diff --git a/detections/network/detect_dga_domains_using_pretrained_model_in_dsdl.yml b/detections/network/detect_dga_domains_using_pretrained_model_in_dsdl.yml index 16cee2fa2b..bf6fe3e506 100644 --- a/detections/network/detect_dga_domains_using_pretrained_model_in_dsdl.yml +++ b/detections/network/detect_dga_domains_using_pretrained_model_in_dsdl.yml @@ -47,7 +47,7 @@ rba: $src$, kindly review. risk_objects: - field: src - type: hostname + type: system score: 63 threat_objects: - field: domain diff --git a/detections/network/detect_dns_data_exfiltration_using_pretrained_model_in_dsdl.yml b/detections/network/detect_dns_data_exfiltration_using_pretrained_model_in_dsdl.yml index 591027cb6e..551eeae22d 100644 --- a/detections/network/detect_dns_data_exfiltration_using_pretrained_model_in_dsdl.yml +++ b/detections/network/detect_dns_data_exfiltration_using_pretrained_model_in_dsdl.yml @@ -51,7 +51,7 @@ rba: message: A DNS data exfiltration request was sent by this host $src$ , kindly review. risk_objects: - field: src - type: hostname + type: system score: 45 threat_objects: - field: query diff --git a/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml b/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml index 761f456178..1e54f28b6a 100644 --- a/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml +++ b/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml @@ -56,7 +56,7 @@ rba: host $host$ risk_objects: - field: host - type: hostname + type: system score: 56 threat_objects: [] tags: diff --git a/detections/network/detect_ipv6_network_infrastructure_threats.yml b/detections/network/detect_ipv6_network_infrastructure_threats.yml index f7699a8589..c15f4fec13 100644 --- a/detections/network/detect_ipv6_network_infrastructure_threats.yml +++ b/detections/network/detect_ipv6_network_infrastructure_threats.yml @@ -42,7 +42,7 @@ rba: message: tbd risk_objects: - field: dest - type: hostname + type: system score: 25 threat_objects: [] tags: diff --git a/detections/network/detect_remote_access_software_usage_dns.yml b/detections/network/detect_remote_access_software_usage_dns.yml index 7d4fdde787..ecb3c9ccc4 100644 --- a/detections/network/detect_remote_access_software_usage_dns.yml +++ b/detections/network/detect_remote_access_software_usage_dns.yml @@ -56,7 +56,7 @@ rba: message: A domain for a known remote access software $query$ was contacted by $src$. risk_objects: - field: src - type: hostname + type: system score: 4 threat_objects: - field: query diff --git a/detections/network/detect_remote_access_software_usage_traffic.yml b/detections/network/detect_remote_access_software_usage_traffic.yml index 2463de187f..b7d0a83612 100644 --- a/detections/network/detect_remote_access_software_usage_traffic.yml +++ b/detections/network/detect_remote_access_software_usage_traffic.yml @@ -57,7 +57,7 @@ rba: detected from $src$. risk_objects: - field: src - type: hostname + type: system score: 25 threat_objects: [] tags: diff --git a/detections/network/detect_snicat_sni_exfiltration.yml b/detections/network/detect_snicat_sni_exfiltration.yml index dec5053fa4..b250e6493b 100644 --- a/detections/network/detect_snicat_sni_exfiltration.yml +++ b/detections/network/detect_snicat_sni_exfiltration.yml @@ -31,7 +31,7 @@ rba: message: tbd risk_objects: - field: dest - type: hostname + type: system score: 25 threat_objects: [] tags: diff --git a/detections/network/detect_software_download_to_network_device.yml b/detections/network/detect_software_download_to_network_device.yml index 146fb2c7b3..e81cf8f34f 100644 --- a/detections/network/detect_software_download_to_network_device.yml +++ b/detections/network/detect_software_download_to_network_device.yml @@ -35,7 +35,7 @@ rba: message: tbd risk_objects: - field: dest - type: hostname + type: system score: 25 threat_objects: [] tags: diff --git a/detections/network/detect_suspicious_dns_txt_records_using_pretrained_model_in_dsdl.yml b/detections/network/detect_suspicious_dns_txt_records_using_pretrained_model_in_dsdl.yml index 437dbaee10..e31dec98cc 100644 --- a/detections/network/detect_suspicious_dns_txt_records_using_pretrained_model_in_dsdl.yml +++ b/detections/network/detect_suspicious_dns_txt_records_using_pretrained_model_in_dsdl.yml @@ -50,7 +50,7 @@ rba: message: A suspicious DNS TXT response was detected on host $src$ , kindly review. risk_objects: - field: src - type: hostname + type: system score: 45 threat_objects: - field: answer diff --git a/detections/network/detect_unauthorized_assets_by_mac_address.yml b/detections/network/detect_unauthorized_assets_by_mac_address.yml index 28763815ab..c1386e0c3d 100644 --- a/detections/network/detect_unauthorized_assets_by_mac_address.yml +++ b/detections/network/detect_unauthorized_assets_by_mac_address.yml @@ -34,7 +34,7 @@ rba: message: tbd risk_objects: - field: dest - type: hostname + type: system score: 25 threat_objects: [] tags: diff --git a/detections/network/detect_zerologon_via_zeek.yml b/detections/network/detect_zerologon_via_zeek.yml index 1ede035e08..bcbd3232fd 100644 --- a/detections/network/detect_zerologon_via_zeek.yml +++ b/detections/network/detect_zerologon_via_zeek.yml @@ -33,7 +33,7 @@ rba: message: tbd risk_objects: - field: dest - type: hostname + type: system score: 25 threat_objects: [] tags: diff --git a/detections/network/dns_query_length_outliers___mltk.yml b/detections/network/dns_query_length_outliers___mltk.yml index d39fe06abe..3182221902 100644 --- a/detections/network/dns_query_length_outliers___mltk.yml +++ b/detections/network/dns_query_length_outliers___mltk.yml @@ -46,7 +46,7 @@ rba: message: tbd risk_objects: - field: dest - type: hostname + type: system score: 25 threat_objects: [] tags: diff --git a/detections/network/dns_query_length_with_high_standard_deviation.yml b/detections/network/dns_query_length_with_high_standard_deviation.yml index d4bfd3163b..9ff3fe733e 100644 --- a/detections/network/dns_query_length_with_high_standard_deviation.yml +++ b/detections/network/dns_query_length_with_high_standard_deviation.yml @@ -45,7 +45,7 @@ rba: query in host $host$ risk_objects: - field: host - type: hostname + type: system score: 56 threat_objects: [] tags: diff --git a/detections/network/excessive_dns_failures.yml b/detections/network/excessive_dns_failures.yml index 723957b61c..374fad8dba 100644 --- a/detections/network/excessive_dns_failures.yml +++ b/detections/network/excessive_dns_failures.yml @@ -33,7 +33,7 @@ rba: message: Excessive DNS failures detected on $src$ risk_objects: - field: src - type: hostname + type: system score: 25 threat_objects: [] tags: diff --git a/detections/network/f5_big_ip_icontrol_rest_vulnerability_cve_2022_1388.yml b/detections/network/f5_big_ip_icontrol_rest_vulnerability_cve_2022_1388.yml index 7912d62963..8dd5900ef6 100644 --- a/detections/network/f5_big_ip_icontrol_rest_vulnerability_cve_2022_1388.yml +++ b/detections/network/f5_big_ip_icontrol_rest_vulnerability_cve_2022_1388.yml @@ -50,7 +50,7 @@ rba: occurred. risk_objects: - field: dest - type: hostname + type: system score: 70 threat_objects: [] tags: diff --git a/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml b/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml index 0bc7102821..d3691e7043 100644 --- a/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml +++ b/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml @@ -42,7 +42,7 @@ rba: message: tbd risk_objects: - field: dest - type: hostname + type: system score: 25 threat_objects: [] tags: diff --git a/detections/network/internal_horizontal_port_scan.yml b/detections/network/internal_horizontal_port_scan.yml index 8a3343125c..bb0720a018 100644 --- a/detections/network/internal_horizontal_port_scan.yml +++ b/detections/network/internal_horizontal_port_scan.yml @@ -50,7 +50,7 @@ rba: IPs risk_objects: - field: src_ip - type: hostname + type: system score: 64 threat_objects: [] tags: diff --git a/detections/network/internal_horizontal_port_scan_nmap_top_20.yml b/detections/network/internal_horizontal_port_scan_nmap_top_20.yml index e512fe519d..3cfa51db21 100644 --- a/detections/network/internal_horizontal_port_scan_nmap_top_20.yml +++ b/detections/network/internal_horizontal_port_scan_nmap_top_20.yml @@ -51,7 +51,7 @@ rba: IPs risk_objects: - field: src_ip - type: hostname + type: system score: 72 threat_objects: [] tags: diff --git a/detections/network/internal_vertical_port_scan.yml b/detections/network/internal_vertical_port_scan.yml index ac2f1d7d66..6eff8c4205 100644 --- a/detections/network/internal_vertical_port_scan.yml +++ b/detections/network/internal_vertical_port_scan.yml @@ -50,7 +50,7 @@ rba: message: $src_ip$ has scanned $totalDestPortCount$ ports on $dest_ip$ risk_objects: - field: src_ip - type: hostname + type: system