|Kimsuky|Soft Cell|Turla|menuPass|Dark Caracal|Dragonfly 2.0|Honeybee|APT37|APT28|APT3|BRONZE BUTLER|Patchwork|Stealth Falcon|Lazarus Group|Dust Storm|Threat Group-3390|APT1|Ke3chang
T1003,OS Credential Dumping,Credential Access,APT39|Frankenstein|APT32|APT28|Leviathan|Sowbug|Suckfly|Poseidon Group|Axiom
T1001,Data Obfuscation,Command And Control,Axiom
1 mitre_id technique tactics groups
2 T1484.002 T1205.001 Domain Trust Modification Port Knocking Defense Evasion|Privilege Escalation Defense Evasion|Persistence|Command And Control UNC2452 no
T1484.001 Group Policy Modification Defense Evasion|Privilege Escalation no
T1606.002 SAML Tokens Credential Access UNC2452
T1606.001 Web Cookies Credential Access UNC2452
T1606 Forge Web Credentials Credential Access no
T1059.008 Network Device CLI Execution no
T1602.002 Network Device Configuration Dump Collection no
T1542.005 TFTP Boot Defense Evasion|Persistence no
T1542.004 ROMMONkit Defense Evasion|Persistence no
T1602.001 SNMP (MIB Dump) Collection no
T1602 Data from Configuration Repository Collection no
T1601.002 Downgrade System Image Defense Evasion no
T1601.001 Patch System Image Defense Evasion no
T1601 Modify System Image Defense Evasion no
T1600.002 Disable Crypto Hardware Defense Evasion no
T1600.001 Reduce Key Space Defense Evasion no
T1600 Weaken Encryption Defense Evasion no
T1556.004 Network Device Authentication Credential Access|Defense Evasion no
T1599.001 Network Address Translation Traversal Defense Evasion no
T1599 Network Boundary Bridging Defense Evasion no
T1020.001 Traffic Duplication Exfiltration no
T1557.002 ARP Cache Poisoning Credential Access|Collection Cleaver
T1588.006 Vulnerabilities Resource Development no
T1053.006 Systemd Timers Execution|Persistence|Privilege Escalation no
T1562.008 Disable Cloud Logs Defense Evasion no
T1547.012 Print Processors Persistence|Privilege Escalation no
T1598.003 Spearphishing Link Reconnaissance no
T1598.002 Spearphishing Attachment Reconnaissance no
T1598.001 Spearphishing Service Reconnaissance no
T1598 Phishing for Information Reconnaissance no
T1597.002 Purchase Technical Data Reconnaissance no
T1597.001 Threat Intel Vendors Reconnaissance no
T1597 Search Closed Sources Reconnaissance no
T1596.005 Scan Databases Reconnaissance no
T1596.004 CDNs Reconnaissance no
T1596.003 Digital Certificates Reconnaissance no
T1596.001 DNS/Passive DNS Reconnaissance no
T1596.002 WHOIS Reconnaissance no
T1596 Search Open Technical Databases Reconnaissance no
T1595.002 Vulnerability Scanning Reconnaissance no
T1595.001 Scanning IP Blocks Reconnaissance no
T1595 Active Scanning Reconnaissance no
T1594 Search Victim-Owned Websites Reconnaissance no
T1593.002 Search Engines Reconnaissance no
T1593.001 Social Media Reconnaissance no
T1593 Search Open Websites/Domains Reconnaissance no
T1592.004 Client Configurations Reconnaissance no
T1592.003 Firmware Reconnaissance no
T1592.002 Software Reconnaissance no
T1592.001 Hardware Reconnaissance no
T1592 Gather Victim Host Information Reconnaissance no
T1591.004 Identify Roles Reconnaissance no
T1591.003 Identify Business Tempo Reconnaissance no
T1591.001 Determine Physical Locations Reconnaissance no
T1591.002 Business Relationships Reconnaissance no
T1591 Gather Victim Org Information Reconnaissance no
T1590.006 Network Security Appliances Reconnaissance no
T1590.005 IP Addresses Reconnaissance no
T1590.004 Network Topology Reconnaissance no
T1590.003 Network Trust Dependencies Reconnaissance no
T1590.002 DNS Reconnaissance no
T1590.001 Domain Properties Reconnaissance no
T1590 Gather Victim Network Information Reconnaissance no
T1589.003 Employee Names Reconnaissance no
T1589.002 Email Addresses Reconnaissance no
T1589.001 Credentials Reconnaissance no
T1589 Gather Victim Identity Information Reconnaissance no
T1588.005 Exploits Resource Development no
T1588.004 Digital Certificates Resource Development no
T1588.003 Code Signing Certificates Resource Development Wizard Spider
T1588.002 Tool Resource Development no
T1588.001 Malware Resource Development Turla|APT1
T1588 Obtain Capabilities Resource Development no
T1587.004 Exploits Resource Development no
T1587.003 Digital Certificates Resource Development APT29|PROMETHIUM
T1587.002 Code Signing Certificates Resource Development PROMETHIUM|Patchwork
T1587.001 Malware Resource Development UNC2452|Turla|FIN7|Night Dragon|Cleaver
T1587 Develop Capabilities Resource Development no
T1586.002 Email Accounts Resource Development no
T1586.001 Social Media Accounts Resource Development no
T1586 Compromise Accounts Resource Development no
T1585.002 Email Accounts Resource Development APT1
T1585.001 Social Media Accounts Resource Development Cleaver
T1585 Establish Accounts Resource Development APT17
T1584.006 Web Services Resource Development Turla
T1584.005 Botnet Resource Development no
T1584.004 Server Resource Development Turla|APT16
T1584.003 Virtual Private Server Resource Development Turla
T1584.002 DNS Server Resource Development no
T1584.001 Domains Resource Development APT1
T1583.006 Web Services Resource Development APT17|APT29
T1583.005 Botnet Resource Development no
T1583.004 Server Resource Development no
T1583.003 Virtual Private Server Resource Development TEMP.Veles
T1583.002 DNS Server Resource Development no
T1584 Compromise Infrastructure Resource Development no
T1583.001 Domains Resource Development APT1|APT28
T1583 Acquire Infrastructure Resource Development no
T1564.007 VBA Stomping Defense Evasion no
T1558.004 AS-REP Roasting Credential Access no
T1580 Cloud Infrastructure Discovery Discovery no
T1218.012 Verclsid Defense Evasion no
T1205.001 Port Knocking Defense Evasion|Persistence|Command And Control PROMETHIUM
3 T1564.006 Run Virtual Instance Defense Evasion no
4 T1564.005 Hidden File System Defense Evasion Strider|Equation
5 T1556.003 Pluggable Authentication Modules Credential Access|Defense Evasion no
7 T1562.007 Disable or Modify Cloud Firewall Defense Evasion no
8 T1098.004 SSH Authorized Keys Persistence no
9 T1480.001 Environmental Keying Defense Evasion APT41|Equation
10 T1059.007 JavaScript/JScript Execution FIN6|APT32|FIN7|Cobalt Group|Molerats|TA505|Silence|Leafminer APT32|FIN7|Cobalt Group|Molerats|TA505|Silence|Leafminer
11 T1578.004 Revert Cloud Instance Defense Evasion no
12 T1578.003 Delete Cloud Instance Defense Evasion no
13 T1578.001 Create Snapshot Defense Evasion no
24 T1071.004 DNS Command And Control APT39|Tropic Trooper|OilRig|Ke3chang|Cobalt Group|APT18|APT41|FIN7
25 T1071.003 Mail Protocols Command And Control APT32|SilverTerrier|APT28
26 T1071.002 File Transfer Protocols Command And Control APT41|SilverTerrier|Machete|Honeybee
27 T1071.001 Web Protocols Command And Control UNC2452|Sandworm Team|TA505|Rocke|APT39|Tropic Trooper|MuddyWater|Wizard Spider|Inception|APT41|SilverTerrier|Machete|APT28|WIRTE|APT33|FIN4|Night Dragon|APT18|APT38|Threat Group-3390|Ke3chang|Dark Caracal|APT19|Cobalt Group|Rancor|Orangeworm|APT37|Turla|Lazarus Group|APT32|Magic Hound|BRONZE BUTLER|OilRig|Gamaredon Group|Stealth Falcon Sandworm Team|TA505|Rocke|APT39|Tropic Trooper|MuddyWater|Wizard Spider|Inception|APT41|SilverTerrier|Machete|APT28|WIRTE|APT33|FIN4|Night Dragon|APT18|APT38|Cobalt Group|APT19|Threat Group-3390|Rancor|Orangeworm|APT37|Ke3chang|Dark Caracal|Turla|Lazarus Group|BRONZE BUTLER|APT32|OilRig|Magic Hound|Gamaredon Group|Stealth Falcon
28 T1572 Protocol Tunneling Command And Control OilRig|Cobalt Group|FIN6
29 T1048.003 Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol Exfiltration Wizard Spider|FIN6|APT32|APT33|Thrip|FIN8|OilRig|Lazarus Group APT32|APT33|Thrip|FIN8|OilRig|Lazarus Group
30 T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol Exfiltration UNC2452 no
31 T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol Exfiltration no
32 T1001.003 Protocol Impersonation Command And Control Lazarus Group
33 T1001.002 Steganography Command And Control APT29|Axiom Axiom
34 T1001.001 Junk Data Command And Control APT28
35 T1132.002 Non-Standard Encoding Command And Control no
36 T1132.001 Standard Encoding Command And Control Sandworm Team|Tropic Trooper|MuddyWater|APT33|APT19|Lazarus Group|BRONZE BUTLER|Patchwork
37 T1090.004 Domain Fronting Command And Control APT29
38 T1090.003 Multi-hop Proxy Command And Control Inception|FIN4|APT29
39 T1090.002 External Proxy Command And Control APT39|Silence|Soft Cell|MuddyWater|APT3|FIN5|Lazarus Group|menuPass|APT28
40 T1090.001 Internal Proxy Command And Control UNC2452|APT39|Strider APT39|Strider
41 T1102.003 One-Way Communication Command And Control Leviathan
42 T1102.002 Bidirectional Communication Command And Control APT29|Sandworm Team|APT39|APT12|Turla|FIN7|APT37|Magic Hound|Carbanak Sandworm Team|APT39|APT12|Turla|FIN7|APT37|Magic Hound|Carbanak
43 T1102.001 Dead Drop Resolver Command And Control Rocke|APT41|BRONZE BUTLER|RTM|Patchwork
44 T1571 Non-Standard Port Command And Control Sandworm Team|Rocke|DarkVishnya|Silence|APT-C-36|Magic Hound|APT33|APT32|TEMP.Veles|Lazarus Group|FIN7
45 T1074.002 Remote Data Staging Collection UNC2452|Threat Group-3390|menuPass|FIN6|Night Dragon|FIN8 Threat Group-3390|menuPass|FIN6|Night Dragon|FIN8
46 T1074.001 Local Data Staging Collection Machete|Soft Cell|TEMP.Veles|Honeybee|Dragonfly 2.0|Patchwork|Leviathan|APT3|FIN5|menuPass|Lazarus Group|Threat Group-3390|APT28 Machete|Soft Cell|TEMP.Veles|Patchwork|Dragonfly 2.0|Honeybee|Leviathan|APT3|FIN5|menuPass|FIN6|Lazarus Group|Threat Group-3390|APT28
47 T1078.004 Cloud Accounts Defense Evasion|Persistence|Privilege Escalation|Initial Access APT33
48 T1564.004 NTFS File Attributes Defense Evasion APT32
49 T1564.003 Hidden Window Defense Evasion Gorgon Group|Deep Panda|DarkHydrus|CopyKittens|APT19|APT32|APT28|APT3|Magic Hound
50 T1078.003 Local Accounts Defense Evasion|Persistence|Privilege Escalation|Initial Access PROMETHIUM|Tropic Trooper|FIN10|Stolen Pencil|APT32 Tropic Trooper|FIN10|Stolen Pencil|APT32
51 T1078.002 Domain Accounts Defense Evasion|Persistence|Privilege Escalation|Initial Access Wizard Spider|APT29|TA505|APT3|Threat Group-1314 TA505|APT3|Threat Group-1314
52 T1078.001 Default Accounts Defense Evasion|Persistence|Privilege Escalation|Initial Access no
53 T1564.002 Hidden Users Defense Evasion no
54 T1574.006 LD_PRELOAD Persistence|Privilege Escalation|Defense Evasion Rocke
64 T1069.001 Local Groups Discovery Turla|OilRig|admin@338
65 T1570 Lateral Tool Transfer Lateral Movement APT32|Wizard Spider|Turla|FIN10
66 T1568.003 DNS Calculation Command And Control APT12
67 T1204.002 Malicious File Execution FIN6|PROMETHIUM|APT30|Magic Hound|Windshift|APT33|Sandworm Team|Naikon|Whitefly|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Wizard Spider|Mofang|Frankenstein|RTM|Inception|BlackTech|APT-C-36|Machete|admin@338|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Dragonfly 2.0|Dark Caracal|FIN7|APT32|Cobalt Group|DarkHydrus|Patchwork|Rancor|MuddyWater|BRONZE BUTLER|APT19|Gorgon Group|OilRig|Lazarus Group|APT29|menuPass|TA459|FIN8|Elderwood|PLATINUM|Leviathan|APT37|APT28 Magic Hound|Windshift|APT33|Sandworm Team|Naikon|Whitefly|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Wizard Spider|Mofang|Frankenstein|RTM|Inception|BlackTech|APT-C-36|Machete|admin@338|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|APT19|Dragonfly 2.0|BRONZE BUTLER|Cobalt Group|DarkHydrus|Gorgon Group|Patchwork|OilRig|Dark Caracal|MuddyWater|Lazarus Group|FIN7|APT32|Rancor|APT37|FIN8|APT28|Elderwood|TA459|APT29|Leviathan|menuPass|PLATINUM
68 T1204.001 Malicious Link Execution Wizard Spider|Patchwork|Windshift|APT32|Molerats|Mofang|BlackTech|TA505|OilRig|Machete|Leviathan|FIN8|FIN4|Elderwood|Dragonfly 2.0|Cobalt Group|APT39|Night Dragon|APT33|Turla Patchwork|Windshift|APT32|Molerats|Mofang|BlackTech|TA505|OilRig|Machete|Leviathan|FIN8|FIN4|Elderwood|Dragonfly 2.0|Cobalt Group|APT39|Night Dragon|APT33|Turla
69 T1195.003 Compromise Hardware Supply Chain Initial Access no
70 T1195.002 Compromise Software Supply Chain Initial Access UNC2452|GOLD SOUTHFIELD|Dragonfly|Sandworm Team|APT41 Sandworm Team|APT41
71 T1195.001 Compromise Software Dependencies and Development Tools Initial Access no
72 T1568.001 Fast Flux DNS Command And Control Machete|TA505 TA505
73 T1052.001 Exfiltration over USB Exfiltration Tropic Trooper
74 T1569.002 Service Execution Execution Wizard Spider|Blue Mockingbird|APT39|APT41|Silence|FIN6|APT32|Ke3chang|Honeybee Blue Mockingbird|APT39|APT41|Silence|FIN6|APT32|Honeybee|Ke3chang
75 T1569.001 Launchctl Execution no
76 T1569 System Services Execution no
77 T1568.002 Domain Generation Algorithms Command And Control APT41
78 T1568 Dynamic Resolution Command And Control UNC2452 no
79 T1011.001 Exfiltration Over Bluetooth Exfiltration no
80 T1567.002 Exfiltration to Cloud Storage Exfiltration Leviathan|Turla
81 T1567.001 Exfiltration to Code Repository Exfiltration no
82 T1059.006 Python Execution APT29|Rocke|BRONZE BUTLER|APT39|Dragonfly 2.0|Machete Rocke|BRONZE BUTLER|APT39|Dragonfly 2.0|Machete
83 T1059.005 Visual Basic Execution Lazarus Group|APT33|Sandworm Team|Gamaredon Group|Sharpshooter|Molerats|Frankenstein|Inception|APT-C-36|Rancor|Patchwork|MuddyWater|Honeybee|FIN7|APT37|BRONZE BUTLER|APT32|Turla|TA505|Silence|WIRTE|FIN4|Gorgon Group|Cobalt Group|Leviathan|TA459|Magic Hound APT33|Sandworm Team|Gamaredon Group|Sharpshooter|Molerats|Frankenstein|Inception|APT-C-36|Rancor|Patchwork|MuddyWater|Honeybee|FIN7|APT37|BRONZE BUTLER|APT32|Turla|TA505|Silence|WIRTE|FIN4|Cobalt Group|Gorgon Group|Leviathan|TA459|Magic Hound
84 T1059.004 Unix Shell Execution Rocke|APT41
85 T1059.003 Windows Command Shell Execution UNC2452|Wizard Spider|FIN6|TA505|Blue Mockingbird|Tropic Trooper|Frankenstein|OilRig|Lazarus Group|Honeybee|Cobalt Group|FIN7|APT41|Soft Cell|Turla|Silence|APT32|Darkhotel|MuddyWater|APT18|APT38|Gorgon Group|Ke3chang|Dragonfly 2.0|Rancor|Dark Caracal|APT37|APT28|Leviathan|FIN8|Sowbug|Magic Hound|BRONZE BUTLER|menuPass|Threat Group-3390|FIN10|Gamaredon Group|Patchwork|Suckfly|Threat Group-1314|APT3|admin@338|APT1 TA505|Blue Mockingbird|Tropic Trooper|Frankenstein|OilRig|Lazarus Group|Honeybee|Cobalt Group|FIN7|APT41|Soft Cell|Turla|Silence|APT32|APT39|Darkhotel|MuddyWater|APT18|APT38|Dark Caracal|Gorgon Group|Dragonfly 2.0|Rancor|Ke3chang|APT37|Leviathan|FIN8|APT28|Magic Hound|Sowbug|BRONZE BUTLER|FIN10|Threat Group-3390|menuPass|Gamaredon Group|Suckfly|Patchwork|Threat Group-1314|APT3|admin@338|APT1
86 T1059.002 AppleScript Execution no
87 T1059.001 PowerShell Execution UNC2452|Lazarus Group|Chimera|Blue Mockingbird|APT39|DarkVishnya|Molerats|Wizard Spider|Frankenstein|Inception|Silence|APT41|Kimsuky|Soft Cell|TA505|WIRTE|TEMP.Veles|APT33|Gallmaker|Turla|APT19|DarkHydrus|APT28|Gorgon Group|Thrip|Cobalt Group|Dragonfly 2.0|Leviathan|TA459|MuddyWater|FIN8|Magic Hound|CopyKittens|BRONZE BUTLER|OilRig|FIN10|Threat Group-3390|APT32|FIN7|menuPass|Patchwork|Stealth Falcon|FIN6|Poseidon Group|APT3|APT29|Deep Panda Blue Mockingbird|APT39|DarkVishnya|Molerats|Wizard Spider|Frankenstein|Inception|Silence|APT41|Kimsuky|Soft Cell|TA505|WIRTE|TEMP.Veles|APT33|Gallmaker|Turla|APT19|DarkHydrus|APT28|Thrip|Gorgon Group|Cobalt Group|Dragonfly 2.0|Leviathan|TA459|FIN8|MuddyWater|Magic Hound|OilRig|BRONZE BUTLER|CopyKittens|APT32|FIN7|FIN10|Threat Group-3390|menuPass|Patchwork|Stealth Falcon|FIN6|Poseidon Group|APT3|APT29|Deep Panda
88 T1567 Exfiltration Over Web Service Exfiltration no
89 T1497.003 Time Based Evasion Defense Evasion|Discovery no
90 T1497.002 User Activity Based Checks Defense Evasion|Discovery FIN7
91 T1497.001 System Checks Defense Evasion|Discovery Frankenstein
92 T1498.002 Reflection Amplification Impact no
93 T1498.001 Direct Network Flood Impact no
94 T1566.003 Spearphishing via Service Initial Access Lazarus Group|Magic Hound|Windshift|FIN6|OilRig|Dark Caracal Magic Hound|Windshift|FIN6|OilRig|Dark Caracal
95 T1566.002 Spearphishing Link Initial Access Wizard Spider|APT1|Windshift|Molerats|Mofang|BlackTech|Machete|Kimsuky|TA505|Stolen Pencil|APT39|FIN4|APT32|Night Dragon|APT28|Cobalt Group|Dragonfly 2.0|Turla|OilRig|APT33|Leviathan|Patchwork|Elderwood|APT29|Magic Hound|FIN8 Windshift|Molerats|Mofang|BlackTech|Machete|Kimsuky|TA505|Stolen Pencil|APT39|FIN4|APT32|Night Dragon|Turla|APT28|Cobalt Group|Dragonfly 2.0|OilRig|APT33|Elderwood|Leviathan|Magic Hound|Patchwork|APT29|FIN8
96 T1566.001 Spearphishing Attachment Initial Access APT1|FIN6|APT30|Magic Hound|Windshift|APT33|Sandworm Team|Naikon|Gamaredon Group|Sharpshooter|Molerats|Mofang|Wizard Spider|RTM|Frankenstein|Inception|BlackTech|APT-C-36|APT41|Machete|admin@338|Kimsuky|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Tropic Trooper|Turla|Lazarus Group|Cobalt Group|FIN7|OilRig|BRONZE BUTLER|APT32|Gorgon Group|Rancor|DarkHydrus|APT19|Dragonfly 2.0|FIN8|PLATINUM|MuddyWater|TA459|Leviathan|Elderwood|APT29|APT37|menuPass|APT28|Patchwork Magic Hound|Windshift|APT33|Sandworm Team|Naikon|Gamaredon Group|Sharpshooter|Molerats|Mofang|Wizard Spider|RTM|Frankenstein|Inception|BlackTech|APT-C-36|APT41|Machete|admin@338|Kimsuky|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Tropic Trooper|Turla|Gorgon Group|Rancor|DarkHydrus|Cobalt Group|FIN7|OilRig|Lazarus Group|APT19|Dragonfly 2.0|BRONZE BUTLER|APT32|FIN8|MuddyWater|APT28|TA459|Leviathan|Patchwork|PLATINUM|Elderwood|APT29|APT37|menuPass
97 T1566 Phishing Initial Access GOLD SOUTHFIELD|Dragonfly no
98 T1565.003 Runtime Data Manipulation Impact APT38
99 T1565.002 Transmitted Data Manipulation Impact APT38
100 T1565.001 Stored Data Manipulation Impact FIN4|APT38
104 T1563.002 RDP Hijacking Lateral Movement no
105 T1563.001 SSH Hijacking Lateral Movement no
106 T1563 Remote Service Session Hijacking Lateral Movement no
107 T1518.001 Security Software Discovery Discovery Wizard Spider|Turla|Rocke|Frankenstein|The White Company|Cobalt Group|Darkhotel|MuddyWater|Tropic Trooper|FIN8|Patchwork|Naikon Turla|Rocke|Frankenstein|The White Company|Cobalt Group|Darkhotel|MuddyWater|Tropic Trooper|FIN8|Patchwork|Naikon
108 T1069.003 Cloud Groups Discovery no
109 T1069.002 Domain Groups Discovery Turla|Wizard Spider|Inception|OilRig|FIN6|Dragonfly 2.0|Ke3chang
110 T1087.004 Cloud Account Discovery no
111 T1087.003 Email Account Discovery Sandworm Team|TA505
112 T1087.002 Domain Account Discovery Wizard Spider|Chimera|Turla|Sandworm Team|Dragonfly 2.0|OilRig|BRONZE BUTLER|menuPass|FIN6|Poseidon Group|Ke3chang Turla|Sandworm Team|Dragonfly 2.0|OilRig|BRONZE BUTLER|menuPass|FIN6|Poseidon Group|Ke3chang
113 T1087.001 Local Account Discovery Turla|Poseidon Group|OilRig|Ke3chang|APT32|APT1|Threat Group-3390|APT3|admin@338
114 T1553.004 Install Root Certificate Defense Evasion no
115 T1562.004 Disable or Modify System Firewall Defense Evasion UNC2452|Rocke|Lazarus Group|Kimsuky|Dragonfly 2.0|Carbanak Rocke|Lazarus Group|Kimsuky|Dragonfly 2.0|Carbanak
116 T1562.003 Impair Command History Logging HISTCONTROL Defense Evasion no
117 T1562.002 Disable Windows Event Logging Defense Evasion UNC2452|Threat Group-3390 Threat Group-3390
118 T1562.001 Disable or Modify Tools Defense Evasion UNC2452|Wizard Spider|FIN6|Gamaredon Group|BRONZE BUTLER|Rocke|Kimsuky|Turla|Night Dragon|Gorgon Group|Lazarus Group|Putter Panda Gamaredon Group|BRONZE BUTLER|Rocke|Kimsuky|Turla|Night Dragon|Gorgon Group|Lazarus Group|Putter Panda
119 T1562 Impair Defenses Defense Evasion no
120 T1003.004 LSA Secrets Credential Access OilRig|MuddyWater|menuPass|Leafminer|Ke3chang|Dragonfly 2.0|APT33|Threat Group-3390
121 T1003.005 Cached Domain Credentials Credential Access OilRig|MuddyWater|Leafminer|APT33
124 T1561 Disk Wipe Impact no
125 T1560.003 Archive via Custom Method Collection Lazarus Group|Kimsuky|CopyKittens|FIN6
126 T1560.002 Archive via Library Collection Lazarus Group|Threat Group-3390
127 T1560.001 Archive via Utility Collection UNC2452|Chimera|APT41|Soft Cell|Turla|Gallmaker|APT33|APT39|MuddyWater|Magic Hound|FIN8|BRONZE BUTLER|CopyKittens|Sowbug|APT3|menuPass|APT1|Ke3chang APT41|Soft Cell|Turla|Gallmaker|APT33|APT39|MuddyWater|Magic Hound|FIN8|BRONZE BUTLER|CopyKittens|APT3|Sowbug|menuPass|APT1|Ke3chang
128 T1560 Archive Collected Data Collection menuPass|APT32|Patchwork|APT28|Dragonfly 2.0|Honeybee|FIN6|Lazarus Group|Ke3chang menuPass|APT32|Honeybee|Patchwork|APT28|Dragonfly 2.0|FIN6|Lazarus Group|Ke3chang
129 T1499.004 Application or System Exploitation Impact no
130 T1499.003 Application Exhaustion Flood Impact no
131 T1499.002 Service Exhaustion Flood Impact no
133 T1491.002 External Defacement Impact no
134 T1491.001 Internal Defacement Impact Lazarus Group
135 T1114.003 Email Forwarding Rule Collection no
136 T1114.002 Remote Email Collection Collection UNC2452|APT1|FIN4|Ke3chang|Leafminer|Dragonfly 2.0|APT28 APT1|FIN4|APT28|Dragonfly 2.0|Ke3chang|Leafminer
137 T1114.001 Local Email Collection Collection Magic Hound|APT1
138 T1134.005 SID-History Injection Defense Evasion|Privilege Escalation no
139 T1134.004 Parent PID Spoofing Defense Evasion|Privilege Escalation no
142 T1134.001 Token Impersonation/Theft Defense Evasion|Privilege Escalation APT28
143 T1213.002 Sharepoint Collection Ke3chang|APT28
144 T1213.001 Confluence Collection no
145 T1555.003 Credentials from Web Browsers Credential Access FIN6|Magic Hound|Sandworm Team|Inception|Stealth Falcon|OilRig|Leafminer|APT33|APT3|Kimsuky|TA505|Stolen Pencil|MuddyWater|APT37|Patchwork|Molerats Magic Hound|Sandworm Team|Inception|Stealth Falcon|OilRig|Leafminer|APT33|APT3|Kimsuky|TA505|Stolen Pencil|MuddyWater|APT37|Patchwork|Molerats
146 T1555.002 Securityd Memory Credential Access no
147 T1555.001 Keychain Credential Access no
148 T1559.002 Dynamic Data Exchange Execution Sharpshooter|TA505|MuddyWater|Gallmaker|Cobalt Group|Patchwork|APT37|FIN7|APT28 Sharpshooter|TA505|MuddyWater|Gallmaker|Patchwork|Cobalt Group|APT37|APT28|FIN7
149 T1559.001 Component Object Model Execution Gamaredon Group|MuddyWater
150 T1559 Inter-Process Communication Execution no
151 T1558.002 Silver Ticket Credential Access no
152 T1558.001 Golden Ticket Credential Access Ke3chang
153 T1558 Steal or Forge Kerberos Tickets Credential Access no
154 T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay Credential Access|Collection Wizard Spider no
155 T1557 Man-in-the-Middle Credential Access|Collection no
156 T1556.002 Password Filter DLL Credential Access|Defense Evasion Strider
157 T1556.001 Domain Controller Authentication Credential Access|Defense Evasion Chimera no
158 T1556 Modify Authentication Process Credential Access|Defense Evasion no
159 T1056.004 Credential API Hooking Collection|Credential Access PLATINUM
160 T1056.003 Web Portal Capture Collection|Credential Access no
161 T1056.002 GUI Input Capture Collection|Credential Access FIN4
162 T1056.001 Keylogging Collection|Credential Access APT32|Sandworm Team|APT39|APT41|Kimsuky|menuPass|Stolen Pencil|FIN4|APT38|OilRig|Ke3chang|PLATINUM|Sowbug|Magic Hound|Group5|Lazarus Group|Threat Group-3390|APT3|Darkhotel|APT28 APT32|Sandworm Team|APT39|APT41|Kimsuky|menuPass|Stolen Pencil|FIN4|APT38|Ke3chang|OilRig|PLATINUM|Sowbug|Magic Hound|Group5|Lazarus Group|Threat Group-3390|APT3|Darkhotel|APT28
163 T1555 Credentials from Password Stores Credential Access UNC2452|FIN6|APT39|OilRig|MuddyWater|Leafminer|APT33|Turla|Stealth Falcon APT39|OilRig|MuddyWater|Leafminer|APT33|Turla|Stealth Falcon
164 T1552.005 Cloud Instance Metadata API Credential Access no
165 T1003.008 /etc/passwd and /etc/shadow Credential Access no
166 T1003.007 Proc Filesystem Credential Access no
167 T1003.006 DCSync Credential Access UNC2452 no
168 T1558.003 Kerberoasting Credential Access UNC2452|Wizard Spider no
169 T1552.006 Group Policy Preferences Credential Access APT33
170 T1003.003 NTDS Credential Access Wizard Spider|Chimera|FIN6|Dragonfly 2.0 FIN6|Dragonfly 2.0
171 T1003.002 Security Account Manager Credential Access Wizard Spider|Threat Group-3390|Ke3chang|Soft Cell|Night Dragon|Dragonfly 2.0|menuPass Threat Group-3390|Ke3chang|Soft Cell|Night Dragon|Dragonfly 2.0|menuPass
172 T1003.001 LSASS Memory Credential Access Sandworm Team|Whitefly|Blue Mockingbird|Silence|Threat Group-3390|Leviathan|APT41|Soft Cell|TEMP.Veles|APT33|APT39|Stolen Pencil|APT32|Leafminer|Lazarus Group|Magic Hound|MuddyWater|FIN8|PLATINUM|OilRig|BRONZE BUTLER|FIN6|APT3|APT28|APT1|Ke3chang|Cleaver Sandworm Team|Whitefly|Blue Mockingbird|Silence|Threat Group-3390|Leviathan|APT41|Soft Cell|TEMP.Veles|APT33|APT39|Stolen Pencil|APT32|Lazarus Group|Leafminer|Magic Hound|MuddyWater|PLATINUM|FIN8|BRONZE BUTLER|OilRig|FIN6|APT3|APT28|APT1|Ke3chang|Cleaver
173 T1110.004 Credential Stuffing Credential Access no
174 T1110.003 Password Spraying Credential Access APT28|APT33|Leafminer|Lazarus Group APT33|Leafminer|Lazarus Group
175 T1110.002 Password Cracking Credential Access FIN6|APT41|Dragonfly 2.0|APT3 APT41|Dragonfly 2.0|APT3
176 T1110.001 Password Guessing Credential Access APT28 no
177 T1021.006 Windows Remote Management Lateral Movement UNC2452|Wizard Spider|Threat Group-3390 Threat Group-3390
178 T1021.005 VNC Lateral Movement GCMAN
179 T1021.004 SSH Lateral Movement Rocke|TEMP.Veles|Leviathan|APT39|OilRig|menuPass|GCMAN
180 T1021.003 Distributed Component Object Model Lateral Movement no
181 T1021.002 SMB/Windows Admin Shares Lateral Movement Wizard Spider|Chimera|Blue Mockingbird|APT39|APT32|Orangeworm|FIN8|APT3|Lazarus Group|Threat Group-1314|Turla|Deep Panda|Ke3chang Blue Mockingbird|APT39|APT32|Orangeworm|FIN8|APT3|Lazarus Group|Threat Group-1314|Turla|Deep Panda|Ke3chang
182 T1021.001 Remote Desktop Protocol Lateral Movement Chimera|Blue Mockingbird|Wizard Spider|Silence|APT41|TEMP.Veles|Leviathan|APT39|Stolen Pencil|Cobalt Group|Dragonfly 2.0|FIN8|APT3|OilRig|FIN10|menuPass|Patchwork|FIN6|Lazarus Group|APT1|Axiom Blue Mockingbird|Wizard Spider|Silence|APT41|TEMP.Veles|Leviathan|APT39|Stolen Pencil|Cobalt Group|Dragonfly 2.0|FIN8|APT3|OilRig|menuPass|FIN10|Patchwork|FIN6|Lazarus Group|APT1|Axiom
183 T1554 Compromise Client Software Binary Persistence no
184 T1036.006 Space after Filename Defense Evasion no
185 T1036.005 Match Legitimate Name or Location Defense Evasion UNC2452|Chimera|PROMETHIUM|Rocke|Sandworm Team|APT39|Blue Mockingbird|Whitefly|Tropic Trooper|Silence|APT41|menuPass|TEMP.Veles|MuddyWater|BRONZE BUTLER|Sowbug|APT32|Patchwork|Poseidon Group|admin@338|Carbanak|APT1 Rocke|Sandworm Team|APT39|Blue Mockingbird|Whitefly|Tropic Trooper|Silence|APT41|menuPass|TEMP.Veles|MuddyWater|BRONZE BUTLER|Sowbug|APT32|Patchwork|Poseidon Group|admin@338|Carbanak|APT1
186 T1036.004 Masquerade Task or Service Defense Evasion UNC2452|Lazarus Group|PROMETHIUM|Wizard Spider|APT-C-36|Carbanak|APT32|FIN6|FIN7 Wizard Spider|APT-C-36|Carbanak|APT32|FIN6|FIN7
187 T1036.003 Rename System Utilities Defense Evasion menuPass|APT32|Soft Cell|PLATINUM
188 T1036.002 Right-to-Left Override Defense Evasion BRONZE BUTLER|BlackTech|Ke3chang|Scarlet Mimic
189 T1036.001 Invalid Code Signature Defense Evasion Windshift|APT37 Windshift
190 T1553.003 SIP and Trust Provider Hijacking Defense Evasion no
191 T1553.002 Code Signing Defense Evasion UNC2452|Wizard Spider|PROMETHIUM|Patchwork|Silence|APT41|FIN6|TA505|FIN7|Honeybee|Leviathan|CopyKittens|Winnti Group|Suckfly|Molerats|Darkhotel Patchwork|Silence|APT41|FIN6|TA505|FIN7|Honeybee|Leviathan|APT37|CopyKittens|Winnti Group|Suckfly|Molerats|Darkhotel
192 T1553.001 Gatekeeper Bypass Defense Evasion no
193 T1553 Subvert Trust Controls Defense Evasion no
194 T1027.003 Steganography Defense Evasion BRONZE BUTLER|Tropic Trooper|MuddyWater|APT37
195 T1027.002 Software Packing Defense Evasion Lazarus Group|TA505|Rocke|Soft Cell|The White Company|APT39|APT38|Dark Caracal|Elderwood|APT3|Patchwork|APT29|Night Dragon TA505|Rocke|Soft Cell|The White Company|APT39|APT38|Dark Caracal|Elderwood|APT3|Patchwork|APT29|Night Dragon
196 T1027.001 Binary Padding Defense Evasion Gamaredon Group|APT32|Patchwork|Leviathan|BRONZE BUTLER|Moafee Gamaredon Group|Patchwork|APT32|Leviathan|BRONZE BUTLER|Moafee
197 T1222.002 Linux and Mac File and Directory Permissions Modification Defense Evasion Rocke|APT32
198 T1222.001 Windows File and Directory Permissions Modification Defense Evasion Wizard Spider no
199 T1552.004 Private Keys Credential Access UNC2452|Rocke Rocke
200 T1552.003 Bash History Credential Access no
201 T1552.002 Credentials in Registry Credential Access APT32
202 T1552.001 Credentials In Files Credential Access Leafminer|APT33|OilRig|TA505|Stolen Pencil|MuddyWater|APT3
203 T1552 Unsecured Credentials Credential Access no
204 T1216.001 PubPrn Defense Evasion APT32
205 T1070.006 Timestomp Defense Evasion UNC2452|Rocke|TEMP.Veles|APT32|Lazarus Group|APT28 Rocke|TEMP.Veles|APT32|Lazarus Group|APT28
206 T1070.005 Network Share Connection Removal Defense Evasion Threat Group-3390
207 T1070.004 File Deletion Defense Evasion UNC2452|FIN6|Sandworm Team|Rocke|Tropic Trooper|Gamaredon Group|Wizard Spider|APT41|Kimsuky|Silence|The White Company|TEMP.Veles|APT32|APT38|Honeybee|Patchwork|Cobalt Group|Dragonfly 2.0|menuPass|FIN8|BRONZE BUTLER|FIN5|APT3|OilRig|Magic Hound|FIN10|APT28|Threat Group-3390|Group5|Lazarus Group|APT18|APT29 Sandworm Team|Rocke|Tropic Trooper|Gamaredon Group|Wizard Spider|APT41|Kimsuky|Silence|The White Company|TEMP.Veles|APT32|APT38|Patchwork|Honeybee|Cobalt Group|Dragonfly 2.0|menuPass|FIN8|OilRig|FIN5|BRONZE BUTLER|Magic Hound|APT3|FIN10|APT28|Threat Group-3390|Group5|Lazarus Group|APT18|APT29
208 T1070.003 Clear Command History Defense Evasion APT41
209 T1550.004 Web Session Cookie Defense Evasion|Lateral Movement UNC2452 no
210 T1550.001 Application Access Token Defense Evasion|Lateral Movement APT28
211 T1550.003 Pass the Ticket Defense Evasion|Lateral Movement APT32|BRONZE BUTLER|APT29
212 T1550.002 Pass the Hash Defense Evasion|Lateral Movement Soft Cell|APT32|Night Dragon|APT28|APT1
213 T1550 Use Alternate Authentication Material Defense Evasion|Lateral Movement UNC2452 no
214 T1548.004 Elevated Execution with Prompt Privilege Escalation|Defense Evasion no
215 T1548.003 Sudo and Sudo Caching Privilege Escalation|Defense Evasion no
216 T1548.002 Bypass User Account Control Bypass User Access Control Privilege Escalation|Defense Evasion APT37|MuddyWater|Honeybee|Cobalt Group|Threat Group-3390|BRONZE BUTLER|Patchwork|APT29
217 T1548.001 Setuid and Setgid Privilege Escalation|Defense Evasion no
218 T1548 Abuse Elevation Control Mechanism Privilege Escalation|Defense Evasion no
219 T1136.003 Cloud Account Persistence no
220 T1070.002 Clear Linux or Mac System Logs Defense Evasion Rocke
221 T1070.001 Clear Windows Event Logs Defense Evasion APT41|APT38|Dragonfly 2.0|APT32|FIN8|FIN5|APT28
222 T1136.002 Domain Account Persistence Soft Cell
223 T1136.001 Local Account Persistence APT39|APT41|Leafminer|Dragonfly 2.0|APT3 APT39|APT41|Dragonfly 2.0|Leafminer|APT3
224 T1547.011 Plist Modification Persistence|Privilege Escalation no
225 T1547.010 Port Monitors Persistence|Privilege Escalation no
226 T1547.009 Shortcut Modification Persistence|Privilege Escalation APT39|Darkhotel|APT29|Gorgon Group|Dragonfly 2.0|Leviathan|Lazarus Group
227 T1547.008 LSASS Driver Persistence|Privilege Escalation no
228 T1547.007 Re-opened Applications Persistence|Privilege Escalation no
229 T1547.006 Kernel Modules and Extensions Persistence|Privilege Escalation no
230 T1547.005 Security Support Provider Persistence|Privilege Escalation Lazarus Group no
231 T1547.004 Winlogon Helper DLL Persistence|Privilege Escalation Wizard Spider|Tropic Trooper|Turla Tropic Trooper|Turla
232 T1547.003 Time Providers Persistence|Privilege Escalation no
233 T1546.014 Emond Privilege Escalation|Persistence no
234 T1546.013 PowerShell Profile Privilege Escalation|Persistence Turla
244 T1546.006 LC_LOAD_DYLIB Addition Privilege Escalation|Persistence no
245 T1546.005 Trap Privilege Escalation|Persistence no
246 T1546.004 .bash_profile and .bashrc Privilege Escalation|Persistence no
247 T1546.003 Windows Management Instrumentation Event Subscription Privilege Escalation|Persistence UNC2452|APT33|Blue Mockingbird|Turla|Leviathan|APT29 APT33|Blue Mockingbird|Turla|Leviathan|APT29
248 T1546.002 Screensaver Privilege Escalation|Persistence no
249 T1546.001 Change Default File Association Privilege Escalation|Persistence Kimsuky
250 T1547.001 Registry Run Keys / Startup Folder Persistence|Privilege Escalation Wizard Spider|PROMETHIUM|Rocke|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Silence|RTM|Inception|APT41|Machete|Kimsuky|APT33|APT39|APT32|APT18|Turla|Dark Caracal|Cobalt Group|Honeybee|APT19|Ke3chang|Threat Group-3390|Dragonfly 2.0|Gorgon Group|MuddyWater|APT37|Leviathan|BRONZE BUTLER|Magic Hound|APT3|FIN10|FIN7|Patchwork|FIN6|Lazarus Group|Putter Panda|APT29|Darkhotel Rocke|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Silence|RTM|Inception|APT41|Machete|Kimsuky|APT33|APT39|APT32|APT18|Turla|Dark Caracal|Cobalt Group|Honeybee|Threat Group-3390|Dragonfly 2.0|Gorgon Group|Ke3chang|APT19|Leviathan|MuddyWater|APT37|BRONZE BUTLER|Magic Hound|APT3|FIN10|FIN7|Patchwork|FIN6|Lazarus Group|Putter Panda|APT29|Darkhotel
251 T1218.002 Control Panel Defense Evasion no
252 T1218.010 Regsvr32 Defense Evasion Blue Mockingbird|Inception|WIRTE|APT19|Cobalt Group|Leviathan|APT32|Deep Panda Blue Mockingbird|Inception|WIRTE|Cobalt Group|APT19|Leviathan|APT32|Deep Panda
253 T1218.009 Regsvcs/Regasm Defense Evasion no
254 T1218.005 Mshta Defense Evasion Lazarus Group|Inception|Kimsuky|APT32|MuddyWater|FIN7 Inception|Kimsuky|APT32|MuddyWater|FIN7
255 T1218.004 InstallUtil Defense Evasion menuPass no
256 T1218.001 Compiled HTML File Defense Evasion APT41|Silence|OilRig|Lazarus Group|Dark Caracal APT41|Silence|Lazarus Group|Dark Caracal|OilRig
257 T1218.003 CMSTP Defense Evasion Cobalt Group|MuddyWater
258 T1218.011 Rundll32 Defense Evasion UNC2452|Gamaredon Group|APT32|Sandworm Team|Blue Mockingbird|TA505|MuddyWater|APT29|APT19|CopyKittens|APT3|Carbanak|APT28 APT32|Sandworm Team|Blue Mockingbird|TA505|MuddyWater|APT29|APT19|CopyKittens|APT3|Carbanak|APT28
259 T1547 Boot or Logon Autostart Execution Persistence|Privilege Escalation no
260 T1546 Event Triggered Execution Privilege Escalation|Persistence no
261 T1098.003 Add Office 365 Global Administrator Role Persistence no
262 T1098.002 Exchange Email Delegate Permissions Persistence UNC2452|Magic Hound Magic Hound
263 T1098.001 Additional Cloud Credentials Additional Azure Service Principal Credentials Persistence UNC2452 no
264 T1543.004 Launch Daemon Persistence|Privilege Escalation no
265 T1543.003 Windows Service Persistence|Privilege Escalation PROMETHIUM|Blue Mockingbird|DarkVishnya|Wizard Spider|APT32|APT41|Kimsuky|Tropic Trooper|Threat Group-3390|Honeybee|Cobalt Group|Ke3chang|FIN7|APT19|APT3|Lazarus Group|Carbanak Blue Mockingbird|DarkVishnya|Wizard Spider|APT32|APT41|Kimsuky|Tropic Trooper|Cobalt Group|Ke3chang|Honeybee|FIN7|Threat Group-3390|APT19|APT3|Lazarus Group|Carbanak
266 T1543.002 Systemd Service Persistence|Privilege Escalation Rocke
267 T1543.001 Launch Agent Persistence|Privilege Escalation no
268 T1037.005 Startup Items Persistence|Privilege Escalation no
269 T1037.004 Rc.common Persistence|Privilege Escalation no
270 T1055.012 Process Hollowing Defense Evasion|Privilege Escalation menuPass|Gorgon Group|Threat Group-3390|Patchwork Threat Group-3390|menuPass|Gorgon Group|Patchwork
271 T1055.013 Process Doppelgänging Defense Evasion|Privilege Escalation Leafminer
272 T1055.011 Extra Window Memory Injection Defense Evasion|Privilege Escalation no
273 T1055.014 VDSO Hijacking Defense Evasion|Privilege Escalation no
277 T1055.004 Asynchronous Procedure Call Defense Evasion|Privilege Escalation no
278 T1055.003 Thread Execution Hijacking Defense Evasion|Privilege Escalation no
279 T1055.002 Portable Executable Injection Defense Evasion|Privilege Escalation Rocke|Gorgon Group
280 T1055.001 Dynamic-link Library Injection Defense Evasion|Privilege Escalation Wizard Spider|TA505|Turla|Tropic Trooper|Lazarus Group|Putter Panda TA505|Turla|Tropic Trooper|Lazarus Group|Putter Panda
281 T1037.003 Network Logon Script Persistence|Privilege Escalation no
282 T1543 Create or Modify System Process Persistence|Privilege Escalation no
283 T1037.002 Logon Script (Mac) Persistence|Privilege Escalation no
291 T1053.003 Cron Execution|Persistence|Privilege Escalation Rocke
292 T1053.004 Launchd Execution|Persistence|Privilege Escalation no
293 T1053.001 At (Linux) Execution|Persistence|Privilege Escalation no
294 T1053.005 Scheduled Task Execution|Persistence|Privilege Escalation UNC2452|Chimera|Gamaredon Group|Blue Mockingbird|MuddyWater|Wizard Spider|Frankenstein|APT-C-36|BRONZE BUTLER|APT41|Machete|Soft Cell|Silence|TEMP.Veles|APT33|APT39|Cobalt Group|OilRig|Rancor|Dragonfly 2.0|Patchwork|FIN8|FIN7|APT32|menuPass|FIN10|Stealth Falcon|FIN6|APT3|APT29 Gamaredon Group|Blue Mockingbird|MuddyWater|Wizard Spider|Frankenstein|APT-C-36|BRONZE BUTLER|APT41|Machete|Soft Cell|Silence|TEMP.Veles|APT33|APT39|Dragonfly 2.0|Patchwork|OilRig|Rancor|Cobalt Group|FIN8|menuPass|FIN10|APT32|FIN7|Stealth Falcon|FIN6|APT3|APT29
295 T1053.002 At (Windows) Execution|Persistence|Privilege Escalation BRONZE BUTLER|Threat Group-3390|APT18
296 T1542 Pre-OS Boot Defense Evasion|Persistence no
297 T1137.001 Office Template Macros Persistence MuddyWater
316 T1505 Server Software Component Persistence no
317 T1499 Endpoint Denial of Service Impact no
318 T1497 Virtualization/Sandbox Evasion Defense Evasion|Discovery no
319 T1498 Network Denial of Service Impact APT28 no
320 T1496 Resource Hijacking Impact Blue Mockingbird|Rocke|APT41|Lazarus Group
321 T1495 Firmware Corruption Impact no
322 T1491 Defacement Impact no
323 T1490 Inhibit System Recovery Impact no
324 T1489 Service Stop Impact Wizard Spider|Lazarus Group Lazarus Group
325 T1486 Data Encrypted for Impact Impact APT41|TA505|APT38
326 T1485 Data Destruction Impact Sandworm Team|Lazarus Group|APT38
327 T1484 Domain Policy Modification Group Policy Modification Defense Evasion|Privilege Escalation no
328 T1482 Domain Trust Discovery Discovery UNC2452|Wizard Spider Wizard Spider
329 T1480 Execution Guardrails Defense Evasion no
T1220 XSL Script Processing Defense Evasion Cobalt Group
330 T1222 File and Directory Permissions Modification Defense Evasion no
331 T1221 Template Injection Defense Evasion Gamaredon Group|Frankenstein|Inception|APT28|Tropic Trooper|Dragonfly 2.0|DarkHydrus
332 T1203 T1220 Exploitation for Client Execution XSL Script Processing Execution Defense Evasion Sandworm Team|MuddyWater|Frankenstein|Inception|BlackTech|APT41|admin@338|Threat Group-3390|APT12|The White Company|APT33|APT32|APT28|Tropic Trooper|BRONZE BUTLER|Lazarus Group|Cobalt Group|APT29|Patchwork|Leviathan|APT37|Elderwood|TA459 Cobalt Group
T1200 Hardware Additions Initial Access DarkVishnya
T1202 Indirect Command Execution Defense Evasion no
T1213 Data from Information Repositories Collection FIN6|Turla
T1207 Rogue Domain Controller Defense Evasion no
T1204 User Execution Execution no
T1217 Browser Bookmark Discovery Discovery no
T1190 Exploit Public-Facing Application Initial Access UNC2452|APT28|APT29|GOLD SOUTHFIELD|Blue Mockingbird|Rocke|APT39|BlackTech|APT41|Soft Cell|Night Dragon|Axiom
T1210 Exploitation of Remote Services Lateral Movement Wizard Spider|Threat Group-3390|APT28
333 T1197 BITS Jobs Defense Evasion|Persistence Patchwork|APT41|Leviathan
334 T1217 Browser Bookmark Discovery Discovery no
335 T1213 Data from Information Repositories Collection Turla
336 T1189 Drive-by Compromise Initial Access Turla|Windshift|RTM|Darkhotel|APT38|Dragonfly 2.0|BRONZE BUTLER|Leafminer|Dark Caracal|APT19|APT32|Lazarus Group|Threat Group-3390|Elderwood|APT37|Patchwork|PLATINUM
337 T1203 Exploitation for Client Execution Execution Sandworm Team|MuddyWater|Frankenstein|Inception|BlackTech|APT41|admin@338|Threat Group-3390|APT12|The White Company|APT33|APT32|APT28|Tropic Trooper|Lazarus Group|BRONZE BUTLER|Cobalt Group|APT37|Patchwork|Leviathan|Elderwood|TA459|APT29
338 T1212 Exploitation for Credential Access Credential Access no
339 T1211 Exploitation for Defense Evasion Defense Evasion APT28
340 T1190 Exploit Public-Facing Application Initial Access Blue Mockingbird|Rocke|APT39|BlackTech|APT41|Soft Cell|Night Dragon|Axiom
341 T1210 Exploitation of Remote Services Lateral Movement Threat Group-3390|APT28
342 T1202 Indirect Command Execution Defense Evasion no
343 T1200 Hardware Additions Initial Access DarkVishnya
344 T1201 Password Policy Discovery Discovery Turla|OilRig
345 T1219 Remote Access Software Command And Control Sandworm Team|DarkVishnya|RTM|Kimsuky|Night Dragon|Thrip|Cobalt Group|Carbanak
346 T1207 Rogue Domain Controller Defense Evasion no
347 T1199 Trusted Relationship Initial Access APT28|menuPass
348 T1218 Signed Binary Proxy Execution Defense Evasion no
349 T1204 User Execution Execution no
350 T1216 Signed Script Proxy Execution Defense Evasion no
351 T1195 Supply Chain Compromise Initial Access Elderwood
352 T1205 Traffic Signaling Defense Evasion|Persistence|Command And Control no
T1189 Drive-by Compromise Initial Access Dragonfly|PROMETHIUM|Turla|Windshift|RTM|Darkhotel|APT38|Lazarus Group|APT32|Dark Caracal|Dragonfly 2.0|BRONZE BUTLER|Leafminer|APT19|Threat Group-3390|APT37|Patchwork|PLATINUM|Elderwood
T1212 Exploitation for Credential Access Credential Access no
T1219 Remote Access Software Command And Control Sandworm Team|DarkVishnya|RTM|Kimsuky|Night Dragon|Thrip|Cobalt Group|Carbanak
T1211 Exploitation for Defense Evasion Defense Evasion APT28
T1218 Signed Binary Proxy Execution Defense Evasion no
T1216 Signed Script Proxy Execution Defense Evasion no
T1199 Trusted Relationship Initial Access GOLD SOUTHFIELD|APT28|menuPass
353 T1176 Browser Extensions Persistence Kimsuky|Stolen Pencil
354 T1175 Component Object Model and Distributed COM Lateral Movement|Execution no
355 T1187 Forced Authentication Credential Access DarkHydrus|Dragonfly 2.0
356 T1185 Man in the Browser Collection no
357 T1187 T1134 Forced Authentication Access Token Manipulation Credential Access Defense Evasion|Privilege Escalation Dragonfly 2.0|DarkHydrus Blue Mockingbird
T1149 LC_MAIN Hijacking Defense Evasion no
358 T1136 Create Account Persistence no
359 T1134 T1140 Access Token Manipulation Deobfuscate/Decode Files or Information Defense Evasion|Privilege Escalation Defense Evasion FIN6|Blue Mockingbird Rocke|Sandworm Team|Gamaredon Group|Molerats|Frankenstein|Turla|WIRTE|Darkhotel|Tropic Trooper|menuPass|Honeybee|Threat Group-3390|APT19|Gorgon Group|Leviathan|MuddyWater|APT28|OilRig|BRONZE BUTLER
360 T1135 T1149 Network Share Discovery LC_MAIN Hijacking Discovery Defense Evasion Wizard Spider|APT32|APT39|DarkVishnya|APT41|Tropic Trooper|APT1|Dragonfly 2.0|Sowbug no
361 T1140 T1135 Deobfuscate/Decode Files or Information Network Share Discovery Defense Evasion Discovery UNC2452|Rocke|Sandworm Team|Gamaredon Group|Molerats|Frankenstein|Turla|WIRTE|Darkhotel|Tropic Trooper|menuPass|Threat Group-3390|Gorgon Group|APT19|Honeybee|Leviathan|MuddyWater|APT28|OilRig|BRONZE BUTLER APT32|APT39|DarkVishnya|APT41|Tropic Trooper|APT1|Dragonfly 2.0|Sowbug
362 T1137 Office Application Startup Persistence Gamaredon Group|APT32
363 T1153 Source Execution no
364 T1133 External Remote Services Persistence|Initial Access Wizard Spider|GOLD SOUTHFIELD|Chimera|Sandworm Team|APT41|Soft Cell|TEMP.Veles|Night Dragon|Ke3chang|OilRig|Dragonfly 2.0|FIN5|Threat Group-3390|APT18 Sandworm Team|APT41|Soft Cell|TEMP.Veles|Night Dragon|OilRig|Dragonfly 2.0|Ke3chang|FIN5|Threat Group-3390|APT18
365 T1132 Data Encoding Command And Control no
366 T1129 Shared Modules Execution no
367 T1127 Trusted Developer Utilities Proxy Execution Defense Evasion no
369 T1124 System Time Discovery Discovery The White Company|Lazarus Group|BRONZE BUTLER|Turla
370 T1123 Audio Capture Collection APT37
371 T1120 Peripheral Device Discovery Discovery Turla|APT37|Gamaredon Group|Equation|APT28
372 T1119 Automated Collection Collection Gamaredon Group|Tropic Trooper|Frankenstein|APT1|APT28|Patchwork|FIN5|OilRig|Threat Group-3390|FIN6 Tropic Trooper|Frankenstein|APT1|APT28|Patchwork|OilRig|FIN5|Threat Group-3390|FIN6
373 T1115 Clipboard Data Collection APT39|APT38
374 T1114 Email Collection Collection no
375 T1113 Screen Capture Collection Gamaredon Group|APT39|Silence|MuddyWater|OilRig|Dragonfly 2.0|FIN7|Dark Caracal|BRONZE BUTLER|Magic Hound|Group5|APT28 Gamaredon Group|APT39|Silence|MuddyWater|Dragonfly 2.0|OilRig|Dark Caracal|FIN7|BRONZE BUTLER|Magic Hound|Group5|APT28
376 T1112 Modify Registry Defense Evasion Lazarus Group|Gamaredon Group|Blue Mockingbird|Wizard Spider|Silence|APT41|Turla|APT32|APT38|Dragonfly 2.0|Patchwork|APT19|Gorgon Group|Threat Group-3390|Honeybee|FIN8 Gamaredon Group|Blue Mockingbird|Wizard Spider|Silence|APT41|Turla|APT32|APT38|Dragonfly 2.0|APT19|Threat Group-3390|Honeybee|Patchwork|Gorgon Group|FIN8
377 T1111 Two-Factor Authentication Interception Credential Access no
378 T1110 Brute Force Credential Access DarkVishnya|APT39|OilRig|FIN5|Turla
379 T1108 Redundant Access Defense Evasion|Persistence no
380 T1106 Native API Execution Chimera|Gamaredon Group|Tropic Trooper|Sharpshooter|Turla|Silence|APT37|Gorgon Group Gamaredon Group|Tropic Trooper|Sharpshooter|Turla|Silence|Gorgon Group|APT37
381 T1105 Ingress Tool Transfer Command And Control UNC2452|Chimera|Sandworm Team|Whitefly|Rocke|APT39|Tropic Trooper|Sharpshooter|Molerats|Frankenstein|Silence|APT-C-36|APT41|Soft Cell|TA505|WIRTE|APT33|MuddyWater|APT18|APT38|Rancor|OilRig|Dragonfly 2.0|Cobalt Group|Turla|Gorgon Group|APT37|Leviathan|Elderwood|PLATINUM|FIN8|Magic Hound|APT32|APT3|BRONZE BUTLER|menuPass|FIN7|Gamaredon Group|Patchwork|Lazarus Group|Threat Group-3390|APT28 Sandworm Team|Whitefly|Rocke|APT39|Tropic Trooper|Sharpshooter|Molerats|Frankenstein|Silence|APT-C-36|APT41|Soft Cell|TA505|WIRTE|APT33|MuddyWater|APT18|APT38|Rancor|Cobalt Group|Turla|Gorgon Group|OilRig|Dragonfly 2.0|APT37|FIN8|PLATINUM|Leviathan|Elderwood|Magic Hound|APT3|APT32|BRONZE BUTLER|menuPass|FIN7|Gamaredon Group|Patchwork|Lazarus Group|Threat Group-3390|APT28
382 T1104 Multi-Stage Channels Command And Control APT41|MuddyWater|APT3
383 T1102 Web Service Command And Control Chimera|Gamaredon Group|Rocke|Inception|FIN6 Gamaredon Group|Rocke|Inception|FIN6
384 T1098 Account Manipulation Persistence APT3|Dragonfly 2.0|Lazarus Group
385 T1095 Non-Application Layer Protocol Command And Control FIN6|APT29|PLATINUM|APT3 APT29|PLATINUM|APT3
386 T1092 Communication Through Removable Media Command And Control APT28
387 T1091 Replication Through Removable Media Lateral Movement|Initial Access Tropic Trooper|Darkhotel|APT28
388 T1090 Proxy Command And Control Sandworm Team|Blue Mockingbird|APT41|Turla Sandworm Team|Blue Mockingbird|Wizard Spider|APT41|Turla
389 T1087 Account Discovery Discovery UNC2452 no
390 T1083 File and Directory Discovery Discovery UNC2452|Gamaredon Group|Tropic Trooper|Inception|APT41|Kimsuky|APT32|MuddyWater|APT18|Dragonfly 2.0|Leafminer|Honeybee|Dark Caracal|APT3|BRONZE BUTLER|Sowbug|Magic Hound|APT28|Patchwork|Lazarus Group|Dust Storm|admin@338|Turla|Ke3chang Gamaredon Group|Tropic Trooper|Inception|APT41|Kimsuky|APT32|MuddyWater|APT18|Leafminer|Honeybee|Dark Caracal|Dragonfly 2.0|Magic Hound|Sowbug|BRONZE BUTLER|APT3|APT28|Patchwork|Lazarus Group|Dust Storm|admin@338|Turla|Ke3chang
391 T1082 System Information Discovery Discovery UNC2452|Wizard Spider|Rocke|Sandworm Team|Blue Mockingbird|Tropic Trooper|Frankenstein|Inception|Kimsuky|Darkhotel|MuddyWater|APT18|APT37|Honeybee|APT19|APT32|Magic Hound|Sowbug|OilRig|APT3|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|admin@338|Turla|Ke3chang Rocke|Sandworm Team|Blue Mockingbird|Tropic Trooper|Frankenstein|Inception|Kimsuky|Darkhotel|MuddyWater|APT18|Honeybee|APT19|APT37|APT32|Magic Hound|OilRig|APT3|Sowbug|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|admin@338|Turla|Ke3chang
392 T1080 Taint Shared Content Lateral Movement Gamaredon Group|BRONZE BUTLER|Darkhotel BRONZE BUTLER|Darkhotel
393 T1078 Valid Accounts Defense Evasion|Persistence|Privilege Escalation|Initial Access UNC2452|Chimera|Sandworm Team|Wizard Spider|Silence|APT41|Soft Cell|TEMP.Veles|APT39|FIN4|Night Dragon|Dragonfly 2.0|Leviathan|APT33|FIN8|FIN5|OilRig|APT28|FIN10|menuPass|Suckfly|FIN6|Threat Group-3390|APT18|PittyTiger|Carbanak Sandworm Team|Wizard Spider|Silence|APT41|Soft Cell|TEMP.Veles|APT39|FIN4|Night Dragon|Dragonfly 2.0|FIN8|Leviathan|APT33|OilRig|FIN5|menuPass|APT28|FIN10|Suckfly|FIN6|Threat Group-3390|APT18|PittyTiger|Carbanak
394 T1074 Data Staged Collection Wizard Spider
395 T1072 Software Deployment Tools Execution|Lateral Movement Silence|APT32|Threat Group-1314
396 T1071 Application Layer Protocol Command And Control Rocke|Magic Hound|Dragonfly 2.0
397 T1070 Indicator Removal on Host Defense Evasion UNC2452 no
398 T1069 Permission Groups Discovery Discovery UNC2452|TA505|APT3 TA505|APT3
399 T1068 Exploitation for Privilege Escalation Privilege Escalation Whitefly|APT33|Cobalt Group|PLATINUM|FIN8|APT32|Threat Group-3390|FIN6|APT28
400 T1064 Scripting Defense Evasion|Execution no
401 T1062 Hypervisor Persistence no
402 T1061 Graphical User Interface Execution no
403 T1059 Command and Scripting Interpreter Execution APT32|Molerats|Whitefly|APT39|APT19|FIN7|Dragonfly 2.0|OilRig|FIN5|Stealth Falcon|FIN6|Ke3chang APT32|Molerats|Whitefly|Dragonfly 2.0|APT19|FIN7|OilRig|FIN5|Stealth Falcon|FIN6|Ke3chang
404 T1057 Process Discovery Discovery UNC2452|Rocke|Frankenstein|Inception|Darkhotel|MuddyWater|APT1|APT38|Tropic Trooper|APT37|Honeybee|OilRig|APT3|Magic Hound|APT28|Winnti Group|Stealth Falcon|Poseidon Group|Lazarus Group|Molerats|Turla|Deep Panda|Ke3chang Rocke|Frankenstein|Inception|Darkhotel|MuddyWater|APT1|APT38|Tropic Trooper|APT37|Honeybee|OilRig|APT3|Magic Hound|APT28|Winnti Group|Stealth Falcon|Poseidon Group|Lazarus Group|Molerats|Turla|Deep Panda|Ke3chang
405 T1056 Input Capture Collection|Credential Access no
406 T1055 Process Injection Defense Evasion|Privilege Escalation APT32|Sharpshooter|Silence|APT41|Kimsuky|Cobalt Group|APT37|Turla|Honeybee|PLATINUM APT32|Sharpshooter|Silence|APT41|Kimsuky|Turla|Cobalt Group|APT37|Honeybee|PLATINUM
407 T1053 Scheduled Task/Job Execution|Persistence|Privilege Escalation no
408 T1052 Exfiltration Over Physical Medium Exfiltration no
409 T1051 Shared Webroot Lateral Movement no
410 T1049 System Network Connections Discovery Discovery Tropic Trooper|APT41|APT38|Soft Cell|APT32|APT1|OilRig|APT3|Threat Group-3390|menuPass|Poseidon Group|admin@338|Turla|Ke3chang Tropic Trooper|APT41|APT38|Soft Cell|APT32|APT1|OilRig|APT3|menuPass|Threat Group-3390|Poseidon Group|admin@338|Turla|Ke3chang
411 T1048 Exfiltration Over Alternative Protocol Exfiltration no
412 T1047 Windows Management Instrumentation Execution UNC2452|Chimera|Blue Mockingbird|Wizard Spider|Frankenstein|APT41|FIN6|Soft Cell|APT32|MuddyWater|OilRig|Threat Group-3390|FIN8|Leviathan|menuPass|Stealth Falcon|Lazarus Group|APT29|Deep Panda Blue Mockingbird|Wizard Spider|Frankenstein|APT41|FIN6|Soft Cell|APT32|MuddyWater|OilRig|Threat Group-3390|FIN8|Leviathan|menuPass|Stealth Falcon|Lazarus Group|APT29|Deep Panda
413 T1046 Network Service Scanning Discovery Rocke|DarkVishnya|APT41|Tropic Trooper|APT39|APT32|Cobalt Group|Leafminer|OilRig|menuPass|Suckfly|FIN6|Threat Group-3390 Rocke|DarkVishnya|APT41|Tropic Trooper|APT39|APT32|Leafminer|OilRig|Cobalt Group|menuPass|Suckfly|FIN6|Threat Group-3390
414 T1043 Commonly Used Port Command And Control OilRig|APT28|TEMP.Veles|Night Dragon|APT29|APT18|FIN7|Dragonfly 2.0|APT19|FIN8|APT37|APT3|Magic Hound|Lazarus Group|Threat Group-3390 Machete|OilRig|APT28|TEMP.Veles|Night Dragon|APT29|APT18|APT19|Dragonfly 2.0|FIN7|FIN8|APT37|Magic Hound|APT3|Lazarus Group|Threat Group-3390
415 T1041 Exfiltration Over C2 Channel Exfiltration Sandworm Team|MuddyWater|Wizard Spider|Frankenstein|Kimsuky|Soft Cell|APT32|APT3|Gamaredon Group|Stealth Falcon|Lazarus Group|Ke3chang
416 T1040 Network Sniffing Credential Access|Discovery Sandworm Team|DarkVishnya|APT33|Stolen Pencil|APT28
417 T1039 Data from Network Shared Drive Collection Gamaredon Group|BRONZE BUTLER|Sowbug|menuPass Sowbug|BRONZE BUTLER|menuPass
418 T1037 Boot or Logon Initialization Scripts Persistence|Privilege Escalation Rocke
419 T1036 Masquerading Defense Evasion UNC2452|Windshift|APT32|BRONZE BUTLER|menuPass|Dragonfly 2.0 Windshift|APT32|BRONZE BUTLER|menuPass|Dragonfly 2.0
420 T1034 Path Interception Persistence|Privilege Escalation no
421 T1033 System Owner/User Discovery Discovery Wizard Spider|Frankenstein|APT41|Soft Cell|Tropic Trooper|APT39|MuddyWater|APT32|APT37|APT19|Dragonfly 2.0|OilRig|Magic Hound|FIN10|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|APT3 Frankenstein|APT41|Soft Cell|Tropic Trooper|APT39|MuddyWater|APT32|APT37|APT19|Dragonfly 2.0|OilRig|Magic Hound|FIN10|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|APT3
422 T1030 Data Transfer Size Limits Exfiltration Threat Group-3390
423 T1029 Scheduled Transfer Exfiltration no
