diff --git a/docs/mitre-map/coverage.json b/docs/mitre-map/coverage.json index d5a3ab5dbb..0a74927670 100644 --- a/docs/mitre-map/coverage.json +++ b/docs/mitre-map/coverage.json @@ -6,13 +6,13 @@ "techniques": [ { "techniqueID": "T1059", - "score": 64, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/detect_risky_spl_using_pretrained_ml_model.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_command_and_scripting_interpreter_delete_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_command_and_scripting_interpreter_risky_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_command_and_scripting_interpreter_risky_spl_mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_certify_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_suspicious_processnames_using_pretrained_model_in_dsdl.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_distinct_processes_from_windows_temp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/exchange_powershell_module_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_unix_shell_enable_all_sysrq_functions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/living_off_the_land.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/log4shell_cve_2021_44228_exploitation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/macos_lolbin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_com_hijacking_inprocserver32_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_powershell_remoting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_load_module_in_meterpreter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_apache_benchmark_binary.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_and_scripting_interpreter_hunting_path_traversal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_and_scripting_interpreter_path_traversal_exec.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_common_abused_cmd_shell_risk_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_identify_protocol_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msexchange_management_mailbox_cmdlet_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_papercut_ng_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_cryptography_namespace.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_import_applocker_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_remotesigned_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_scheduletask.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_wmi_win32_scheduledjob.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_scheduled_task_service_spawned_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/juniper_networks_remote_code_execution_exploit_detection.yml" + "score": 69, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/detect_risky_spl_using_pretrained_ml_model.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_command_and_scripting_interpreter_delete_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_command_and_scripting_interpreter_risky_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_command_and_scripting_interpreter_risky_spl_mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_certify_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_suspicious_processnames_using_pretrained_model_in_dsdl.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_distinct_processes_from_windows_temp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/exchange_powershell_module_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_unix_shell_enable_all_sysrq_functions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/living_off_the_land.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/log4shell_cve_2021_44228_exploitation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/macos_lolbin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_com_hijacking_inprocserver32_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_powershell_remoting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_load_module_in_meterpreter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_apache_benchmark_binary.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_autoit3_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_and_scripting_interpreter_hunting_path_traversal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_and_scripting_interpreter_path_traversal_exec.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_common_abused_cmd_shell_risk_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_asr_audit_events.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_asr_block_events.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_asr_rules_stacking.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_identify_protocol_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msexchange_management_mailbox_cmdlet_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_papercut_ng_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_cryptography_namespace.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_import_applocker_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_remotesigned_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_scheduletask.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_wmi_win32_scheduledjob.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_scheduled_task_service_spawned_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_windbg_spawning_autoit3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/juniper_networks_remote_code_execution_exploit_detection.yml" }, { "techniqueID": "T1114", - "score": 8, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/email_files_written_outside_of_the_outlook_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml" + "score": 10, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/email_files_written_outside_of_the_outlook_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_mailbox_inbox_folder_shared_with_all_users.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_mailbox_read_access_granted_to_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml" }, { "techniqueID": "T1114.001", @@ -21,13 +21,13 @@ }, { "techniqueID": "T1114.002", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_mailbox_inbox_folder_shared_with_all_users.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_mailbox_read_access_granted_to_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml" }, { "techniqueID": "T1078", - "score": 55, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_account_lockout_events.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_failed_sso_attempts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_new_api_token_created.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_new_device_enrolled_on_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_phishing_detection_with_fastpass_origin_check.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_risk_threshold_exceeded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_suspicious_activity_reported.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_threatinsight_login_failure_with_high_unknown_users.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_threatinsight_suspected_passwordspray_attack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_threatinsight_threat_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_user_logins_from_multiple_cities.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_user_enumeration_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_attach_to_role_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_permanent_key_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_role_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_sts_assume_role_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_powershell_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_runbook_webhook_created.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_detect_gcploit_framework.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_computer_account_name_change.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_kerberos_service_ticket_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_ticket_granting_ticket_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unusual_number_of_computer_service_tickets_requested.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unusual_number_of_remote_endpoint_authentication_events.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_large_number_of_computer_service_tickets_requested.yml" + "score": 58, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_account_lockout_events.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_failed_sso_attempts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_new_api_token_created.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_new_device_enrolled_on_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_phishing_detection_with_fastpass_origin_check.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_risk_threshold_exceeded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_suspicious_activity_reported.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_threatinsight_login_failure_with_high_unknown_users.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_threatinsight_suspected_passwordspray_attack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_threatinsight_threat_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_user_logins_from_multiple_cities.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/pingid_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_user_enumeration_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_attach_to_role_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_permanent_key_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_role_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_sts_assume_role_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_appids_and_useragents_authentication_spike.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_powershell_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_runbook_webhook_created.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_detect_gcploit_framework.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_multiple_appids_and_useragents_authentication_spike.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_computer_account_name_change.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_kerberos_service_ticket_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_ticket_granting_ticket_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unusual_number_of_computer_service_tickets_requested.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unusual_number_of_remote_endpoint_authentication_events.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_large_number_of_computer_service_tickets_requested.yml" }, { "techniqueID": "T1078.001", @@ -36,13 +36,13 @@ }, { "techniqueID": "T1110", - "score": 38, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/okta_account_locked_out.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_mfa_exhaustion_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_risk_threshold_exceeded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_two_or_more_rejected_okta_pushes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_failed_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_getpassworddata.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_rds_password_reset.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_active_directory_high_risk_sign_in.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_high_number_of_failed_authentications_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_high_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_authentication_from_different_ips.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/high_number_of_login_failures_from_a_single_source.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_local_administrator_credential_stuffing.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml" + "score": 43, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/okta_account_locked_out.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_mfa_exhaustion_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_risk_threshold_exceeded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_two_or_more_rejected_okta_pushes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/pingid_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_failed_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_getpassworddata.