mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
updating src files
This commit is contained in:
@@ -241,7 +241,7 @@ data_models = ["Application_State", "Authentication", "Network_Resolution", "Net
|
||||
description = Detect and investigate tactics, techniques, and procedures leveraged by attackers to establish and operate command and control channels. Implants installed by attackers on compromised endpoints use these channels to receive instructions and send data back to the malicious operators.
|
||||
id = 943773c6-c4de-4f38-89a8-0b92f98804d8
|
||||
version = 1.0
|
||||
mappings = {"mitre_attack": ["Command and Control", "Exfiltration Over Command and Control Channel", "Standard Non-Application Layer Protocol", "Commonly Used Port", "Exfiltration Over Alternative Protocol", "Exfiltration", "Standard Application Layer Protocol", "Defense Evasion"], "cis20": ["CIS 8", "CIS 9", "CIS 11", "CIS 12", "CIS 13", "CIS 3", "CIS 1"], "kill_chain_phases": ["Command and Control", "Actions on Objectives", "Delivery"], "nist": ["ID.AM", "PR.DS", "PR.IP", "PR.PT", "PR.AC", "DE.AE", "DE.CM"]}
|
||||
mappings = {"mitre_attack": ["Command and Control", "Exfiltration Over Command and Control Channel", "Standard Non-Application Layer Protocol", "Commonly Used Port", "Exfiltration Over Alternative Protocol", "Exfiltration", "Standard Application Layer Protocol", "Defense Evasion"], "cis20": ["CIS 8", "CIS 9", "CIS 11", "CIS 12", "CIS 13", "CIS 3", "CIS 1"], "kill_chain_phases": ["Command and Control", "Delivery", "Actions on Objectives"], "nist": ["ID.AM", "PR.DS", "PR.IP", "PR.PT", "PR.AC", "DE.AE", "DE.CM"]}
|
||||
modification_date = 2018-07-24
|
||||
reference = ["https://attack.mitre.org/wiki/Command_and_Control", "https://searchsecurity.techtarget.com/feature/Command-and-control-servers-The-puppet-masters-that-govern-malware"]
|
||||
providing_technologies = ["AWS", "Bluecoat", "Bro", "Carbon Black Response", "CrowdStrike Falcon", "Linux", "Microsoft Windows", "Palo Alto Firewall", "Splunk Enterprise Security", "Splunk Stream", "Sysmon", "Tanium", "Ziften", "macOS"]
|
||||
@@ -368,7 +368,7 @@ data_models = ["Application_State", "Authentication", "Email", "Endpoint", "Netw
|
||||
description = Detect rarely used executables, specific registry paths that may confer malware survivability and persistence, instances where cmd.exe is used to launch script interpreters, and other indicators that the Emotet financial malware has compromised your environment.
|
||||
id = bb9f5ed2-916e-4364-bb6d-91c310efcf52
|
||||
version = 1.0
|
||||
mappings = {"mitre_attack": ["Third-party Software", "AppInit DLLs", "Commonly Used Port", "Command-Line Interface", "Registry Run Keys / Start Folder", "Persistence", "Defense Evasion", "Execution", "Authentication Package", "Account Discovery"], "cis20": ["CIS 7", "CIS 12", "CIS 2", "CIS 3", "CIS 8"], "kill_chain_phases": ["Exploitation", "Actions on Objectives", "Delivery", "Installation", "Command and Control"], "nist": ["ID.AM", "PR.DS", "PR.IP", "PR.PT", "DE.AE", "DE.CM"]}
|
||||
mappings = {"mitre_attack": ["Third-party Software", "AppInit DLLs", "Commonly Used Port", "Command-Line Interface", "Registry Run Keys / Start Folder", "Persistence", "Defense Evasion", "Execution", "Authentication Package", "Account Discovery"], "cis20": ["CIS 7", "CIS 12", "CIS 2", "CIS 3", "CIS 8"], "kill_chain_phases": ["Exploitation", "Delivery", "Installation", "Command and Control", "Actions on Objectives"], "nist": ["ID.AM", "PR.DS", "PR.IP", "PR.PT", "DE.AE", "DE.CM"]}
|
||||
modification_date = 2018-12-03
|
||||
reference = ["https://www.us-cert.gov/ncas/alerts/TA18-201A", "https://www.first.org/resources/papers/conf2017/Advanced-Incident-Detection-and-Threat-Hunting-using-Sysmon-and-Splunk.pdf", "https://www.vkremez.com/2017/05/emotet-banking-trojan-malware-analysis.html"]
|
||||
providing_technologies = ["Bluecoat", "Bro", "Carbon Black Response", "CrowdStrike Falcon", "Linux", "Microsoft Exchange", "Microsoft Windows", "Palo Alto Firewall", "Splunk Enterprise Security", "Splunk Stream", "Sysmon", "Tanium", "Ziften", "macOS"]
|
||||
@@ -698,7 +698,7 @@ data_models = ["Application_State", "Authentication", "Network_Resolution", "Net
|
||||
description = Detect instances of prohibited network traffic allowed in the environment, as well as protocols running on non-standard ports. Both of these types of behaviors typically violate policy and can be leveraged by attackers.
|
||||
id = 6d13121c-90f3-446d-8ac3-27efbbc65218
|
||||
version = 1.0
|
||||
mappings = {"mitre_attack": ["Command and Control", "Exfiltration Over Command and Control Channel", "Commonly Used Port", "Exfiltration Over Alternative Protocol", "Exfiltration", "Defense Evasion"], "cis20": ["CIS 12", "CIS 13", "CIS 8", "CIS 9"], "kill_chain_phases": ["Command and Control", "Actions on Objectives", "Delivery"], "nist": ["PR.PT", "DE.AE", "DE.CM", "PR.AC", "PR.DS"]}
|
||||
mappings = {"mitre_attack": ["Command and Control", "Exfiltration Over Command and Control Channel", "Commonly Used Port", "Exfiltration Over Alternative Protocol", "Exfiltration", "Defense Evasion"], "cis20": ["CIS 12", "CIS 13", "CIS 8", "CIS 9"], "kill_chain_phases": ["Command and Control", "Delivery", "Actions on Objectives"], "nist": ["PR.PT", "DE.AE", "DE.CM", "PR.AC", "PR.DS"]}
|
||||
modification_date = 2018-07-24
|
||||
reference = ["http://www.novetta.com/2015/02/advanced-methods-to-detect-advanced-cyber-attacks-protocol-abuse/"]
|
||||
providing_technologies = ["Bluecoat", "Bro", "Linux", "Microsoft Windows", "Palo Alto Firewall", "Splunk Enterprise Security", "Splunk Stream", "macOS"]
|
||||
@@ -766,7 +766,7 @@ data_models = ["Application_State", "Authentication", "Endpoint", "Network_Traff
|
||||
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the SamSam ransomware, including looking for file writes associated with SamSam, RDP brute force attacks, the presence of files with SamSam ransomware extensions, suspicious psexec use, and more.
|
||||
id = c4b89506-fbcf-4cb7-bfd6-527e54789604
|
||||
version = 1.0
|
||||
mappings = {"mitre_attack": ["Exploitation of Vulnerability", "Execution", "Commonly Used Port", "Command-Line Interface", "Credential Access", "Lateral Movement", "Defense Evasion", "System Information Discovery", "Remote Desktop Protocol", "Discovery"], "cis20": ["CIS 3", "CIS 18", "CIS 8", "CIS 9", "CIS 10", "CIS 12", "CIS 2", "CIS 4", "CIS 16"], "kill_chain_phases": ["Delivery", "Actions on Objectives", "Reconnaissance", "Installation", "Command and Control"], "nist": ["ID.AM", "PR.DS", "ID.RA", "PR.IP", "PR.PT", "PR.AC", "DE.AE", "PR.MA", "DE.CM"]}
|
||||
mappings = {"mitre_attack": ["Exploitation of Vulnerability", "System Information Discovery", "Commonly Used Port", "Command-Line Interface", "Credential Access", "Lateral Movement", "Defense Evasion", "Execution", "Remote Desktop Protocol", "Discovery"], "cis20": ["CIS 3", "CIS 18", "CIS 8", "CIS 9", "CIS 10", "CIS 12", "CIS 2", "CIS 4", "CIS 16"], "kill_chain_phases": ["Delivery", "Actions on Objectives", "Reconnaissance", "Installation", "Command and Control"], "nist": ["ID.AM", "PR.DS", "ID.RA", "PR.IP", "PR.PT", "PR.AC", "DE.AE", "PR.MA", "DE.CM"]}
|
||||
modification_date = 2018-12-14
|
||||
reference = ["https://www.crowdstrike.com/blog/an-in-depth-analysis-of-samsam-ransomware-and-boss-spider/", "https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/SamSam-ransomware-chooses-Its-targets-carefully-wpna.pdf", "https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/SamSam-The-Almost-Six-Million-Dollar-Ransomware.pdf?cmp=26061"]
|
||||
providing_technologies = ["Apache", "Bluecoat", "Bro", "Carbon Black Response", "CrowdStrike Falcon", "Linux", "Microsoft Windows", "Nessus", "Netbackup", "Palo Alto Firewall", "Splunk Enterprise Security", "Splunk Stream", "Sysmon", "Tanium", "Ziften", "macOS"]
|
||||
@@ -898,7 +898,7 @@ data_models =
|
||||
description = Use the searches in this Analytic Story to monitor your AWS S3 buckets for evidence of anomalous activity and suspicious behaviors, such as detecting open S3 buckets and buckets being accessed from a new IP. The contextual and investigative searches will give you more information, when required.
|
||||
id = 2e8948a5-5239-406b-b56b-6c50w3168af3
|
||||
version = 2.0
|
||||
mappings = {"mitre_attack": ["Exfiltration", "Credential Access", "Execution", "Initial Access"], "cis20": ["CIS 13", "CIS 14"], "kill_chain_phases": ["Actions on Objectives"], "nist": ["DE.CM", "PR.DS", "DE.DP", "PR.AC"]}
|
||||
mappings = {"mitre_attack": ["Exfiltration", "Credential Access", "Execution", "Initial Access"], "cis20": ["CIS 13", "CIS 14"], "kill_chain_phases": ["Actions on Objectives"], "nist": ["DE.DP", "PR.DS", "DE.CM", "PR.AC"]}
|
||||
modification_date = 2018-11-27
|
||||
reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf", "https://www.tripwire.com/state-of-security/security-data-protection/cloud/public-aws-s3-buckets-writable/"]
|
||||
providing_technologies = ["AWS", "Splunk Enterprise Security"]
|
||||
|
||||
+399
-399
File diff suppressed because it is too large
Load Diff
+1345
-1345
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user