424 T1027 Obfuscated Files or Information Defense Evasion UNC2452|FIN6|Chimera|Gamaredon Group|Rocke|Sandworm Team|Blue Mockingbird|Whitefly|Molerats|Wizard Spider|Mofang|Frankenstein|Inception|APT-C-36|APT41|Machete|Soft Cell|Turla|TA505|Silence|APT33|Night Dragon|Darkhotel|Gallmaker|APT29|APT18|Tropic Trooper|menuPass|Honeybee|Patchwork|Threat Group-3390|APT19|Cobalt Group|Leafminer|APT37|Dark Caracal|FIN8|MuddyWater|FIN7|BlackOasis|Leviathan|Elderwood|OilRig|Magic Hound|APT3|APT32|Group5|Lazarus Group|Dust Storm|Putter Panda|APT28 Gamaredon Group|Rocke|Sandworm Team|Blue Mockingbird|Whitefly|Molerats|Wizard Spider|Mofang|Frankenstein|Inception|APT-C-36|APT41|Machete|Soft Cell|Turla|TA505|Silence|APT33|Night Dragon|Darkhotel|Gallmaker|APT29|APT18|Tropic Trooper|Cobalt Group|Patchwork|Leafminer|APT37|Threat Group-3390|Honeybee|Dark Caracal|menuPass|APT19|BlackOasis|FIN8|Leviathan|Elderwood|MuddyWater|FIN7|Magic Hound|OilRig|APT3|APT32|Group5|Dust Storm|Lazarus Group|Putter Panda|APT28
425 T1026 Multiband Communication Command And Control Lazarus Group
426 T1025 Data from Removable Media Collection Machete|Turla|Gamaredon Group|APT28
427 T1021 Remote Services Lateral Movement no
428 T1020 Automated Exfiltration Exfiltration Gamaredon Group|Tropic Trooper|Frankenstein|Honeybee Tropic Trooper|Frankenstein|Honeybee
429 T1018 Remote System Discovery Discovery UNC2452|Sandworm Team|Rocke|Wizard Spider|Silence|Soft Cell|APT39|APT32|Threat Group-3390|Dragonfly 2.0|Ke3chang|Leafminer|Deep Panda|FIN8|FIN5|APT3|BRONZE BUTLER|menuPass|FIN6|Turla Sandworm Team|Rocke|Wizard Spider|Silence|Soft Cell|APT39|APT32|Deep Panda|Threat Group-3390|Dragonfly 2.0|Leafminer|Ke3chang|FIN8|APT3|FIN5|BRONZE BUTLER|menuPass|FIN6|Turla
430 T1016 System Network Configuration Discovery Discovery Wizard Spider|Sandworm Team|Tropic Trooper|Frankenstein|APT41|Soft Cell|APT32|Darkhotel|MuddyWater|APT1|Dragonfly 2.0|APT19|OilRig|Magic Hound|menuPass|Threat Group-3390|Stealth Falcon|Lazarus Group|APT3|Naikon|admin@338|Turla|Ke3chang Sandworm Team|Tropic Trooper|Frankenstein|APT41|Soft Cell|APT32|Darkhotel|MuddyWater|APT1|APT19|Dragonfly 2.0|Magic Hound|OilRig|menuPass|Threat Group-3390|Stealth Falcon|Lazarus Group|APT3|Naikon|admin@338|Turla|Ke3chang
431 T1014 Rootkit Defense Evasion Rocke|APT41|APT28|Winnti Group
432 T1012 Query Registry Discovery APT32|Threat Group-3390|Dragonfly 2.0|OilRig|Stealth Falcon|Lazarus Group|Turla APT32|Dragonfly 2.0|Threat Group-3390|OilRig|Stealth Falcon|Lazarus Group|Turla
433 T1011 Exfiltration Over Other Network Medium Exfiltration no
434 T1010 Application Window Discovery Discovery Lazarus Group
435 T1008 Fallback Channels Command And Control APT41|OilRig|Lazarus Group
436 T1007 System Service Discovery Discovery BRONZE BUTLER|APT1|OilRig|Poseidon Group|admin@338|Turla|Ke3chang
437 T1006 Direct Volume Access Defense Evasion no
438 T1005 Data from Local System Collection UNC2452|FIN6|Gamaredon Group|APT39|Frankenstein|Inception|Kimsuky|Soft Cell|Turla|menuPass|Dark Caracal|Dragonfly 2.0|Honeybee|APT28|APT37|APT3|BRONZE BUTLER|Patchwork|Stealth Falcon|Lazarus Group|Dust Storm|Threat Group-3390|APT1|Ke3chang Gamaredon Group|APT39|Frankenstein|Inception|Kimsuky|Soft Cell|Turla|menuPass|Dark Caracal|Dragonfly 2.0|Honeybee|APT37|APT28|APT3|BRONZE BUTLER|Patchwork|Stealth Falcon|Lazarus Group|Dust Storm|Threat Group-3390|APT1|Ke3chang
439 T1003 OS Credential Dumping Credential Access APT39|Frankenstein|APT32|APT28|Leviathan|Sowbug|Suckfly|Poseidon Group|Axiom
440 T1001 Data Obfuscation Command And Control Axiom
+2591 -173
View File
File diff suppressed because it is too large Load Diff
+2452 -180
View File
File diff suppressed because it is too large Load Diff
+28864 -21472
View File
File diff suppressed because it is too large Load Diff
+11968 -7744
View File
File diff suppressed because it is too large Load Diff
+21197 -14509
View File
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+118 -52
View File
@@ -384,8 +384,16 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us
* [Cobalt Strike Named Pipes](detections.md#cobalt-strike-named-pipes)
* [DLLHost with no Command Line Arguments with Network](detections.md#dllhost-with-no-command-line-arguments-with-network)
* [Detect Regsvr32 Application Control Bypass](detections.md#detect-regsvr32-application-control-bypass)
* [GPUpdate with no Command Line Arguments with Network](detections.md#gpupdate-with-no-command-line-arguments-with-network)
* [Rundll32 with no Command Line Arguments with Network](detections.md#rundll32-with-no-command-line-arguments-with-network)
* [SearchProtocolHost with no Command Line with Network](detections.md#searchprotocolhost-with-no-command-line-with-network)
* [Suspicious DLLHost no Command Line Arguments](detections.md#suspicious-dllhost-no-command-line-arguments)
* [Suspicious GPUpdate no Command Line Arguments](detections.md#suspicious-gpupdate-no-command-line-arguments)
@@ -409,9 +417,9 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us
| ----------- | ----------- |--------------|
| T1055 | Process Injection | Defense Evasion, Privilege Escalation |
| T1218.010 | Regsvr32 | Defense Evasion |
| T1218.011 | Rundll32 | Defense Evasion |
| T1127.001 | MSBuild | Defense Evasion |
| T1036.003 | Rename System Utilities | Defense Evasion |
| T1218.011 | Rundll32 | Defense Evasion |
| T1127 | Trusted Developer Utilities Proxy Execution | Defense Evasion |
#### Kill Chain Phase
@@ -628,8 +636,6 @@ Uncover activity consistent with credential dumping, a technique wherein attacke
* [Assessment of Credential Strength via DSInternals modules](detections.md#assessment-of-credential-strength-via-dsinternals-modules)
* [Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass](detections.md#attempt-to-set-default-powershell-execution-policy-to-unrestricted-or-bypass)
* [Attempted Credential Dump From Registry via Reg exe](detections.md#attempted-credential-dump-from-registry-via-reg-exe)
* [Create Remote Thread into LSASS](detections.md#create-remote-thread-into-lsass)
@@ -680,6 +686,8 @@ Uncover activity consistent with credential dumping, a technique wherein attacke
* [Ntdsutil Export NTDS](detections.md#ntdsutil-export-ntds)
* [Set Default PowerShell Execution Policy To Unrestricted or Bypass](detections.md#set-default-powershell-execution-policy-to-unrestricted-or-bypass)
* [Unsigned Image Loaded by LSASS](detections.md#unsigned-image-loaded-by-lsass)
@@ -703,11 +711,11 @@ Uncover activity consistent with credential dumping, a technique wherein attacke
| T1087 | Account Discovery | Discovery |
| T1201 | Password Policy Discovery | Discovery |
| T1552 | Unsecured Credentials | Credential Access |
| T1059.001 | PowerShell | Execution |
| T1003.002 | Security Account Manager | Credential Access |
| T1003 | OS Credential Dumping | Credential Access |
| T1003.003 | NTDS | Credential Access |
| T1558.003 | Kerberoasting | Credential Access |
| T1059.001 | PowerShell | Execution |
#### Kill Chain Phase
@@ -1066,8 +1074,6 @@ HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVE
* [Any Powershell DownloadString](detections.md#any-powershell-downloadstring)
* [Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass](detections.md#attempt-to-set-default-powershell-execution-policy-to-unrestricted-or-bypass)
* [Detect Exchange Web Shell](detections.md#detect-exchange-web-shell)
* [Detect New Local Admin account](detections.md#detect-new-local-admin-account)
@@ -1090,6 +1096,8 @@ HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVE
* [Ntdsutil Export NTDS](detections.md#ntdsutil-export-ntds)
* [Set Default PowerShell Execution Policy To Unrestricted or Bypass](detections.md#set-default-powershell-execution-policy-to-unrestricted-or-bypass)
* [Unified Messaging Service Spawning a Process](detections.md#unified-messaging-service-spawning-a-process)
* [W3WP Spawning Shell](detections.md#w3wp-spawning-shell)
@@ -1265,8 +1273,6 @@ Attackers are finding stealthy ways "live off the land," leveraging utilities an
* [Any Powershell DownloadString](detections.md#any-powershell-downloadstring)
* [Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass](detections.md#attempt-to-set-default-powershell-execution-policy-to-unrestricted-or-bypass)
* [Credential Extraction indicative of use of DSInternals credential conversion modules](detections.md#credential-extraction-indicative-of-use-of-dsinternals-credential-conversion-modules)
* [Credential Extraction indicative of use of DSInternals modules](detections.md#credential-extraction-indicative-of-use-of-dsinternals-modules)
@@ -1289,6 +1295,8 @@ Attackers are finding stealthy ways "live off the land," leveraging utilities an
* [Malicious PowerShell Process With Obfuscation Techniques](detections.md#malicious-powershell-process-with-obfuscation-techniques)
* [Set Default PowerShell Execution Policy To Unrestricted or Bypass](detections.md#set-default-powershell-execution-policy-to-unrestricted-or-bypass)
#### ATT&CK
@@ -1414,48 +1422,6 @@ _version_: 2
---
### Phishing Payloads
Detect signs of malicious payloads that may indicate that your environment has been breached via a phishing attack.
- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- **Datamodel**:
- **ATT&CK**: [T1566.001](https://attack.mitre.org/techniques/T1566.001/), [T1566.002](https://attack.mitre.org/techniques/T1566.002/)
- **Last Updated**: 2019-04-29
<details>
<summary>details</summary>
#### Detection Profile
* [Detect Oulook exe writing a zip file](detections.md#detect-oulook-exe-writing-a--zip-file)
* [Process Creating LNK file in Suspicious Location](detections.md#process-creating-lnk-file-in-suspicious-location)
#### ATT&CK
| ID | Technique | Tactic |
| ----------- | ----------- |--------------|
| T1566.001 | Spearphishing Attachment | Initial Access |
| T1566.002 | Spearphishing Link | Initial Access |
#### Kill Chain Phase
* Actions on Objectives
* Installation
#### Reference
* https://www.fireeye.com/blog/threat-research/2019/04/spear-phishing-campaign-targets-ukraine-government.html
_version_: 1
</details>
---
### Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns
Monitor your environment for suspicious behaviors that resemble the techniques employed by the MUDCARP threat group.
@@ -1588,6 +1554,69 @@ Silver Sparrow, identified by Red Canary Intelligence, is a new forward looking
* https://www.sentinelone.com/blog/5-things-you-need-to-know-about-silver-sparrow/
_version_: 1
</details>
---
### Spearphishing Attachments
Detect signs of malicious payloads that may indicate that your environment has been breached via a phishing attack.
- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- **Datamodel**: Endpoint
- **ATT&CK**: [T1003.002](https://attack.mitre.org/techniques/T1003.002/), [T1566.001](https://attack.mitre.org/techniques/T1566.001/), [T1566.002](https://attack.mitre.org/techniques/T1566.002/)
- **Last Updated**: 2019-04-29
<details>
<summary>details</summary>
#### Detection Profile
* [Detect Outlook exe writing a zip file](detections.md#detect-outlook-exe-writing-a-zip-file)
* [Excel Spawning PowerShell](detections.md#excel-spawning-powershell)
* [Excel Spawning Windows Script Host](detections.md#excel-spawning-windows-script-host)
* [Office Application Spawn rundll32 process](detections.md#office-application-spawn-rundll32-process)
* [Office Document Creating Schedule Task](detections.md#office-document-creating-schedule-task)
* [Office Document Executing Macro Code](detections.md#office-document-executing-macro-code)
* [Office Document Spawned Child Process To Download](detections.md#office-document-spawned-child-process-to-download)
* [Office Product Spawning Rundll32 with no DLL](detections.md#office-product-spawning-rundll32-with-no-dll)
* [Process Creating LNK file in Suspicious Location](detections.md#process-creating-lnk-file-in-suspicious-location)
* [Winword Spawning Cmd](detections.md#winword-spawning-cmd)
* [Winword Spawning PowerShell](detections.md#winword-spawning-powershell)
#### ATT&CK
| ID | Technique | Tactic |
| ----------- | ----------- |--------------|
| T1566.001 | Spearphishing Attachment | Initial Access |
| T1003.002 | Security Account Manager | Credential Access |
| T1566.002 | Spearphishing Link | Initial Access |
#### Kill Chain Phase
* Actions on Objectives
* Exploitation
* Installation
#### Reference
* https://www.fireeye.com/blog/threat-research/2019/04/spear-phishing-campaign-targets-ukraine-government.html
_version_: 1
</details>
@@ -2027,6 +2056,8 @@ Monitor and detect techniques used by attackers who leverage rundll32.exe to exe
* [Dump LSASS via comsvcs DLL](detections.md#dump-lsass-via-comsvcs-dll)
* [Rundll32 with no Command Line Arguments with Network](detections.md#rundll32-with-no-command-line-arguments-with-network)
* [Suspicious Rundll32 Rename](detections.md#suspicious-rundll32-rename)
* [Suspicious Rundll32 StartW](detections.md#suspicious-rundll32-startw)
@@ -2048,6 +2079,8 @@ Monitor and detect techniques used by attackers who leverage rundll32.exe to exe
* Actions on Objectives
* Exploitation
#### Reference
@@ -2643,12 +2676,18 @@ Monitor for activities and techniques associated with maintaining persistence on
* [Setting Credentials via PowerSploit modules](detections.md#setting-credentials-via-powersploit-modules)
* [Shedule Task with HTTP Command Arguments](detections.md#shedule-task-with-http-command-arguments)
* [Shim Database File Creation](detections.md#shim-database-file-creation)
* [Shim Database Installation With Suspicious Parameters](detections.md#shim-database-installation-with-suspicious-parameters)
* [Suspicious Scheduled Task from Public Directory](detections.md#suspicious-scheduled-task-from-public-directory)
* [WinEvent Scheduled Task Created Within Public Path](detections.md#winevent-scheduled-task-created-within-public-path)
* [WinEvent Scheduled Task Created to Spawn Shell](detections.md#winevent-scheduled-task-created-to-spawn-shell)
#### ATT&CK
@@ -3169,7 +3208,7 @@ This analytic story contains detections that query your AWS Cloudtrail for activ
- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- **Datamodel**:
- **ATT&CK**: [T1078.004](https://attack.mitre.org/techniques/T1078.004/), [T1136.003](https://attack.mitre.org/techniques/T1136.003/)
- **ATT&CK**: [T1069.003](https://attack.mitre.org/techniques/T1069.003/), [T1078.004](https://attack.mitre.org/techniques/T1078.004/), [T1098](https://attack.mitre.org/techniques/T1098/), [T1110](https://attack.mitre.org/techniques/T1110/), [T1136.003](https://attack.mitre.org/techniques/T1136.003/), [T1580](https://attack.mitre.org/techniques/T1580/)
- **Last Updated**: 2021-03-08
<details>
@@ -3183,6 +3222,14 @@ This analytic story contains detections that query your AWS Cloudtrail for activ
* [AWS CreateLoginProfile](detections.md#aws-createloginprofile)
* [AWS IAM Assume Role Policy Brute Force](detections.md#aws-iam-assume-role-policy-brute-force)
* [AWS IAM Delete Policy](detections.md#aws-iam-delete-policy)
* [AWS IAM Failure Group Deletion](detections.md#aws-iam-failure-group-deletion)
* [AWS IAM Successful Group Deletion](detections.md#aws-iam-successful-group-deletion)
* [AWS SetDefaultPolicyVersion](detections.md#aws-setdefaultpolicyversion)
* [AWS UpdateLoginProfile](detections.md#aws-updateloginprofile)
@@ -3194,11 +3241,17 @@ This analytic story contains detections that query your AWS Cloudtrail for activ
| ----------- | ----------- |--------------|
| T1078.004 | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation |
| T1136.003 | Cloud Account | Persistence |
| T1580 | Cloud Infrastructure Discovery | Discovery |
| T1110 | Brute Force | Credential Access |
| T1098 | Account Manipulation | Persistence |
| T1069.003 | Cloud Groups | Discovery |
#### Kill Chain Phase
* Actions on Objectives
* Reconnaissance
#### Reference
@@ -4116,7 +4169,7 @@ Detect and investigate suspicious activities by users and roles in your cloud en
- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- **Datamodel**: Change
- **ATT&CK**: [T1078](https://attack.mitre.org/techniques/T1078/), [T1078.004](https://attack.mitre.org/techniques/T1078.004/)
- **ATT&CK**: [T1078](https://attack.mitre.org/techniques/T1078/), [T1078.004](https://attack.mitre.org/techniques/T1078.004/), [T1580](https://attack.mitre.org/techniques/T1580/)
- **Last Updated**: 2020-09-04
<details>
@@ -4124,6 +4177,8 @@ Detect and investigate suspicious activities by users and roles in your cloud en
#### Detection Profile
* [AWS IAM AccessDenied Discovery Events](detections.md#aws-iam-accessdenied-discovery-events)
* [Abnormally High Number Of Cloud Infrastructure API Calls](detections.md#abnormally-high-number-of-cloud-infrastructure-api-calls)
* [Abnormally High Number Of Cloud Security Group API Calls](detections.md#abnormally-high-number-of-cloud-security-group-api-calls)
@@ -4135,6 +4190,7 @@ Detect and investigate suspicious activities by users and roles in your cloud en
| ID | Technique | Tactic |
| ----------- | ----------- |--------------|
| T1580 | Cloud Infrastructure Discovery | Discovery |
| T1078.004 | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation |
| T1078 | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation |
@@ -4142,6 +4198,8 @@ Detect and investigate suspicious activities by users and roles in your cloud en
* Actions on Objectives
* Reconnaissance
#### Reference
@@ -4729,6 +4787,10 @@ Leverage searches that allow you to detect and investigate unusual activities th
* [WBAdmin Delete System Backups](detections.md#wbadmin-delete-system-backups)
* [WinEvent Scheduled Task Created Within Public Path](detections.md#winevent-scheduled-task-created-within-public-path)
* [WinEvent Scheduled Task Created to Spawn Shell](detections.md#winevent-scheduled-task-created-to-spawn-shell)
* [Windows Event Log Cleared](detections.md#windows-event-log-cleared)
@@ -4855,6 +4917,10 @@ Leverage searches that allow you to detect and investigate unusual activities th
* [WBAdmin Delete System Backups](detections.md#wbadmin-delete-system-backups)
* [WinEvent Scheduled Task Created Within Public Path](detections.md#winevent-scheduled-task-created-within-public-path)
* [WinEvent Scheduled Task Created to Spawn Shell](detections.md#winevent-scheduled-task-created-to-spawn-shell)
* [Windows DisableAntiSpyware Registry](detections.md#windows-disableantispyware-registry)
* [Windows Security Account Manager Stopped](detections.md#windows-security-account-manager-stopped)
+156 -72
View File
@@ -455,7 +455,7 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us
* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
* '''Datamodel''': Endpoint
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1218.010/ T1218.010], [https://attack.mitre.org/techniques/T1127.001/ T1127.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003], [https://attack.mitre.org/techniques/T1218.011/ T1218.011], [https://attack.mitre.org/techniques/T1127/ T1127]
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1218.010/ T1218.010], [https://attack.mitre.org/techniques/T1218.011/ T1218.011], [https://attack.mitre.org/techniques/T1127.001/ T1127.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003], [https://attack.mitre.org/techniques/T1127/ T1127]
* '''Last Updated''': 2021-02-16
<div class="toccolours mw-collapsible mw-collapsed">
@@ -465,8 +465,16 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us
* [[Documentation:ESSOC:detections:Detections#Cobalt_strike_named_pipes|Cobalt Strike Named Pipes]]
* [[Documentation:ESSOC:detections:Detections#Dllhost_with_no_command_line_arguments_with_network|DLLHost with no Command Line Arguments with Network]]
* [[Documentation:ESSOC:detections:Detections#Detect_regsvr32_application_control_bypass|Detect Regsvr32 Application Control Bypass]]
* [[Documentation:ESSOC:detections:Detections#Gpupdate_with_no_command_line_arguments_with_network|GPUpdate with no Command Line Arguments with Network]]
* [[Documentation:ESSOC:detections:Detections#Rundll32_with_no_command_line_arguments_with_network|Rundll32 with no Command Line Arguments with Network]]
* [[Documentation:ESSOC:detections:Detections#Searchprotocolhost_with_no_command_line_with_network|SearchProtocolHost with no Command Line with Network]]
* [[Documentation:ESSOC:detections:Detections#Suspicious_dllhost_no_command_line_arguments|Suspicious DLLHost no Command Line Arguments]]
* [[Documentation:ESSOC:detections:Detections#Suspicious_gpupdate_no_command_line_arguments|Suspicious GPUpdate no Command Line Arguments]]
@@ -499,6 +507,10 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us
| Regsvr32
| Defense Evasion
|-
| T1218.011
| Rundll32
| Defense Evasion
|-
| T1127.001
| MSBuild
| Defense Evasion
@@ -507,10 +519,6 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us
| Rename System Utilities
| Defense Evasion
|-
| T1218.011
| Rundll32
| Defense Evasion
|-
| T1127
| Trusted Developer Utilities Proxy Execution
| Defense Evasion
@@ -761,7 +769,7 @@ Uncover activity consistent with credential dumping, a technique wherein attacke
* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
* '''Datamodel''': Endpoint
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003.001/ T1003.001], [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1134/ T1134], [https://attack.mitre.org/techniques/T1543/ T1543], [https://attack.mitre.org/techniques/T1547/ T1547], [https://attack.mitre.org/techniques/T1548/ T1548], [https://attack.mitre.org/techniques/T1554/ T1554], [https://attack.mitre.org/techniques/T1556/ T1556], [https://attack.mitre.org/techniques/T1558/ T1558], [https://attack.mitre.org/techniques/T1555/ T1555], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1201/ T1201], [https://attack.mitre.org/techniques/T1552/ T1552], [https://attack.mitre.org/techniques/T1059.001/ T1059.001], [https://attack.mitre.org/techniques/T1003.002/ T1003.002], [https://attack.mitre.org/techniques/T1003/ T1003], [https://attack.mitre.org/techniques/T1003.003/ T1003.003], [https://attack.mitre.org/techniques/T1558.003/ T1558.003]
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003.001/ T1003.001], [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1134/ T1134], [https://attack.mitre.org/techniques/T1543/ T1543], [https://attack.mitre.org/techniques/T1547/ T1547], [https://attack.mitre.org/techniques/T1548/ T1548], [https://attack.mitre.org/techniques/T1554/ T1554], [https://attack.mitre.org/techniques/T1556/ T1556], [https://attack.mitre.org/techniques/T1558/ T1558], [https://attack.mitre.org/techniques/T1555/ T1555], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1201/ T1201], [https://attack.mitre.org/techniques/T1552/ T1552], [https://attack.mitre.org/techniques/T1003.002/ T1003.002], [https://attack.mitre.org/techniques/T1003/ T1003], [https://attack.mitre.org/techniques/T1003.003/ T1003.003], [https://attack.mitre.org/techniques/T1558.003/ T1558.003], [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
* '''Last Updated''': 2020-02-04
<div class="toccolours mw-collapsible mw-collapsed">
@@ -777,8 +785,6 @@ Uncover activity consistent with credential dumping, a technique wherein attacke
* [[Documentation:ESSOC:detections:Detections#Assessment_of_credential_strength_via_dsinternals_modules|Assessment of Credential Strength via DSInternals modules]]
* [[Documentation:ESSOC:detections:Detections#Attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass|Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass]]
* [[Documentation:ESSOC:detections:Detections#Attempted_credential_dump_from_registry_via_reg_exe|Attempted Credential Dump From Registry via Reg exe]]
* [[Documentation:ESSOC:detections:Detections#Create_remote_thread_into_lsass|Create Remote Thread into LSASS]]
@@ -829,6 +835,8 @@ Uncover activity consistent with credential dumping, a technique wherein attacke
* [[Documentation:ESSOC:detections:Detections#Ntdsutil_export_ntds|Ntdsutil Export NTDS]]
* [[Documentation:ESSOC:detections:Detections#Set_default_powershell_execution_policy_to_unrestricted_or_bypass|Set Default PowerShell Execution Policy To Unrestricted or Bypass]]
* [[Documentation:ESSOC:detections:Detections#Unsigned_image_loaded_by_lsass|Unsigned Image Loaded by LSASS]]
@@ -903,10 +911,6 @@ Uncover activity consistent with credential dumping, a technique wherein attacke
| Unsecured Credentials
| Credential Access
|-
| T1059.001
| PowerShell
| Execution
|-
| T1003.002
| Security Account Manager
| Credential Access
@@ -922,6 +926,10 @@ Uncover activity consistent with credential dumping, a technique wherein attacke
| T1558.003
| Kerberoasting
| Credential Access
|-
| T1059.001
| PowerShell
| Execution
|}
@@ -1375,8 +1383,6 @@ HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVE
* [[Documentation:ESSOC:detections:Detections#Any_powershell_downloadstring|Any Powershell DownloadString]]
* [[Documentation:ESSOC:detections:Detections#Attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass|Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass]]
* [[Documentation:ESSOC:detections:Detections#Detect_exchange_web_shell|Detect Exchange Web Shell]]
* [[Documentation:ESSOC:detections:Detections#Detect_new_local_admin_account|Detect New Local Admin account]]
@@ -1399,6 +1405,8 @@ HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVE
* [[Documentation:ESSOC:detections:Detections#Ntdsutil_export_ntds|Ntdsutil Export NTDS]]
* [[Documentation:ESSOC:detections:Detections#Set_default_powershell_execution_policy_to_unrestricted_or_bypass|Set Default PowerShell Execution Policy To Unrestricted or Bypass]]
* [[Documentation:ESSOC:detections:Detections#Unified_messaging_service_spawning_a_process|Unified Messaging Service Spawning a Process]]
* [[Documentation:ESSOC:detections:Detections#W3wp_spawning_shell|W3WP Spawning Shell]]
@@ -1670,8 +1678,6 @@ Attackers are finding stealthy ways "live off the land," leveraging utilities an
* [[Documentation:ESSOC:detections:Detections#Any_powershell_downloadstring|Any Powershell DownloadString]]
* [[Documentation:ESSOC:detections:Detections#Attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass|Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass]]
* [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules|Credential Extraction indicative of use of DSInternals credential conversion modules]]
* [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_use_of_dsinternals_modules|Credential Extraction indicative of use of DSInternals modules]]
@@ -1694,6 +1700,8 @@ Attackers are finding stealthy ways "live off the land," leveraging utilities an
* [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_with_obfuscation_techniques|Malicious PowerShell Process With Obfuscation Techniques]]
* [[Documentation:ESSOC:detections:Detections#Set_default_powershell_execution_policy_to_unrestricted_or_bypass|Set Default PowerShell Execution Policy To Unrestricted or Bypass]]
====ATT&CK====
@@ -1907,59 +1915,6 @@ Sunburst is a trojanized updates to SolarWinds Orion IT monitoring and managemen
----
===Phishing payloads===
Detect signs of malicious payloads that may indicate that your environment has been breached via a phishing attack.
* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
* '''Datamodel''':
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566.001/ T1566.001], [https://attack.mitre.org/techniques/T1566.002/ T1566.002]
* '''Last Updated''': 2019-04-29
<div class="toccolours mw-collapsible mw-collapsed">
<div class="mw-collapsible-content">
====Detection Profile====
* [[Documentation:ESSOC:detections:Detections#Detect_oulook_exe_writing_a__zip_file|Detect Oulook exe writing a zip file]]
* [[Documentation:ESSOC:detections:Detections#Process_creating_lnk_file_in_suspicious_location|Process Creating LNK file in Suspicious Location]]
====ATT&CK====
{|
! style="text-align:left;"| ID
! Technique
! Tactic
|-
| T1566.001
| Spearphishing Attachment
| Initial Access
|-
| T1566.002
| Spearphishing Link
| Initial Access
|}
====Kill Chain Phase====
* Actions on Objectives
* Installation
====Reference====
* https://www.fireeye.com/blog/threat-research/2019/04/spear-phishing-campaign-targets-ukraine-government.html
''version'': 1
</div>
</div>
----
===Possible backdoor activity associated with mudcarp espionage campaigns===
Monitor your environment for suspicious behaviors that resemble the techniques employed by the MUDCARP threat group.
@@ -2127,6 +2082,83 @@ Silver Sparrow, identified by Red Canary Intelligence, is a new forward looking
* https://www.sentinelone.com/blog/5-things-you-need-to-know-about-silver-sparrow/
''version'': 1
</div>
</div>
----
===Spearphishing attachments===
Detect signs of malicious payloads that may indicate that your environment has been breached via a phishing attack.
* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
* '''Datamodel''': Endpoint
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566.001/ T1566.001], [https://attack.mitre.org/techniques/T1003.002/ T1003.002], [https://attack.mitre.org/techniques/T1566.002/ T1566.002]
* '''Last Updated''': 2019-04-29
<div class="toccolours mw-collapsible mw-collapsed">
<div class="mw-collapsible-content">
====Detection Profile====
* [[Documentation:ESSOC:detections:Detections#Detect_outlook_exe_writing_a_zip_file|Detect Outlook exe writing a zip file]]
* [[Documentation:ESSOC:detections:Detections#Excel_spawning_powershell|Excel Spawning PowerShell]]
* [[Documentation:ESSOC:detections:Detections#Excel_spawning_windows_script_host|Excel Spawning Windows Script Host]]
* [[Documentation:ESSOC:detections:Detections#Office_application_spawn_rundll32_process|Office Application Spawn rundll32 process]]
* [[Documentation:ESSOC:detections:Detections#Office_document_creating_schedule_task|Office Document Creating Schedule Task]]
* [[Documentation:ESSOC:detections:Detections#Office_document_executing_macro_code|Office Document Executing Macro Code]]
* [[Documentation:ESSOC:detections:Detections#Office_document_spawned_child_process_to_download|Office Document Spawned Child Process To Download]]
* [[Documentation:ESSOC:detections:Detections#Office_product_spawning_rundll32_with_no_dll|Office Product Spawning Rundll32 with no DLL]]
* [[Documentation:ESSOC:detections:Detections#Process_creating_lnk_file_in_suspicious_location|Process Creating LNK file in Suspicious Location]]
* [[Documentation:ESSOC:detections:Detections#Winword_spawning_cmd|Winword Spawning Cmd]]
* [[Documentation:ESSOC:detections:Detections#Winword_spawning_powershell|Winword Spawning PowerShell]]
====ATT&CK====
{|
! style="text-align:left;"| ID
! Technique
! Tactic
|-
| T1566.001
| Spearphishing Attachment
| Initial Access
|-
| T1003.002
| Security Account Manager
| Credential Access
|-
| T1566.002
| Spearphishing Link
| Initial Access
|}
====Kill Chain Phase====
* Actions on Objectives
* Exploitation
* Installation
====Reference====
* https://www.fireeye.com/blog/threat-research/2019/04/spear-phishing-campaign-targets-ukraine-government.html
''version'': 1
</div>
</div>
@@ -2670,6 +2702,8 @@ Monitor and detect techniques used by attackers who leverage rundll32.exe to exe
* [[Documentation:ESSOC:detections:Detections#Dump_lsass_via_comsvcs_dll|Dump LSASS via comsvcs DLL]]
* [[Documentation:ESSOC:detections:Detections#Rundll32_with_no_command_line_arguments_with_network|Rundll32 with no Command Line Arguments with Network]]
* [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_rename|Suspicious Rundll32 Rename]]
* [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_startw|Suspicious Rundll32 StartW]]
@@ -2704,6 +2738,8 @@ Monitor and detect techniques used by attackers who leverage rundll32.exe to exe
* Actions on Objectives
* Exploitation
====Reference====
@@ -3522,12 +3558,18 @@ Monitor for activities and techniques associated with maintaining persistence on
* [[Documentation:ESSOC:detections:Detections#Setting_credentials_via_powersploit_modules|Setting Credentials via PowerSploit modules]]
* [[Documentation:ESSOC:detections:Detections#Shedule_task_with_http_command_arguments|Shedule Task with HTTP Command Arguments]]
* [[Documentation:ESSOC:detections:Detections#Shim_database_file_creation|Shim Database File Creation]]
* [[Documentation:ESSOC:detections:Detections#Shim_database_installation_with_suspicious_parameters|Shim Database Installation With Suspicious Parameters]]
* [[Documentation:ESSOC:detections:Detections#Suspicious_scheduled_task_from_public_directory|Suspicious Scheduled Task from Public Directory]]
* [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_within_public_path|WinEvent Scheduled Task Created Within Public Path]]
* [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_to_spawn_shell|WinEvent Scheduled Task Created to Spawn Shell]]
====ATT&CK====
@@ -4186,7 +4228,7 @@ This analytic story contains detections that query your AWS Cloudtrail for activ
* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
* '''Datamodel''':
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.004/ T1078.004], [https://attack.mitre.org/techniques/T1136.003/ T1136.003]
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.004/ T1078.004], [https://attack.mitre.org/techniques/T1136.003/ T1136.003], [https://attack.mitre.org/techniques/T1580/ T1580], [https://attack.mitre.org/techniques/T1110/ T1110], [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1069.003/ T1069.003]
* '''Last Updated''': 2021-03-08
<div class="toccolours mw-collapsible mw-collapsed">
@@ -4200,6 +4242,14 @@ This analytic story contains detections that query your AWS Cloudtrail for activ
* [[Documentation:ESSOC:detections:Detections#Aws_createloginprofile|AWS CreateLoginProfile]]
* [[Documentation:ESSOC:detections:Detections#Aws_iam_assume_role_policy_brute_force|AWS IAM Assume Role Policy Brute Force]]
* [[Documentation:ESSOC:detections:Detections#Aws_iam_delete_policy|AWS IAM Delete Policy]]
* [[Documentation:ESSOC:detections:Detections#Aws_iam_failure_group_deletion|AWS IAM Failure Group Deletion]]
* [[Documentation:ESSOC:detections:Detections#Aws_iam_successful_group_deletion|AWS IAM Successful Group Deletion]]
* [[Documentation:ESSOC:detections:Detections#Aws_setdefaultpolicyversion|AWS SetDefaultPolicyVersion]]
* [[Documentation:ESSOC:detections:Detections#Aws_updateloginprofile|AWS UpdateLoginProfile]]
@@ -4219,6 +4269,22 @@ This analytic story contains detections that query your AWS Cloudtrail for activ
| T1136.003
| Cloud Account
| Persistence
|-
| T1580
| Cloud Infrastructure Discovery
| Discovery
|-
| T1110
| Brute Force
| Credential Access
|-
| T1098
| Account Manipulation
| Persistence
|-
| T1069.003
| Cloud Groups
| Discovery
|}
@@ -4226,6 +4292,8 @@ This analytic story contains detections that query your AWS Cloudtrail for activ
* Actions on Objectives
* Reconnaissance
====Reference====
@@ -5304,7 +5372,7 @@ Detect and investigate suspicious activities by users and roles in your cloud en
* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
* '''Datamodel''': Change
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.004/ T1078.004], [https://attack.mitre.org/techniques/T1078/ T1078]
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1580/ T1580], [https://attack.mitre.org/techniques/T1078.004/ T1078.004], [https://attack.mitre.org/techniques/T1078/ T1078]
* '''Last Updated''': 2020-09-04
<div class="toccolours mw-collapsible mw-collapsed">
@@ -5312,6 +5380,8 @@ Detect and investigate suspicious activities by users and roles in your cloud en
====Detection Profile====
* [[Documentation:ESSOC:detections:Detections#Aws_iam_accessdenied_discovery_events|AWS IAM AccessDenied Discovery Events]]
* [[Documentation:ESSOC:detections:Detections#Abnormally_high_number_of_cloud_infrastructure_api_calls|Abnormally High Number Of Cloud Infrastructure API Calls]]
* [[Documentation:ESSOC:detections:Detections#Abnormally_high_number_of_cloud_security_group_api_calls|Abnormally High Number Of Cloud Security Group API Calls]]
@@ -5326,6 +5396,10 @@ Detect and investigate suspicious activities by users and roles in your cloud en
! Technique
! Tactic
|-
| T1580
| Cloud Infrastructure Discovery
| Discovery
|-
| T1078.004
| Cloud Accounts
| Defense Evasion, Initial Access, Persistence, Privilege Escalation
@@ -5340,6 +5414,8 @@ Detect and investigate suspicious activities by users and roles in your cloud en
* Actions on Objectives
* Reconnaissance
====Reference====
@@ -6106,6 +6182,10 @@ Leverage searches that allow you to detect and investigate unusual activities th
* [[Documentation:ESSOC:detections:Detections#Wbadmin_delete_system_backups|WBAdmin Delete System Backups]]
* [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_within_public_path|WinEvent Scheduled Task Created Within Public Path]]
* [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_to_spawn_shell|WinEvent Scheduled Task Created to Spawn Shell]]
* [[Documentation:ESSOC:detections:Detections#Windows_event_log_cleared|Windows Event Log Cleared]]
@@ -6296,6 +6376,10 @@ Leverage searches that allow you to detect and investigate unusual activities th
* [[Documentation:ESSOC:detections:Detections#Wbadmin_delete_system_backups|WBAdmin Delete System Backups]]
* [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_within_public_path|WinEvent Scheduled Task Created Within Public Path]]
* [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_to_spawn_shell|WinEvent Scheduled Task Created to Spawn Shell]]
* [[Documentation:ESSOC:detections:Detections#Windows_disableantispyware_registry|Windows DisableAntiSpyware Registry]]
* [[Documentation:ESSOC:detections:Detections#Windows_security_account_manager_stopped|Windows Security Account Manager Stopped]]
@@ -6997,7 +7081,7 @@ Reduce the risk of CVE-2018-11409, an information disclosure vulnerability withi
''
#############
# Automatically generated by doc_gen.py in https://github.com/splunk/security_content
# On Date: 2021-04-15 19:33:38.229931 UTC
# On Date: 2021-04-22 21:48:48.069505 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -1,12 +0,0 @@
name: First Time Seen Child Process of Zoom Unit Test
tests:
- name: First Time Seen Child Process of Zoom
file: endpoint/first_time_seen_child_process_of_zoom.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/zoom_child_process/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -1,12 +0,0 @@
name: IPv6 Network Infrastructure Threats
tests:
- name: Detect IPv6 Network Infrastructure Threats
file: experimental/network/detect_ipv6_network_infrastructure_threats.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: cisco_ios.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1557.002/cisco_ios/cisco_ios.log
source: udp:514
sourcetype: cisco:ios
@@ -1,12 +0,0 @@
name: Detect SNICat SNI Exfiltration Unit Test
tests:
- name: Detect SNICat SNI Exfiltration
file: experimental/network/detect_snicat_sni_exfiltration.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: zeek-ssl.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1041/zeek_ssl/zeek_ssl.log
source: zeek-ssl.log
sourcetype: bro:ssl:json