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_rds_password_reset.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_active_directory_high_risk_sign_in.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_high_number_of_failed_authentications_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_high_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multi_source_failed_authentications_spike.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_authentication_from_different_ips.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/high_number_of_login_failures_from_a_single_source.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_high_number_of_failed_authentications_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_multi_source_failed_authentications_spike.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_local_administrator_credential_stuffing.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml" }, { "techniqueID": "T1621", - "score": 9, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/okta_mismatch_between_source_and_response_for_verify_push_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml" + "score": 15, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/okta_mismatch_between_source_and_response_for_verify_push_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/pingid_mismatch_auth_source_and_verification_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/pingid_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/pingid_new_mfa_method_after_credential_reset.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/pingid_new_mfa_method_registered_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_denied_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_multiple_failed_mfa_requests_for_user.yml" }, { "techniqueID": "T1550.004", @@ -66,33 +66,43 @@ }, { "techniqueID": "T1110.004", - "score": 9, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/okta_threatinsight_login_failure_with_high_unknown_users.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_local_administrator_credential_stuffing.yml" + "score": 12, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/okta_threatinsight_login_failure_with_high_unknown_users.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multi_source_failed_authentications_spike.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_multi_source_failed_authentications_spike.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_local_administrator_credential_stuffing.yml" }, { "techniqueID": "T1110.003", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/okta_threatinsight_suspected_passwordspray_attack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_active_directory_high_risk_sign_in.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_high_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_authentication_from_different_ips.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml" + "score": 30, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/okta_threatinsight_suspected_passwordspray_attack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_active_directory_high_risk_sign_in.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_high_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multi_source_failed_authentications_spike.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_authentication_from_different_ips.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_multi_source_failed_authentications_spike.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml" }, { "techniqueID": "T1083", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/path_traversal_spl_injection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_absolute_path_traversal_using_runshellscript.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_path_traversal_in_splunk_app_for_lookup_file_edit.yml" }, + { + "techniqueID": "T1556.006", + "score": 10, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/pingid_mismatch_auth_source_and_verification_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/pingid_new_mfa_method_after_credential_reset.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/pingid_new_mfa_method_registered_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_new_mfa_method_registered_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_new_mfa_method_registered_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_new_mfa_method_registered_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multi_factor_authentication_disabled.yml" + }, + { + "techniqueID": "T1098.005", + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/pingid_mismatch_auth_source_and_verification_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/pingid_new_mfa_method_after_credential_reset.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/pingid_new_mfa_method_registered_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_new_mfa_method_registered.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_new_mfa_method_registered.yml" + }, { "techniqueID": "T1087", - "score": 35, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_account_discovery_drilldown_dashboard_disclosure.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_abnormal_object_access_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_privileged_object_access_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_root_domain_linked_policies_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_special_privileged_logon_on_multiple_hosts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml" + "score": 39, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_account_discovery_drilldown_dashboard_disclosure.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_account_discovery_for_none_disable_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_account_discovery_for_sam_account_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_account_discovery_with_netuser_preauthnotrequire.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_abnormal_object_access_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_privileged_object_access_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_domain_account_discovery_via_get_netcomputer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_root_domain_linked_policies_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_special_privileged_logon_on_multiple_hosts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml" }, { "techniqueID": "T1210", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_code_injection_via_custom_dashboard_leading_to_rce.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_rce_via_splunk_secure_gateway__splunk_mobile_alerts_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/active_directory_lateral_movement_identified.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/vmware_aria_operations_exploit_attempt.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_app_for_lookup_file_editing_rce_via_user_xslt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_code_injection_via_custom_dashboard_leading_to_rce.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_rce_via_splunk_secure_gateway__splunk_mobile_alerts_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_rce_via_user_xslt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/active_directory_lateral_movement_identified.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/vmware_aria_operations_exploit_attempt.yml" }, { "techniqueID": "T1189", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_csrf_in_the_ssg_kvstore_client_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_list_all_nonstandard_admin_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/persistent_xss_in_rapiddiag_through_user_interface_views.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_persistent_xss_via_url_validation_bypass_w_dashboard.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_reflected_xss_in_the_templates_lists_radio.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_reflected_xss_on_app_search_table_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_stored_xss_via_data_model_objectname_field.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_unnecessary_file_extensions_allowed_by_lookup_table_uploads.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_xss_in_monitoring_console.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_xss_in_save_table_dialog_header_in_search_page.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_xss_via_view.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" + "score": 13, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_csrf_in_the_ssg_kvstore_client_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_list_all_nonstandard_admin_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/persistent_xss_in_rapiddiag_through_user_interface_views.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_persistent_xss_via_url_validation_bypass_w_dashboard.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_reflected_xss_in_the_templates_lists_radio.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_reflected_xss_on_app_search_table_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_stored_xss_via_data_model_objectname_field.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_unnecessary_file_extensions_allowed_by_lookup_table_uploads.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_xss_in_highlighted_json_events.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_xss_in_monitoring_console.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_xss_in_save_table_dialog_header_in_search_page.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_xss_via_view.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1567", @@ -116,19 +126,29 @@ }, { "techniqueID": "T1548", - "score": 51, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_edit_user_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_risky_command_abuse_disclosed_february_2023.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_operation_with_consent_admin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_uac_remote_restriction.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_apt_get_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_apt_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_awk_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_busybox_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_c89_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_c99_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_common_process_for_elevation_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_composer_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_cpulimit_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_csvtool_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_doas_conf_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_doas_tool_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_docker_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_emacs_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_find_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_gdb_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_gem_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_gnu_awk_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_make_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_mysql_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_node_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_octave_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_openvpn_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_persistence_and_privilege_escalation_risk_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_php_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_access_to_sudoers_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_puppet_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_rpm_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_ruby_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_setuid_using_chmod_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_setuid_using_setcap_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_sqlite3_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_sudo_or_su_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_sudoers_tmp_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_visudo_utility_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/services_escalate_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml" + "score": 54, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_edit_user_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_enterprise_kv_store_incorrect_authorization.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_risky_command_abuse_disclosed_february_2023.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_operation_with_consent_admin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_uac_remote_restriction.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_apt_get_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_apt_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_awk_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_busybox_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_c89_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_c99_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_common_process_for_elevation_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_composer_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_cpulimit_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_csvtool_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_doas_conf_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_doas_tool_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_docker_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_emacs_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_find_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_gdb_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_gem_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_gnu_awk_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_make_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_mysql_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_node_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_octave_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_openvpn_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_persistence_and_privilege_escalation_risk_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_php_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_access_to_sudoers_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_puppet_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_rpm_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_ruby_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_setuid_using_chmod_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_setuid_using_setcap_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_sqlite3_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_sudo_or_su_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_sudoers_tmp_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_visudo_utility_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/services_escalate_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_uac_bypass_suspicious_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_uac_bypass_suspicious_escalation_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml" }, { "techniqueID": "T1499", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_endpoint_denial_of_service_dos_zip_bomb.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_improperly_formatted_parameter_crashes_splunkd.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_endpoint_denial_of_service_dos_zip_bomb.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_es_dos_investigations_manager_via_investigation_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_es_dos_through_investigation_attachments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_improperly_formatted_parameter_crashes_splunkd.yml" + }, + { + "techniqueID": "T1190", + "score": 59, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_enterprise_windows_deserialization_file_partition.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_rce_via_serialized_session_payload.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_unauthenticated_log_injection_web_service_log.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/exchange_powershell_abuse_via_ssrf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/java_class_file_download_by_java_user_agent.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/java_writing_jsp_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_java_spawning_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/living_off_the_land.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/log4shell_cve_2021_44228_exploitation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/outbound_network_connection_from_java_using_default_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/papercut_ng_suspicious_behavior_debug_log.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_java_spawning_shells.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_moveit_transfer_writing_aspx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_papercut_ng_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winrm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_zerologon_via_zeek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/f5_big_ip_icontrol_rest_vulnerability_cve_2022_1388.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/access_to_vulnerable_ivanti_connect_secure_bookmark_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/adobe_coldfusion_access_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/adobe_coldfusion_unauthenticated_arbitrary_file_read.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/cisco_ios_xe_implant_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/citrix_adc_and_gateway_unauthorized_data_disclosure.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/citrix_adc_exploitation_cve_2023_3519.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/citrix_sharefile_exploitation_cve_2023_24489.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/confluence_cve_2023_22515_trigger_vulnerability.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/confluence_data_center_and_server_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/confluence_pre_auth_rce_via_ognl_injection_cve_2023_22527.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/confluence_unauthenticated_remote_code_execution_cve_2022_26134.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/detect_f5_tmui_rce_cve_2020_5902.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/exploit_public_facing_application_via_apache_commons_text.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/exploit_public_facing_fortinet_fortinac_cve_2022_39952.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/fortinet_appliance_auth_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/hunting_for_log4shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/ivanti_connect_secure_command_injection_attempts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/ivanti_connect_secure_system_information_access_via_auth_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/ivanti_epmm_remote_unauthenticated_api_access_cve_2023_35078.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/ivanti_epmm_remote_unauthenticated_api_access_cve_2023_35082.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/ivanti_sentry_authentication_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/jenkins_arbitrary_file_read_cve_2024_23897.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/jetbrains_teamcity_rce_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/juniper_networks_remote_code_execution_exploit_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/log4shell_jndi_payload_injection_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/log4shell_jndi_payload_injection_with_outbound_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/papercut_ng_remote_web_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/proxyshell_proxynotshell_behavior_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/spring4shell_payload_url_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/sql_injection_with_long_urls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/vmware_aria_operations_exploit_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/vmware_server_side_template_injection_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/vmware_workspace_one_freemarker_server_side_template_injection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/web_jsp_request_via_url.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/web_remote_shellservlet_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/web_spring4shell_http_request_class_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/web_spring_cloud_function_functionrouter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/windows_exchange_autodiscover_ssrf_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/ws_ftp_remote_code_execution.yml" }, { "techniqueID": "T1027.006", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_http_response_splitting_via_rest_spl_command.yml" }, + { + "techniqueID": "T1082", + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_information_disclosure_in_splunk_add_on_builder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/web_servers_executing_suspicious_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_kernel_module_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_information_discovery_fsutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_post_exploitation_risk_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/detect_attackers_scanning_for_vulnerable_jboss_servers.yml" + }, { "techniqueID": "T1212", "score": 3, @@ -136,8 +156,8 @@ }, { "techniqueID": "T1055", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_process_injection_forwarder_bundle_downloads.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/loading_of_dynwrapx_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/notepad_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_shell_fetch_env_variables.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_into_notepad.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_remote_thread.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_wermgr_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_with_public_source_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_with_namedpipe_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_rasautou_dll_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_assistance_spawning_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winhlp32_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml" + "score": 28, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_process_injection_forwarder_bundle_downloads.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/loading_of_dynwrapx_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/notepad_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_shell_fetch_env_variables.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_in_non_service_searchindexer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_into_notepad.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_remote_thread.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_wermgr_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_with_public_source_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_with_namedpipe_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_rasautou_dll_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_assistance_spawning_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winhlp32_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml" }, { "techniqueID": "T1001.003", @@ -151,13 +171,8 @@ }, { "techniqueID": "T1134", - "score": 10, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_rbac_bypass_on_indexing_preview_rest_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/runas_execution_in_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_access_token_manipulation_winlogon_duplicate_token_handle.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_access_token_winlogon_duplicate_handle_in_uncommon_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_privileged_account_sid_history_addition.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_sid_history_attribute_modified.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml" - }, - { - "techniqueID": "T1190", - "score": 51, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_rce_via_serialized_session_payload.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_unauthenticated_log_injection_web_service_log.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/exchange_powershell_abuse_via_ssrf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/java_class_file_download_by_java_user_agent.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/java_writing_jsp_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_java_spawning_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/living_off_the_land.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/log4shell_cve_2021_44228_exploitation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/outbound_network_connection_from_java_using_default_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/papercut_ng_suspicious_behavior_debug_log.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_java_spawning_shells.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_moveit_transfer_writing_aspx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_papercut_ng_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winrm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_zerologon_via_zeek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/f5_big_ip_icontrol_rest_vulnerability_cve_2022_1388.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/adobe_coldfusion_access_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/adobe_coldfusion_unauthenticated_arbitrary_file_read.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/cisco_ios_xe_implant_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/citrix_adc_exploitation_cve_2023_3519.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/citrix_sharefile_exploitation_cve_2023_24489.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/confluence_cve_2023_22515_trigger_vulnerability.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/confluence_data_center_and_server_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/confluence_unauthenticated_remote_code_execution_cve_2022_26134.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/detect_f5_tmui_rce_cve_2020_5902.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/exploit_public_facing_application_via_apache_commons_text.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/exploit_public_facing_fortinet_fortinac_cve_2022_39952.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/fortinet_appliance_auth_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/hunting_for_log4shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/ivanti_epmm_remote_unauthenticated_api_access_cve_2023_35078.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/ivanti_epmm_remote_unauthenticated_api_access_cve_2023_35082.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/ivanti_sentry_authentication_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/jetbrains_teamcity_rce_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/juniper_networks_remote_code_execution_exploit_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/log4shell_jndi_payload_injection_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/log4shell_jndi_payload_injection_with_outbound_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/papercut_ng_remote_web_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/proxyshell_proxynotshell_behavior_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/spring4shell_payload_url_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/sql_injection_with_long_urls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/vmware_aria_operations_exploit_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/vmware_server_side_template_injection_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/vmware_workspace_one_freemarker_server_side_template_injection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/web_jsp_request_via_url.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/web_spring4shell_http_request_class_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/web_spring_cloud_function_functionrouter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/windows_exchange_autodiscover_ssrf_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/ws_ftp_remote_code_execution.yml" + "score": 11, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_rbac_bypass_on_indexing_preview_rest_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/runas_execution_in_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_access_token_manipulation_winlogon_duplicate_token_handle.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_access_token_winlogon_duplicate_handle_in_uncommon_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_privileged_account_sid_history_addition.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_sid_history_attribute_modified.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_parent_pid_spoofing_with_explorer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml" }, { "techniqueID": "T1202", @@ -166,18 +181,13 @@ }, { "techniqueID": "T1566.001", - "score": 31, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/suspicious_email_attachment_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_office_product_spawning_msdt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_pdf_file_executes_url_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_spearphishing_attachment_connect_to_none_ms_office_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml" + "score": 35, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/suspicious_email_attachment_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_cab_file_on_disk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_asr_audit_events.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_asr_block_events.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_asr_rules_stacking.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_office_product_spawning_msdt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_pdf_file_executes_url_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_spearphishing_attachment_connect_to_none_ms_office_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml" }, { "techniqueID": "T1566", - "score": 35, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/suspicious_email_attachment_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gdrive_suspicious_file_sharing.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_calendar_invite.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_office_product_spawning_msdt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_pdf_file_executes_url_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_spearphishing_attachment_connect_to_none_ms_office_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml" - }, - { - "techniqueID": "T1082", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/web_servers_executing_suspicious_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_kernel_module_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_information_discovery_fsutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_post_exploitation_risk_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/detect_attackers_scanning_for_vulnerable_jboss_servers.yml" + "score": 36, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/suspicious_email_attachment_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_device_code_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gdrive_suspicious_file_sharing.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_calendar_invite.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_office_product_spawning_msdt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_pdf_file_executes_url_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_spearphishing_attachment_connect_to_none_ms_office_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml" }, { "techniqueID": "T1078.004", @@ -186,43 +196,38 @@ }, { "techniqueID": "T1526", - "score": 8, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/amazon_eks_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/amazon_eks_kubernetes_pod_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_excessive_security_scanning.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_excessive_security_scanning.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_kubernetes_cluster_pod_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_scanner_image_pulling.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/kubernetes_azure_scan_fingerprint.yml" + "score": 9, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/amazon_eks_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/amazon_eks_kubernetes_pod_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_excessive_security_scanning.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_excessive_security_scanning.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_kubernetes_cluster_pod_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_scanner_image_pulling.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_suspicious_image_pulling.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/kubernetes_azure_scan_fingerprint.yml" }, { "techniqueID": "T1185", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_concurrent_sessions_from_different_ips.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_concurrent_sessions_from_different_ips.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_concurrent_sessions_from_different_ips.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_concurrent_sessions_from_different_ips.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_concurrent_sessions_from_different_ips.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_concurrent_sessions_from_different_ips.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_concurrent_sessions_from_different_ips.yml" }, { "techniqueID": "T1562.008", - "score": 9, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_defense_evasion_delete_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_defense_evasion_delete_cloudwatch_log_group.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_defense_evasion_impair_security_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_impair_security_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_update_cloudtrail.yml" + "score": 10, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_defense_evasion_delete_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_defense_evasion_delete_cloudwatch_log_group.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_defense_evasion_impair_security_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_impair_security_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_update_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_advanced_audit_disabled.yml" }, { "techniqueID": "T1562", - "score": 71, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_defense_evasion_delete_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_defense_evasion_delete_cloudwatch_log_group.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_defense_evasion_impair_security_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_impair_security_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_update_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_impair_defenses_process_kill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_iptables_firewall_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_delete_or_modify_system_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_windows_event_logging_disable_http_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_for_service_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_excessive_disabled_services_event.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defenses_disable_hvci.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_disable_http_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_import_applocker_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_registry_delete_task_sd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_terminating_lsass_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml" + "score": 97, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_defense_evasion_delete_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_defense_evasion_delete_cloudwatch_log_group.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_defense_evasion_impair_security_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_impair_security_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_update_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_block_user_consent_for_risky_apps_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_advanced_audit_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_block_user_consent_for_risky_apps_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_impair_defenses_process_kill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_iptables_firewall_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_delete_or_modify_system_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_windows_event_logging_disable_http_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_for_service_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_excessive_disabled_services_event.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_change_win_defender_health_check_intervals.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_change_win_defender_quick_scan_interval.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_change_win_defender_throttle_rate.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_change_win_defender_tracing_level.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_configure_app_install_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_define_win_defender_threat_action.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_controlled_folder_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_defender_firewall_and_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_defender_protocol_recognition.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_pua_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_realtime_signature_delivery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_web_evaluation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_win_defender_app_guard.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_win_defender_compute_file_hashes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_win_defender_gen_reports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_win_defender_network_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_win_defender_report_infection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_win_defender_scan_on_update.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_win_defender_signature_retirement.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_overide_win_defender_phishing_filter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_override_smartscreen_prompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_set_win_defender_smart_screen_level_to_warn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defenses_disable_hvci.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_system_firewall_with_notable_process_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_disable_http_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_import_applocker_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_registry_delete_task_sd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_terminating_lsass_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml" }, { "techniqueID": "T1098", - "score": 20, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_application_administrator_role_assigned.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_pim_role_assigned.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_pim_role_assignment_activated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_privileged_role_assigned.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_service_principal_new_client_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_service_principal_owner_added.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_user_enabled_and_password_reset.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_user_immutableid_attribute_updated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_ssh_key_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_dsrm_account_changes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_dsrm_password_reset.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_serviceprincipalname_added_to_domain_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_short_lived_domain_account_serviceprincipalname.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dnsadmins_new_member_added.yml" + "score": 30, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_application_administrator_role_assigned.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_new_mfa_method_registered.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_pim_role_assigned.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_pim_role_assignment_activated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_privileged_role_assigned.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_service_principal_new_client_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_service_principal_owner_added.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_tenant_wide_admin_consent_granted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_user_enabled_and_password_reset.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_user_immutableid_attribute_updated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_application_registration_owner_added.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_applicationimpersonation_role_assigned.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_high_privilege_role_granted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_mailbox_read_access_granted_to_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_new_mfa_method_registered.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_service_principal_new_client_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_tenant_wide_admin_consent_granted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_ssh_key_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_dsrm_account_changes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_dsrm_password_reset.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_serviceprincipalname_added_to_domain_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_short_lived_domain_account_serviceprincipalname.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dnsadmins_new_member_added.yml" }, { "techniqueID": "T1586", - "score": 28, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_failed_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_getpassworddata.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_rds_password_reset.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_successful_console_authentication_from_multiple_ips.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_active_directory_high_risk_sign_in.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_powershell_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_aws_console_login_by_new_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml" + "score": 31, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_failed_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_getpassworddata.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_rds_password_reset.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_successful_console_authentication_from_multiple_ips.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_active_directory_high_risk_sign_in.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multi_source_failed_authentications_spike.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_powershell_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_aws_console_login_by_new_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_multi_source_failed_authentications_spike.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_multiple_users_failing_to_authenticate_from_ip.yml" }, { "techniqueID": "T1586.003", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_failed_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_getpassworddata.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_rds_password_reset.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_active_directory_high_risk_sign_in.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_powershell_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_aws_console_login_by_new_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml" - }, - { - "techniqueID": "T1556.006", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_new_mfa_method_registered_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_new_mfa_method_registered_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_new_mfa_method_registered_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multi_factor_authentication_disabled.yml" + "score": 30, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_failed_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_getpassworddata.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_rds_password_reset.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_active_directory_high_risk_sign_in.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multi_source_failed_authentications_spike.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_powershell_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_aws_console_login_by_new_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multi_factor_authentication_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_multi_source_failed_authentications_spike.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_multiple_users_failing_to_authenticate_from_ip.yml" }, { "techniqueID": "T1201", @@ -246,8 +251,8 @@ }, { "techniqueID": "T1110.001", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_failed_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_getpassworddata.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_high_number_of_failed_authentications_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_high_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_authentication_from_different_ips.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/high_number_of_login_failures_from_a_single_source.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_failed_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_getpassworddata.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_high_number_of_failed_authentications_for_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_high_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_authentication_from_different_ips.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/high_number_of_login_failures_from_a_single_source.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_high_number_of_failed_authentications_for_user.yml" }, { "techniqueID": "T1550", @@ -266,13 +271,13 @@ }, { "techniqueID": "T1204.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_scanning_findings_high.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_scanning_findings_medium.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_upload_unknown_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/correlation_by_repository_and_risk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/correlation_by_user_and_risk.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_scanning_findings_high.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_scanning_findings_medium.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_upload_unknown_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/risk_rule_for_dev_sec_ops_by_repository.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/correlation_by_repository_and_risk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/correlation_by_user_and_risk.yml" }, { "techniqueID": "T1204", - "score": 17, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_scanning_findings_high.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_scanning_findings_medium.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_upload_unknown_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_lambda_updatefunctioncode.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/correlation_by_repository_and_risk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/correlation_by_user_and_risk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clop_common_exec_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/conti_common_exec_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_common_exec_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml" + "score": 39, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_scanning_findings_high.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_scanning_findings_medium.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_upload_unknown_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_lambda_updatefunctioncode.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_anomalous_inbound_network_activity_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_anomalous_inbound_outbound_network_io.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_anomalous_inbound_to_outbound_network_io_ratio.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_anomalous_outbound_network_activity_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_anomalous_traffic_on_network_edge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_create_or_update_privileged_pod.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_daemonset_deployed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_falco_shell_spawned.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_newly_seen_tcp_edge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_newly_seen_udp_edge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_node_port_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_pod_created_in_default_namespace.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_pod_with_host_network_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_previously_unseen_container_image_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_previously_unseen_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_process_running_from_new_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_process_with_anomalous_resource_utilisation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_process_with_resource_ratio_anomalies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_shell_running_on_worker_node.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_shell_running_on_worker_node_with_cpu_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_unauthorized_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/risk_rule_for_dev_sec_ops_by_repository.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/correlation_by_repository_and_risk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/correlation_by_user_and_risk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clop_common_exec_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/conti_common_exec_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_common_exec_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml" }, { "techniqueID": "T1119", @@ -306,8 +311,18 @@ }, { "techniqueID": "T1098.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_application_administrator_role_assigned.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_global_administrator_role_assigned.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_pim_role_assigned.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_pim_role_assignment_activated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_privileged_role_assigned.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml" + "score": 10, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_application_administrator_role_assigned.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_global_administrator_role_assigned.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_pim_role_assigned.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_pim_role_assignment_activated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_privileged_role_assigned.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_tenant_wide_admin_consent_granted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_high_privilege_role_granted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_mailbox_read_access_granted_to_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_tenant_wide_admin_consent_granted.yml" + }, + { + "techniqueID": "T1528", + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_device_code_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_oauth_application_consent_granted_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_user_consent_blocked_for_risky_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_user_consent_denied_for_oauth_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_file_permissioned_application_consent_granted_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_mail_permissioned_application_consent_granted_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_user_consent_blocked_for_risky_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_user_consent_denied_for_oauth_application.yml" + }, + { + "techniqueID": "T1566.002", + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_device_code_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_asr_audit_events.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_asr_block_events.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_asr_rules_stacking.yml" }, { "techniqueID": "T1484", @@ -326,8 +341,8 @@ }, { "techniqueID": "T1098.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_service_principal_new_client_credentials.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_service_principal_new_client_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_service_principal_new_client_credentials.yml" }, { "techniqueID": "T1554", @@ -379,6 +394,26 @@ "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dns_exfiltration_using_nslookup_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_nslookup_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/prohibited_network_traffic_allowed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/protocol_or_port_mismatch.yml" }, + { + "techniqueID": "T1552.007", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_abuse_of_secret_by_unusual_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_abuse_of_secret_by_unusual_user_agent.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_abuse_of_secret_by_unusual_user_group.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_abuse_of_secret_by_unusual_user_name.yml" + }, + { + "techniqueID": "T1046", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_access_scanning.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_scanning_by_unauthenticated_ip_address.yml" + }, + { + "techniqueID": "T1053.007", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_cron_job_creation.yml" + }, + { + "techniqueID": "T1098.002", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_applicationimpersonation_role_assigned.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" + }, { "techniqueID": "T1114.003", "score": 2, @@ -436,8 +471,8 @@ }, { "techniqueID": "T1562.004", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_iptables_firewall_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_delete_or_modify_system_firewall.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_iptables_firewall_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_delete_or_modify_system_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_system_firewall_with_notable_process_path.yml" }, { "techniqueID": "T1564.001", @@ -456,18 +491,18 @@ }, { "techniqueID": "T1218", - "score": 58, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/control_loading_from_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/lolbas_with_network_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/verclsid_clsid_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_diskshadow_proxy_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_credential_theft.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_in_non_standard_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_remote_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_uninstall_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_uninstall_option_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_rasautou_dll_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_regsvr32_renamed_binary.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml" + "score": 60, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/control_loading_from_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/lolbas_with_network_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/verclsid_clsid_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_diskshadow_proxy_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_credential_theft.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_in_non_standard_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_remote_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_uninstall_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_uninstall_option_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msiexec_hidewindow_rundll32_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_rasautou_dll_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_regsvr32_renamed_binary.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_rundll32_apply_user_settings_changes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml" }, { "techniqueID": "T1036", - "score": 16, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rtlo_in_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rtlo_in_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_kworker_process_in_writable_process_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_copy_on_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_in_non_standard_path.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rtlo_in_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rtlo_in_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_kworker_process_in_writable_process_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_copy_on_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_in_non_standard_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_masquerading_msdtc_process.yml" }, { "techniqueID": "T1218.011", - "score": 16, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_rundll32_apply_user_settings_changes.yml" }, { "techniqueID": "T1204.002", @@ -476,18 +511,18 @@ }, { "techniqueID": "T1560.001", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_archive_collected_data_via_rar.yml" }, { "techniqueID": "T1560", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_certipy_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_certipy_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_archive_collected_data_via_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_archive_collected_data_via_rar.yml" }, { "techniqueID": "T1087.002", - "score": 26, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_abnormal_object_access_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_privileged_object_access_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_root_domain_linked_policies_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml" + "score": 27, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_abnormal_object_access_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_privileged_object_access_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_domain_account_discovery_via_get_netcomputer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_root_domain_linked_policies_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml" }, { "techniqueID": "T1547.014", @@ -506,8 +541,8 @@ }, { "techniqueID": "T1562.001", - "score": 49, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_impair_defenses_process_kill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_domain_controller_audit_policy_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_for_service_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_excessive_disabled_services_event.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defenses_disable_hvci.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_import_applocker_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_terminating_lsass_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml" + "score": 71, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_impair_defenses_process_kill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_domain_controller_audit_policy_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_for_service_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_excessive_disabled_services_event.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_change_win_defender_health_check_intervals.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_change_win_defender_quick_scan_interval.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_change_win_defender_throttle_rate.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_change_win_defender_tracing_level.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_configure_app_install_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_define_win_defender_threat_action.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_controlled_folder_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_defender_firewall_and_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_defender_protocol_recognition.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_pua_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_realtime_signature_delivery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_web_evaluation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_win_defender_app_guard.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_win_defender_compute_file_hashes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_win_defender_gen_reports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_win_defender_network_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_win_defender_report_infection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_win_defender_scan_on_update.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_disable_win_defender_signature_retirement.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_overide_win_defender_phishing_filter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_override_smartscreen_prompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_set_win_defender_smart_screen_level_to_warn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defenses_disable_hvci.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_import_applocker_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_terminating_lsass_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml" }, { "techniqueID": "T1021.001", @@ -516,8 +551,8 @@ }, { "techniqueID": "T1021", - "score": 26, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enable_rdp_in_other_port_number.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executable_file_written_in_administrative_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mmc_lolbas_execution_process_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_lateral_movement_powershell_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_desktop_process_running_on_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_allow_remote_assistance.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_rdp_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsmprovhost_lolbas_execution_process_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/remote_desktop_network_bruteforce.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/remote_desktop_network_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/smb_traffic_spike.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/smb_traffic_spike___mltk.yml" + "score": 27, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enable_rdp_in_other_port_number.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executable_file_written_in_administrative_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mmc_lolbas_execution_process_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_lateral_movement_powershell_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_services_add_trustedhost.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_desktop_process_running_on_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_allow_remote_assistance.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_rdp_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsmprovhost_lolbas_execution_process_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/remote_desktop_network_bruteforce.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/remote_desktop_network_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/smb_traffic_spike.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/smb_traffic_spike___mltk.yml" }, { "techniqueID": "T1105", @@ -561,8 +596,8 @@ }, { "techniqueID": "T1033", - "score": 11, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_common_abused_cmd_shell_risk_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_discovery_using_ldap_nslookup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_discovery_using_qwinsta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_user_discovery_via_quser.yml" + "score": 12, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_common_abused_cmd_shell_risk_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_discovery_using_ldap_nslookup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_discovery_using_qwinsta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_user_discovery_via_quser.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_user_privilege_discovery.yml" }, { "techniqueID": "T1068", @@ -576,8 +611,8 @@ }, { "techniqueID": "T1070", - "score": 20, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_account_manipulation_of_ssh_config_and_keys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_cron_jobs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_init_daemon_script.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_ssl_certificate.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_indicator_removal_clear_cache.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_indicator_removal_service_file_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml" + "score": 21, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_account_manipulation_of_ssh_config_and_keys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_cron_jobs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_init_daemon_script.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_ssl_certificate.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_indicator_removal_clear_cache.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_indicator_removal_service_file_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_indicator_removal_via_rmdir.yml" }, { "techniqueID": "T1543", @@ -662,7 +697,7 @@ { "techniqueID": "T1649", "score": 17, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_certify_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_certify_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_certipy_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/steal_or_forge_authentication_certificates_behavior_identified.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_export_certificate.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_mimikatz_crypto_export_file_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_export_certificate.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_export_pfxcertificate.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_steal_authentication_certificates___esc1_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_steal_authentication_certificates_certificate_issued.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_steal_authentication_certificates_certificate_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_steal_authentication_certificates_certutil_backup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_steal_authentication_certificates_cryptoapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_steal_authentication_certificates_cs_backup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_steal_authentication_certificates___esc1_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_steal_authentication_certificates_export_certificate.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_steal_authentication_certificates_export_pfxcertificate.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_certify_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_certify_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_certipy_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/steal_or_forge_authentication_certificates_behavior_identified.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_export_certificate.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_mimikatz_crypto_export_file_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_export_certificate.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_export_pfxcertificate.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_steal_authentication_certificates___esc1_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_steal_authentication_certificates___esc1_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_steal_authentication_certificates_certificate_issued.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_steal_authentication_certificates_certificate_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_steal_authentication_certificates_certutil_backup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_steal_authentication_certificates_cryptoapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_steal_authentication_certificates_cs_backup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_steal_authentication_certificates_export_certificate.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_steal_authentication_certificates_export_pfxcertificate.yml" }, { "techniqueID": "T1078.003", @@ -701,8 +736,8 @@ }, { "techniqueID": "T1574", - "score": 11, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_preload_hijack_library_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/msi_module_loaded_by_non_system_binary.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_search_order_hijacking_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_side_loading_in_calc.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_hijack_execution_flow_version_dll_side_load.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_masquerading_explorer_as_child_process.yml" + "score": 12, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_preload_hijack_library_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/msi_module_loaded_by_non_system_binary.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_search_order_hijacking_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_side_loading_in_calc.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_hijack_execution_flow_version_dll_side_load.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_known_graphicalproton_loaded_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_masquerading_explorer_as_child_process.yml" }, { "techniqueID": "T1016", @@ -761,18 +796,18 @@ }, { "techniqueID": "T1112", - "score": 49, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_security_logs_using_minint_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_inprocserver32_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_client_registry_install_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_shimcache_flush.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_deleted_registry_by_a_non_critical_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_change_password_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_lock_workstation_feature_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_logoff_button_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_notification_center.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_shutdown_button_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_windows_group_policy_features_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_hide_notification_features_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_auto_minor_updates.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_auto_update_notif.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_default_icon_setting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disable_toast_notifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disable_win_defender_raw_write_notif.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disable_windefender_notifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disable_windows_security_center_notif.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disabling_wer_settings.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disallow_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_do_not_connect_to_win_update.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_enablelinkedconnections.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_longpathsenabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_maxconnectionperserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_no_auto_reboot_with_logon_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_no_auto_update.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_qakbot_binary_data_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_regedit_silent_reg_import.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_risk_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_suppress_win_defender_notif.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_tamper_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_updateserviceurlalternate.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_usewuserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_with_md5_reg_key_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_wuserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_wustatusserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_show_compress_color_and_info_tip_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_snake_malware_registry_modification_wav_openwithprogids.yml" + "score": 59, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_security_logs_using_minint_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_inprocserver32_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_client_registry_install_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_shimcache_flush.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_asr_registry_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_asr_rule_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_deleted_registry_by_a_non_critical_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_change_password_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_lock_workstation_feature_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_logoff_button_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_notification_center.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_shutdown_button_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_windows_group_policy_features_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_hide_notification_features_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_authenticationleveloverride.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_auto_minor_updates.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_auto_update_notif.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_default_icon_setting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disable_restricted_admin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disable_toast_notifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disable_win_defender_raw_write_notif.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disable_windefender_notifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disable_windows_security_center_notif.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disableremotedesktopantialias.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disablesecuritysettings.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disabling_wer_settings.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disallow_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_do_not_connect_to_win_update.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_dontshowui.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_enablelinkedconnections.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_longpathsenabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_maxconnectionperserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_no_auto_reboot_with_logon_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_no_auto_update.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_nochangingwallpaper.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_proxyenable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_proxyserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_qakbot_binary_data_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_regedit_silent_reg_import.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_risk_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_suppress_win_defender_notif.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_tamper_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_updateserviceurlalternate.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_usewuserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_with_md5_reg_key_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_wuserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_wustatusserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_show_compress_color_and_info_tip_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_snake_malware_registry_modification_wav_openwithprogids.yml" }, { "techniqueID": "T1564", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_alternate_datastream___base64_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_alternate_datastream___executable_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_alternate_datastream___process_execution.yml" }, { "techniqueID": "T1548.002", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_uac_remote_restriction.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_bypass_uac_via_pkgmgr_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_uac_remote_restriction.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_bypass_uac_via_pkgmgr_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_uac_bypass_suspicious_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_uac_bypass_suspicious_escalation_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml" }, { "techniqueID": "T1558", @@ -821,8 +856,8 @@ }, { "techniqueID": "T1564.003", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/headless_browser_mockbin_or_mocky_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/headless_browser_usage.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/headless_browser_mockbin_or_mocky_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/headless_browser_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_conhost_with_headless_argument.yml" }, { "techniqueID": "T1222.001", @@ -841,8 +876,8 @@ }, { "techniqueID": "T1021.006", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_lateral_movement_powershell_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsmprovhost_lolbas_execution_process_spawn.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_lateral_movement_powershell_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_services_add_trustedhost.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsmprovhost_lolbas_execution_process_spawn.yml" }, { "techniqueID": "T1558.003", @@ -1031,8 +1066,8 @@ }, { "techniqueID": "T1574.002", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msi_module_loaded_by_non_system_binary.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_side_loading_in_calc.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_masquerading_explorer_as_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unsigned_dll_side_loading.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msi_module_loaded_by_non_system_binary.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_side_loading_in_calc.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_known_graphicalproton_loaded_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_masquerading_explorer_as_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_unsigned_dll_side_loading.yml" }, { "techniqueID": "T1016.001", @@ -1046,8 +1081,8 @@ }, { "techniqueID": "T1555", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_browser_pass_view_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_credentials_from_password_stores_query.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_browser_pass_view_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_credentials_from_password_stores_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_credentials_from_password_stores_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_credentials_from_password_stores_query.yml" }, { "techniqueID": "T1555.003", @@ -1099,11 +1134,6 @@ "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/print_processor_registry_autostart.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/print_spooler_adding_a_printer_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_spawning_rundll32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_loaded_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_writing_a_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml" }, - { - "techniqueID": "T1566.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" - }, { "techniqueID": "T1559.001", "score": 1, @@ -1181,8 +1211,8 @@ }, { "techniqueID": "T1218.007", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msiexec_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msiexec_remote_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msiexec_spawn_discovery_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msiexec_with_network_connections.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msiexec_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msiexec_hidewindow_rundll32_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msiexec_remote_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msiexec_spawn_discovery_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msiexec_spawn_windbg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msiexec_with_network_connections.yml" }, { "techniqueID": "T1218.012", @@ -1224,6 +1254,11 @@ "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_admon_default_group_policy_object_modified.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_admon_group_policy_object_created.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_default_group_policy_object_modified.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_default_group_policy_object_modified_with_gpme.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_group_policy_object_created.yml" }, + { + "techniqueID": "T1564.004", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_alternate_datastream___base64_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_alternate_datastream___executable_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_alternate_datastream___process_execution.yml" + }, { "techniqueID": "T1071", "score": 9, @@ -1254,6 +1289,11 @@ "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_cached_domain_credentials_reg_query.yml" }, + { + "techniqueID": "T1564.006", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_conhost_with_headless_argument.yml" + }, { "techniqueID": "T1012", "score": 8, @@ -1339,6 +1379,11 @@ "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_lateral_tool_transfer_remcom.yml" }, + { + "techniqueID": "T1003.004", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_lsa_secrets_nolmhash_registry.yml" + }, { "techniqueID": "T1553.005", "score": 1, @@ -1354,11 +1399,21 @@ "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_odbcconf_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_odbcconf_load_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_odbcconf_load_response_file.yml" }, + { + "techniqueID": "T1134.004", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_parent_pid_spoofing_with_explorer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml" + }, { "techniqueID": "T1555.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_password_managers_discovery.yml" }, + { + "techniqueID": "T1057", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_commandline_discovery.yml" + }, { "techniqueID": "T1055.002", "score": 3, @@ -1429,11 +1484,6 @@ "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_xsl_execution_via_url.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, - { - "techniqueID": "T1134.004", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml" - }, { "techniqueID": "T1557", "score": 4, @@ -1492,7 +1542,7 @@ "#096ed7" ], "minValue": 0, - "maxValue": 71 + "maxValue": 97 }, "filters": { "platforms": [ @@ -1519,4 +1569,4 @@ "showTacticRowBackground": true, "tacticRowBackground": "#dddddd", "sorting": 3 -} \ No newline at end of file +}