score: 64 threat_objects: [] tags: diff --git a/detections/network/internal_vulnerability_scan.yml b/detections/network/internal_vulnerability_scan.yml index 736c203dbc..e00307b218 100644 --- a/detections/network/internal_vulnerability_scan.yml +++ b/detections/network/internal_vulnerability_scan.yml @@ -36,7 +36,7 @@ rba: message: Large volume of IDS signatures triggered by $src$ risk_objects: - field: src - type: hostname + type: system score: 64 threat_objects: [] tags: diff --git a/detections/network/large_volume_of_dns_any_queries.yml b/detections/network/large_volume_of_dns_any_queries.yml index 71a095005a..36e219bc11 100644 --- a/detections/network/large_volume_of_dns_any_queries.yml +++ b/detections/network/large_volume_of_dns_any_queries.yml @@ -27,7 +27,7 @@ rba: message: tbd risk_objects: - field: dest - type: hostname + type: system score: 25 threat_objects: [] tags: diff --git a/detections/network/ngrok_reverse_proxy_on_network.yml b/detections/network/ngrok_reverse_proxy_on_network.yml index d2e185f587..9f0aac31d4 100644 --- a/detections/network/ngrok_reverse_proxy_on_network.yml +++ b/detections/network/ngrok_reverse_proxy_on_network.yml @@ -43,7 +43,7 @@ rba: message: An endpoint, $src$, is beaconing out to the reverse proxy service of Ngrok. risk_objects: - field: src - type: hostname + type: system score: 50 threat_objects: [] tags: diff --git a/detections/network/protocol_or_port_mismatch.yml b/detections/network/protocol_or_port_mismatch.yml index 1d815ec5b9..620101ddbb 100644 --- a/detections/network/protocol_or_port_mismatch.yml +++ b/detections/network/protocol_or_port_mismatch.yml @@ -32,7 +32,7 @@ rba: message: tbd risk_objects: - field: dest - type: hostname + type: system score: 25 threat_objects: [] tags: diff --git a/detections/network/protocols_passing_authentication_in_cleartext.yml b/detections/network/protocols_passing_authentication_in_cleartext.yml index 5c738ec7b8..5bfeb9c00b 100644 --- a/detections/network/protocols_passing_authentication_in_cleartext.yml +++ b/detections/network/protocols_passing_authentication_in_cleartext.yml @@ -37,7 +37,7 @@ rba: type: user score: 25 - field: dest - type: hostname + type: system score: 25 threat_objects: [] tags: diff --git a/detections/network/remote_desktop_network_bruteforce.yml b/detections/network/remote_desktop_network_bruteforce.yml index 71c2d1ca65..e50eb5a46e 100644 --- a/detections/network/remote_desktop_network_bruteforce.yml +++ b/detections/network/remote_desktop_network_bruteforce.yml @@ -30,10 +30,10 @@ rba: message: $dest$ may be the target of an RDP Bruteforce risk_objects: - field: dest - type: hostname + type: system score: 25 - field: src - type: hostname + type: system score: 25 threat_objects: [] tags: diff --git a/detections/network/smb_traffic_spike.yml b/detections/network/smb_traffic_spike.yml index c06fb749e4..c64d105564 100644 --- a/detections/network/smb_traffic_spike.yml +++ b/detections/network/smb_traffic_spike.yml @@ -31,7 +31,7 @@ rba: message: Anomalous splike of SMB traffic sent from $src$ risk_objects: - field: src - type: hostname + type: system score: 25 threat_objects: [] tags: diff --git a/detections/network/smb_traffic_spike___mltk.yml b/detections/network/smb_traffic_spike___mltk.yml index 1322231481..db78f7be74 100644 --- a/detections/network/smb_traffic_spike___mltk.yml +++ b/detections/network/smb_traffic_spike___mltk.yml @@ -46,7 +46,7 @@ rba: message: tbd risk_objects: - field: dest - type: hostname + type: system score: 25 threat_objects: [] tags: diff --git a/detections/network/ssl_certificates_with_punycode.yml b/detections/network/ssl_certificates_with_punycode.yml index e57dcde55b..8e88d5145d 100644 --- a/detections/network/ssl_certificates_with_punycode.yml +++ b/detections/network/ssl_certificates_with_punycode.yml @@ -36,7 +36,7 @@ rba: email domain on $dest$. risk_objects: - field: dest - type: hostname + type: system score: 15 threat_objects: [] tags: diff --git a/detections/network/zeek_x509_certificate_with_punycode.yml b/detections/network/zeek_x509_certificate_with_punycode.yml index ce231c8eed..2f9b53863a 100644 --- a/detections/network/zeek_x509_certificate_with_punycode.yml +++ b/detections/network/zeek_x509_certificate_with_punycode.yml @@ -36,7 +36,7 @@ rba: alternative name on $dest$. risk_objects: - field: dest - type: hostname + type: system score: 15 threat_objects: [] tags: