From f1dd70da1ea344a8285d2adbfa591eecb9c00868 Mon Sep 17 00:00:00 2001 From: pyth0n1c Date: Fri, 14 Feb 2025 10:22:46 -0800 Subject: [PATCH] update and pull in all the latest changes from develop branch --- ...ct_distributed_password_spray_attempts.yml | 5 +- .../detect_password_spray_attempts.yml | 5 +- ...itten_outside_of_the_outlook_directory.yml | 5 +- ...s_sending_high_volume_traffic_to_hosts.yml | 5 +- ...entication_failed_during_mfa_challenge.yml | 8 +- ...a_multi_factor_authentication_disabled.yml | 5 +- .../okta_new_api_token_created.yml | 5 +- .../okta_new_device_enrolled_on_account.yml | 5 +- ...g_detection_with_fastpass_origin_check.yml | 5 +- ...uccessful_single_factor_authentication.yml | 8 +- .../okta_suspicious_activity_reported.yml | 5 +- .../okta_threatinsight_threat_detected.yml | 5 +- ..._auth_source_and_verification_response.yml | 2 +- ...suspicious_email_attachment_extensions.yml | 5 +- ...ows_ad_dangerous_deny_acl_modification.yml | 7 +- ...ws_ad_dangerous_group_acl_modification.yml | 7 +- ...ows_ad_dangerous_user_acl_modification.yml | 7 +- .../windows_ad_domain_root_acl_deletion.yml | 7 +- ...indows_ad_domain_root_acl_modification.yml | 7 +- .../windows_ad_gpo_new_cse_addition.yml | 8 +- .../windows_ad_hidden_ou_creation.yml | 7 +- .../windows_ad_object_owner_updated.yml | 7 +- ...s_ad_suspicious_attribute_modification.yml | 7 +- ...windows_ad_suspicious_gpo_modification.yml | 8 +- ...mber_of_cloud_infrastructure_api_calls.yml | 5 +- ...gh_number_of_cloud_instances_destroyed.yml | 5 +- ...igh_number_of_cloud_instances_launched.yml | 5 +- ...mber_of_cloud_security_group_api_calls.yml | 5 +- .../cloud/asl_aws_create_access_key.yml | 35 +++-- ..._policy_version_to_allow_all_resources.yml | 48 ++++-- ..._aws_credential_access_getpassworddata.yml | 46 ++++-- ...s_credential_access_rds_password_reset.yml | 44 ++++-- ..._aws_defense_evasion_delete_cloudtrail.yml | 35 +++-- ...se_evasion_delete_cloudwatch_log_group.yml | 33 +++- ...fense_evasion_impair_security_services.yml | 37 +++-- ...aws_defense_evasion_putbucketlifecycle.yml | 39 +++-- ...efense_evasion_stop_logging_cloudtrail.yml | 39 +++-- ..._aws_defense_evasion_update_cloudtrail.yml | 37 +++-- ...ontainer_upload_outside_business_hours.yml | 40 +++-- ..._aws_ecr_container_upload_unknown_user.yml | 35 ++++- .../asl_aws_iam_successful_group_deletion.yml | 34 +++-- ...s_multi_factor_authentication_disabled.yml | 39 +++-- ...ntrol_list_created_with_all_open_ports.yml | 58 ++++--- ...ws_network_access_control_list_deleted.yml | 49 ++++-- ...aws_new_mfa_method_registered_for_user.yml | 36 +++-- .../cloud/asl_aws_updateloginprofile.yml | 52 +++++-- ...sole_login_failed_during_mfa_challenge.yml | 5 +- ..._policy_version_to_allow_all_resources.yml | 5 +- detections/cloud/aws_createaccesskey.yml | 5 +- detections/cloud/aws_createloginprofile.yml | 5 +- .../aws_credential_access_failed_login.yml | 8 +- .../aws_credential_access_getpassworddata.yml | 8 +- ...s_credential_access_rds_password_reset.yml | 7 +- .../aws_defense_evasion_delete_cloudtrail.yml | 5 +- ...se_evasion_delete_cloudwatch_log_group.yml | 5 +- ...fense_evasion_impair_security_services.yml | 5 +- ...aws_defense_evasion_putbucketlifecycle.yml | 8 +- ...efense_evasion_stop_logging_cloudtrail.yml | 5 +- .../aws_defense_evasion_update_cloudtrail.yml | 5 +- ...s_ecr_container_scanning_findings_high.yml | 5 +- ...ing_findings_low_informational_unknown.yml | 5 +- ...ecr_container_scanning_findings_medium.yml | 5 +- ...ontainer_upload_outside_business_hours.yml | 5 +- .../aws_ecr_container_upload_unknown_user.yml | 5 +- ...mber_of_failed_authentications_from_ip.yml | 5 +- .../aws_iam_successful_group_deletion.yml | 5 +- ...s_multi_factor_authentication_disabled.yml | 8 +- ..._multiple_failed_mfa_requests_for_user.yml | 5 +- ..._users_failing_to_authenticate_from_ip.yml | 5 +- ...ntrol_list_created_with_all_open_ports.yml | 5 +- ...ws_network_access_control_list_deleted.yml | 5 +- ...aws_new_mfa_method_registered_for_user.yml | 5 +- .../cloud/aws_setdefaultpolicyversion.yml | 5 +- ...uccessful_single_factor_authentication.yml | 8 +- ...mber_of_failed_authentications_from_ip.yml | 8 +- detections/cloud/aws_updateloginprofile.yml | 5 +- ...ure_active_directory_high_risk_sign_in.yml | 8 +- ...pplication_administrator_role_assigned.yml | 5 +- ...entication_failed_during_mfa_challenge.yml | 8 +- ...azure_ad_azurehound_useragent_detected.yml | 2 +- .../azure_ad_device_code_authentication.yml | 5 +- .../azure_ad_external_guest_user_invited.yml | 2 +- ...ber_of_failed_authentications_for_user.yml | 5 +- ...mber_of_failed_authentications_from_ip.yml | 5 +- ...d_multi_factor_authentication_disabled.yml | 8 +- ...ti_source_failed_authentications_spike.yml | 8 +- ..._multiple_failed_mfa_requests_for_user.yml | 8 +- ..._users_failing_to_authenticate_from_ip.yml | 8 +- .../azure_ad_new_custom_domain_added.yml | 5 +- .../azure_ad_new_federated_domain_added.yml | 5 +- .../azure_ad_new_mfa_method_registered.yml | 5 +- ..._ad_new_mfa_method_registered_for_user.yml | 5 +- .../cloud/azure_ad_pim_role_assigned.yml | 5 +- ...azure_ad_pim_role_assignment_activated.yml | 5 +- .../azure_ad_privileged_role_assigned.yml | 5 +- ...ged_role_assigned_to_service_principal.yml | 5 +- ...azure_ad_service_principal_enumeration.yml | 2 +- ...rvice_principal_new_client_credentials.yml | 5 +- ...azure_ad_service_principal_owner_added.yml | 2 +- ...service_principal_privilege_escalation.yml | 45 ++++-- ...sful_authentication_from_different_ips.yml | 5 +- ...d_successful_powershell_authentication.yml | 8 +- ...uccessful_single_factor_authentication.yml | 8 +- ...e_ad_tenant_wide_admin_consent_granted.yml | 5 +- ...mber_of_failed_authentications_from_ip.yml | 8 +- ...ure_ad_user_enabled_and_password_reset.yml | 2 +- ..._ad_user_immutableid_attribute_updated.yml | 2 +- .../azure_automation_account_created.yml | 5 +- .../azure_automation_runbook_created.yml | 5 +- .../cloud/azure_runbook_webhook_created.yml | 5 +- ...ance_created_by_previously_unseen_user.yml | 5 +- ...nce_modified_by_previously_unseen_user.yml | 5 +- .../detect_aws_console_login_by_new_user.yml | 7 +- ...ws_console_login_by_user_from_new_city.yml | 7 +- ...console_login_by_user_from_new_country.yml | 7 +- ..._console_login_by_user_from_new_region.yml | 7 +- ...entication_failed_during_mfa_challenge.yml | 8 +- ...p_multi_factor_authentication_disabled.yml | 8 +- ..._multiple_failed_mfa_requests_for_user.yml | 8 +- ..._users_failing_to_authenticate_from_ip.yml | 8 +- ...uccessful_single_factor_authentication.yml | 8 +- ...mber_of_failed_authentications_from_ip.yml | 8 +- ...thub_actions_disable_security_workflow.yml | 5 +- detections/cloud/github_dependabot_alert.yml | 5 +- .../github_pull_request_from_unknown_user.yml | 5 +- .../gsuite_drive_share_in_external_email.yml | 5 +- .../gsuite_email_suspicious_attachment.yml | 5 +- ...ail_suspicious_subject_with_attachment.yml | 5 +- ...mail_with_known_abuse_web_service_link.yml | 5 +- ...ail_with_attachment_to_external_domain.yml | 5 +- .../gsuite_suspicious_shared_file_name.yml | 5 +- ...of_login_failures_from_a_single_source.yml | 5 +- ...365_add_app_role_assignment_grant_user.yml | 5 +- .../cloud/o365_added_service_principal.yml | 5 +- .../cloud/o365_advanced_audit_disabled.yml | 5 +- ...application_available_to_other_tenants.yml | 5 +- ...applicationimpersonation_role_assigned.yml | 5 +- .../cloud/o365_bypass_mfa_via_trusted_ip.yml | 5 +- ...365_compliance_content_search_exported.yml | 5 +- ...o365_compliance_content_search_started.yml | 5 +- ...5_elevated_mailbox_permission_assigned.yml | 5 +- ...email_access_by_security_administrator.yml | 7 +- ...mail_reported_by_admin_found_malicious.yml | 5 +- ...email_reported_by_user_found_malicious.yml | 5 +- .../o365_email_security_feature_changed.yml | 7 +- .../o365_email_suspicious_behavior_alert.yml | 5 +- .../o365_email_transport_rule_changed.yml | 67 ++++++++ ...ber_of_failed_authentications_for_user.yml | 5 +- .../o365_high_privilege_role_granted.yml | 5 +- .../o365_mailbox_email_forwarding_enabled.yml | 5 +- ...ailbox_folder_read_permission_assigned.yml | 5 +- ...mailbox_folder_read_permission_granted.yml | 5 +- ...box_inbox_folder_shared_with_all_users.yml | 5 +- ...box_read_access_granted_to_application.yml | 8 +- ...ti_source_failed_authentications_spike.yml | 8 +- ...le_os_vendors_authenticating_from_user.yml | 66 ++++++++ ..._users_failing_to_authenticate_from_ip.yml | 8 +- ...o365_new_email_forwarding_rule_created.yml | 5 +- ...o365_new_email_forwarding_rule_enabled.yml | 5 +- .../cloud/o365_new_federated_domain_added.yml | 5 +- .../cloud/o365_new_mfa_method_registered.yml | 5 +- .../cloud/o365_privileged_role_assigned.yml | 5 +- ...ged_role_assigned_to_service_principal.yml | 5 +- .../cloud/o365_safe_links_detection.yml | 5 +- ...ecurity_and_compliance_alert_triggered.yml | 5 +- ...rvice_principal_new_client_credentials.yml | 5 +- ...service_principal_privilege_escalation.yml | 39 +++-- .../o365_sharepoint_malware_detection.yml | 5 +- ..._sharepoint_suspicious_search_behavior.yml | 67 ++++++++ ...o365_tenant_wide_admin_consent_granted.yml | 5 +- ...ntelligence_suspicious_email_delivered.yml | 5 +- ..._intelligence_suspicious_file_detected.yml | 5 +- .../cloud/o365_zap_activity_detection.yml | 5 +- ...isk_rule_for_dev_sec_ops_by_repository.yml | 5 +- .../account_discovery_with_net_app.yml | 5 +- .../attempt_to_stop_security_service.yml | 5 +- ...dential_dump_from_registry_via_reg_exe.yml | 5 +- ...ovisioning_from_previously_unseen_city.yml | 4 +- ...sioning_from_previously_unseen_country.yml | 14 +- ...isioning_from_previously_unseen_region.yml | 4 +- .../change_default_file_association.yml | 5 +- ...cmdline_tool_not_executed_in_cmd_shell.yml | 5 +- .../correlation_by_repository_and_risk.yml | 5 +- .../correlation_by_user_and_risk.yml | 5 +- ...ate_local_admin_accounts_using_net_exe.yml | 5 +- .../deprecated/deleting_of_net_users.yml | 18 +-- ...ivity_related_to_pass_the_hash_attacks.yml | 5 +- ...ct_critical_alerts_from_security_tools.yml | 38 +---- ...to_phishing_sites_leveraging_evilginx2.yml | 6 +- .../detect_mimikatz_using_loaded_images.yml | 5 +- .../detect_new_api_calls_from_user_roles.yml | 6 +- .../detect_new_user_aws_console_login.yml | 6 +- ...system_network_configuration_discovery.yml | 21 +-- .../detect_webshell_exploit_behavior.yml | 5 +- .../deprecated/disabling_net_user_account.yml | 18 +-- .../domain_account_discovery_with_net_app.yml | 5 +- .../domain_group_discovery_with_net.yml | 5 +- .../elevated_group_discovery_with_net.yml | 5 +- .../deprecated/excel_spawning_powershell.yml | 5 +- .../excel_spawning_windows_script_host.yml | 12 +- .../excessive_service_stop_attempt.yml | 17 ++- .../deprecated/excessive_usage_of_net_app.yml | 19 +-- .../extraction_of_registry_hives.yml | 5 +- .../known_services_killed_by_ransomware.yml | 10 +- .../linux_auditd_find_private_keys.yml | 5 +- .../local_account_discovery_with_net.yml | 5 +- .../mshtml_module_load_in_office_product.yml | 5 +- ...h_invalid_credentials_from_the_same_ip.yml | 7 +- .../deprecated/net_localgroup_discovery.yml | 5 +- .../network_connection_discovery_with_net.yml | 18 +-- ...o365_suspicious_admin_email_forwarding.yml | 5 +- .../o365_suspicious_rights_delegation.yml | 8 +- .../o365_suspicious_user_email_forwarding.yml | 5 +- .../office_application_drop_executable.yml | 5 +- ...ice_application_spawn_regsvr32_process.yml | 5 +- ...ice_application_spawn_rundll32_process.yml | 5 +- ...office_document_creating_schedule_task.yml | 5 +- .../office_document_executing_macro_code.yml | 5 +- ...ment_spawned_child_process_to_download.yml | 5 +- .../office_product_spawn_cmd_process.yml | 5 +- .../office_product_spawning_bitsadmin.yml | 5 +- .../office_product_spawning_certutil.yml | 5 +- .../office_product_spawning_mshta.yml | 5 +- ..._product_spawning_rundll32_with_no_dll.yml | 5 +- ...e_product_spawning_windows_script_host.yml | 5 +- .../office_product_spawning_wmic.yml | 5 +- .../office_product_writing_cab_or_inf.yml | 5 +- .../deprecated/office_spawning_control.yml | 5 +- .../okta_account_lockout_events.yml | 5 +- .../deprecated/okta_failed_sso_attempts.yml | 5 +- ..._login_failure_with_high_unknown_users.yml | 5 +- ...insight_suspected_passwordspray_attack.yml | 5 +- .../osquery_pack___coldroot_detection.yml | 2 +- .../password_policy_discovery_with_net.yml | 19 +-- .../remote_desktop_network_bruteforce.yml | 58 +++++++ .../remote_system_discovery_with_net.yml | 31 +--- .../suspicious_driver_loaded_path.yml | 9 +- .../suspicious_process_file_path.yml | 10 +- .../deprecated/suspicious_rundll32_rename.yml | 8 +- ...dows_command_shell_fetch_env_variables.yml | 17 ++- ...indows_dll_search_order_hijacking_hunt.yml | 5 +- .../windows_lateral_tool_transfer_remcom.yml | 2 +- .../windows_modify_registry_reg_restore.yml | 18 +-- ...ndows_msiexec_with_network_connections.yml | 19 +-- ...ows_network_share_interaction_with_net.yml | 14 +- .../windows_office_product_spawning_msdt.yml | 5 +- .../windows_query_registry_reg_save.yml | 16 +- ...id_account_with_never_expires_password.yml | 17 ++- .../deprecated/winword_spawning_cmd.yml | 5 +- .../winword_spawning_powershell.yml | 5 +- .../winword_spawning_windows_script_host.yml | 5 +- .../7zip_commandline_to_smb_share_path.yml | 5 +- .../access_lsass_memory_for_dump_creation.yml | 5 +- .../active_setup_registry_autostart.yml | 5 +- ...d_defaultuser_and_password_in_registry.yml | 5 +- .../add_or_set_windows_defender_exclusion.yml | 5 +- .../adsisearcher_account_discovery.yml | 5 +- ..._file_and_printing_sharing_in_firewall.yml | 5 +- ...ound_traffic_by_firewall_rule_registry.yml | 5 +- ...allow_inbound_traffic_in_firewall_rule.yml | 5 +- .../allow_network_discovery_in_firewall.yml | 5 +- .../endpoint/anomalous_usage_of_7zip.yml | 5 +- .../endpoint/any_powershell_downloadfile.yml | 8 +- .../any_powershell_downloadstring.yml | 5 +- .../endpoint/attacker_tools_on_endpoint.yml | 7 +- ..._to_add_certificate_to_untrusted_store.yml | 5 +- .../auto_admin_logon_registry_entry.yml | 5 +- .../endpoint/batch_file_write_to_system32.yml | 5 +- .../bcdedit_failure_recovery_modification.yml | 2 +- detections/endpoint/bits_job_persistence.yml | 2 +- .../endpoint/bitsadmin_download_file.yml | 2 +- ...load_with_urlcache_and_split_arguments.yml | 2 +- ...oad_with_verifyctl_and_split_arguments.yml | 2 +- .../certutil_exe_certificate_extraction.yml | 2 +- .../certutil_with_decode_argument.yml | 2 +- .../check_elevated_cmd_using_whoami.yml | 2 +- ...ar_unallocated_sector_using_cipher_app.yml | 5 +- .../endpoint/clop_common_exec_parameter.yml | 2 +- ...cmd_carry_out_string_command_parameter.yml | 5 +- .../endpoint/cmd_echo_pipe___escalation.yml | 6 +- .../endpoint/cmlua_or_cmstplua_uac_bypass.yml | 5 +- .../endpoint/common_ransomware_extensions.yml | 2 +- .../endpoint/conti_common_exec_parameter.yml | 2 +- ..._loading_from_world_writable_directory.yml | 5 +- ...or_delete_windows_shares_using_net_exe.yml | 5 +- .../create_remote_thread_into_lsass.yml | 5 +- .../creation_of_lsass_dump_with_taskmgr.yml | 5 +- .../endpoint/creation_of_shadow_copy.yml | 5 +- ...f_shadow_copy_with_wmic_and_powershell.yml | 5 +- ...ping_via_copy_command_from_shadow_copy.yml | 5 +- ...ial_dumping_via_symlink_to_shadow_copy.yml | 5 +- .../csc_net_on_the_fly_compilation.yml | 5 +- .../endpoint/deleting_shadow_copies.yml | 2 +- ...tect_azurehound_command_line_arguments.yml | 12 +- .../detect_azurehound_file_modifications.yml | 12 +- ...y_with_powershell_script_block_logging.yml | 7 +- .../detect_certipy_file_modifications.yml | 2 +- ...f_shadowcopy_with_script_block_logging.yml | 5 +- ...redential_dumping_through_lsass_access.yml | 5 +- ...e_with_powershell_script_block_logging.yml | 5 +- ...cessive_account_lockouts_from_endpoint.yml | 5 +- ...detect_excessive_user_account_lockouts.yml | 5 +- .../endpoint/detect_exchange_web_shell.yml | 31 ++-- .../endpoint/detect_html_help_renamed.yml | 5 +- .../detect_html_help_spawn_child_process.yml | 5 +- .../detect_html_help_url_in_command_line.yml | 5 +- ...l_help_using_infotech_storage_handlers.yml | 5 +- ...z_with_powershell_script_block_logging.yml | 2 +- .../detect_mshta_inline_hta_execution.yml | 5 +- detections/endpoint/detect_mshta_renamed.yml | 5 +- .../detect_mshta_url_in_command_line.yml | 5 +- .../detect_new_local_admin_account.yml | 5 +- .../detect_outlook_exe_writing_a_zip_file.yml | 5 +- ...word_spray_attack_behavior_from_source.yml | 5 +- ...password_spray_attack_behavior_on_user.yml | 5 +- ...nterception_by_creation_of_program_exe.yml | 5 +- ...ohibited_applications_spawning_cmd_exe.yml | 5 +- .../detect_psexec_with_accepteula_flag.yml | 5 +- .../detect_rclone_command_line_usage.yml | 2 +- .../detect_regasm_spawning_a_process.yml | 5 +- .../detect_regasm_with_network_connection.yml | 5 +- ..._regasm_with_no_command_line_arguments.yml | 5 +- .../detect_regsvcs_spawning_a_process.yml | 5 +- ...detect_regsvcs_with_network_connection.yml | 5 +- ...regsvcs_with_no_command_line_arguments.yml | 5 +- ...ct_regsvr32_application_control_bypass.yml | 5 +- ...tect_remote_access_software_usage_file.yml | 9 +- ..._remote_access_software_usage_fileinfo.yml | 12 +- ...t_remote_access_software_usage_process.yml | 9 +- ..._remote_access_software_usage_registry.yml | 3 +- detections/endpoint/detect_renamed_7_zip.yml | 5 +- detections/endpoint/detect_renamed_psexec.yml | 8 +- detections/endpoint/detect_renamed_winrar.yml | 8 +- .../endpoint/detect_rtlo_in_file_name.yml | 5 +- .../endpoint/detect_rtlo_in_process.yml | 5 +- ...2_application_control_bypass___advpack.yml | 5 +- ..._application_control_bypass___setupapi.yml | 5 +- ..._application_control_bypass___syssetup.yml | 5 +- .../detect_rundll32_inline_hta_execution.yml | 5 +- ...tect_sharphound_command_line_arguments.yml | 12 +- .../detect_sharphound_file_modifications.yml | 12 +- .../endpoint/detect_sharphound_usage.yml | 12 +- ...ssnames_using_pretrained_model_in_dsdl.yml | 2 +- ..._cmd_exe_to_launch_script_interpreters.yml | 5 +- ...ect_wmi_event_subscription_persistence.yml | 5 +- .../disable_amsi_through_registry.yml | 5 +- .../disable_defender_antivirus_registry.yml | 5 +- ...able_defender_blockatfirstseen_feature.yml | 5 +- ...disable_defender_enhanced_notification.yml | 5 +- .../disable_defender_mpengine_registry.yml | 5 +- .../disable_defender_spynet_reporting.yml | 5 +- ...efender_submit_samples_consent_feature.yml | 5 +- .../endpoint/disable_etw_through_registry.yml | 5 +- .../endpoint/disable_logs_using_wevtutil.yml | 5 +- detections/endpoint/disable_registry_tool.yml | 7 +- detections/endpoint/disable_schedule_task.yml | 5 +- .../endpoint/disable_show_hidden_files.yml | 10 +- .../disable_uac_remote_restriction.yml | 5 +- .../endpoint/disable_windows_app_hotkeys.yml | 7 +- .../disable_windows_behavior_monitoring.yml | 5 +- ...disable_windows_smartscreen_protection.yml | 5 +- ...thentication_discovery_with_get_aduser.yml | 5 +- ...uthentication_discovery_with_powerview.yml | 5 +- .../endpoint/disabling_cmd_application.yml | 7 +- .../endpoint/disabling_controlpanel.yml | 7 +- .../endpoint/disabling_defender_services.yml | 5 +- .../disabling_firewall_with_netsh.yml | 5 +- ...isabling_folderoptions_windows_feature.yml | 5 +- .../endpoint/disabling_norun_windows_app.yml | 7 +- .../disabling_remote_user_account_control.yml | 5 +- .../endpoint/disabling_task_manager.yml | 5 +- .../dns_exfiltration_using_nslookup_app.yml | 2 +- .../domain_account_discovery_with_dsquery.yml | 5 +- .../domain_account_discovery_with_wmic.yml | 5 +- ...main_group_discovery_with_adsisearcher.yml | 5 +- .../domain_group_discovery_with_dsquery.yml | 5 +- .../domain_group_discovery_with_wmic.yml | 5 +- .../endpoint/drop_icedid_license_dat.yml | 5 +- .../endpoint/dsquery_domain_discovery.yml | 2 +- .../endpoint/dump_lsass_via_comsvcs_dll.yml | 5 +- .../endpoint/dump_lsass_via_procdump.yml | 5 +- ...levated_group_discovery_with_powerview.yml | 5 +- .../elevated_group_discovery_with_wmic.yml | 5 +- detections/endpoint/esentutl_sam_copy.yml | 5 +- detections/endpoint/etw_registry_disabled.yml | 7 +- detections/endpoint/eventvwr_uac_bypass.yml | 5 +- ...r_of_service_control_start_as_disabled.yml | 5 +- .../excessive_usage_of_sc_service_utility.yml | 5 +- .../endpoint/excessive_usage_of_taskkill.yml | 5 +- .../exchange_powershell_module_usage.yml | 5 +- ...le_written_in_administrative_smb_share.yml | 5 +- ...cute_javascript_with_jscript_com_clsid.yml | 5 +- ...ution_of_file_with_multiple_extensions.yml | 5 +- .../endpoint/file_with_samsam_extension.yml | 2 +- .../firewall_allowed_program_enable.yml | 5 +- ...irst_time_seen_running_windows_service.yml | 5 +- detections/endpoint/fodhelper_uac_bypass.yml | 5 +- .../endpoint/get_aduser_with_powershell.yml | 5 +- ...et_aduser_with_powershell_script_block.yml | 5 +- .../get_domainuser_with_powershell.yml | 5 +- ...omainuser_with_powershell_script_block.yml | 5 +- .../get_wmiobject_group_discovery.yml | 5 +- ...up_discovery_with_script_block_logging.yml | 5 +- .../endpoint/getadgroup_with_powershell.yml | 5 +- ...etadgroup_with_powershell_script_block.yml | 5 +- .../getdomaingroup_with_powershell.yml | 5 +- ...maingroup_with_powershell_script_block.yml | 5 +- .../endpoint/getlocaluser_with_powershell.yml | 5 +- ...localuser_with_powershell_script_block.yml | 7 +- .../getwmiobject_ds_group_with_powershell.yml | 5 +- ..._ds_group_with_powershell_script_block.yml | 5 +- .../getwmiobject_ds_user_with_powershell.yml | 5 +- ...t_ds_user_with_powershell_script_block.yml | 5 +- ...wmiobject_user_account_with_powershell.yml | 5 +- ...r_account_with_powershell_script_block.yml | 7 +- ...no_command_line_arguments_with_network.yml | 2 +- ...dless_browser_mockbin_or_mocky_request.yml | 2 +- .../hide_user_account_from_sign_in_screen.yml | 5 +- ..._files_and_directories_with_attrib_exe.yml | 5 +- ...did_exfiltrated_archived_file_creation.yml | 5 +- ...ateral_movement_commandline_parameters.yml | 5 +- ...ovement_smbexec_commandline_parameters.yml | 5 +- ...ovement_wmiexec_commandline_parameters.yml | 5 +- ...ion_on_remote_endpoint_with_powershell.yml | 5 +- .../jscript_execution_using_cscript_app.yml | 5 +- ...asting_spn_request_with_rc4_encryption.yml | 5 +- ...on_flag_disabled_in_useraccountcontrol.yml | 8 +- ...tication_flag_disabled_with_powershell.yml | 5 +- ...ce_ticket_request_using_rc4_encryption.yml | 5 +- .../endpoint/kerberos_user_enumeration.yml | 5 +- ...nt_manipulation_of_ssh_config_and_keys.yml | 7 +- ...add_files_in_known_crontab_directories.yml | 5 +- .../endpoint/linux_add_user_account.yml | 5 +- ...ux_adding_crontab_using_list_parameter.yml | 5 +- .../linux_apt_get_privilege_escalation.yml | 5 +- .../linux_apt_privilege_escalation.yml | 5 +- .../linux_at_allow_config_file_creation.yml | 5 +- .../linux_at_application_execution.yml | 5 +- .../linux_auditd_add_user_account.yml | 5 +- .../linux_auditd_add_user_account_type.yml | 5 +- .../linux_auditd_at_application_execution.yml | 5 +- ...linux_auditd_change_file_owner_to_root.yml | 42 +++-- ...ditd_disable_or_modify_system_firewall.yml | 5 +- .../linux_auditd_doas_conf_file_creation.yml | 5 +- .../linux_auditd_doas_tool_execution.yml | 5 +- ...linux_auditd_edit_cron_table_parameter.yml | 5 +- ...file_permission_modification_via_chmod.yml | 10 +- ...le_permissions_modification_via_chattr.yml | 39 +++-- ...ind_credentials_from_password_managers.yml | 26 +++- ..._find_credentials_from_password_stores.yml | 45 ++++-- .../linux_auditd_find_ssh_private_keys.yml | 45 ++++-- ..._hidden_files_and_directories_creation.yml | 8 +- ...ert_kernel_module_using_insmod_utility.yml | 11 +- ...l_kernel_module_using_modprobe_utility.yml | 41 +++-- ...ditd_kernel_module_using_rmmod_utility.yml | 5 +- ..._auditd_nopasswd_entry_in_sudoers_file.yml | 8 +- ...ss_or_modification_of_sshd_config_file.yml | 5 +- ...td_possible_access_to_credential_files.yml | 8 +- ...auditd_possible_access_to_sudoers_file.yml | 8 +- ...cronjob_entry_on_existing_cronjob_file.yml | 11 +- ...ux_auditd_preload_hijack_library_calls.yml | 8 +- ...auditd_preload_hijack_via_preload_file.yml | 8 +- ...ivate_keys_and_certificate_enumeration.yml | 47 ++++-- .../linux_auditd_service_restarted.yml | 5 +- .../endpoint/linux_auditd_service_started.yml | 9 +- ...inux_auditd_setuid_using_chmod_utility.yml | 5 +- ...nux_auditd_setuid_using_setcap_utility.yml | 45 ++++-- .../linux_auditd_sudo_or_su_execution.yml | 42 +++-- ..._unix_shell_configuration_modification.yml | 5 +- ...inux_auditd_unload_module_via_modprobe.yml | 43 ++++-- .../linux_awk_privilege_escalation.yml | 5 +- .../linux_busybox_privilege_escalation.yml | 5 +- .../linux_c89_privilege_escalation.yml | 5 +- .../linux_c99_privilege_escalation.yml | 5 +- .../linux_change_file_owner_to_root.yml | 5 +- ...x_common_process_for_elevation_control.yml | 8 +- .../linux_composer_privilege_escalation.yml | 5 +- .../linux_cpulimit_privilege_escalation.yml | 5 +- .../linux_csvtool_privilege_escalation.yml | 5 +- .../linux_data_destruction_command.yml | 2 +- .../endpoint/linux_decode_base64_to_shell.yml | 2 +- .../endpoint/linux_deletion_of_cron_jobs.yml | 7 +- .../linux_deletion_of_init_daemon_script.yml | 7 +- .../endpoint/linux_deletion_of_services.yml | 7 +- .../linux_deletion_of_ssl_certificate.yml | 7 +- .../linux_doas_conf_file_creation.yml | 5 +- .../endpoint/linux_doas_tool_execution.yml | 5 +- .../linux_docker_privilege_escalation.yml | 5 +- .../linux_edit_cron_table_parameter.yml | 5 +- .../linux_emacs_privilege_escalation.yml | 5 +- ...ile_created_in_kernel_driver_directory.yml | 5 +- ...x_file_creation_in_init_boot_directory.yml | 8 +- ...nux_file_creation_in_profile_directory.yml | 5 +- .../linux_find_privilege_escalation.yml | 5 +- .../linux_gdb_privilege_escalation.yml | 5 +- .../linux_gem_privilege_escalation.yml | 5 +- .../linux_gnu_awk_privilege_escalation.yml | 5 +- ...quency_of_file_deletion_in_boot_folder.yml | 7 +- ...equency_of_file_deletion_in_etc_folder.yml | 7 +- .../linux_impair_defenses_process_kill.yml | 5 +- ...ndicator_removal_service_file_deletion.yml | 5 +- ...ert_kernel_module_using_insmod_utility.yml | 5 +- ...l_kernel_module_using_modprobe_utility.yml | 5 +- .../linux_iptables_firewall_modification.yml | 8 +- .../endpoint/linux_java_spawning_shell.yml | 2 +- .../linux_kernel_module_enumeration.yml | 2 +- ...orker_process_in_writable_process_path.yml | 5 +- .../linux_make_privilege_escalation.yml | 5 +- .../linux_mysql_privilege_escalation.yml | 5 +- .../linux_ngrok_reverse_proxy_usage.yml | 2 +- .../linux_node_privilege_escalation.yml | 5 +- .../linux_nopasswd_entry_in_sudoers_file.yml | 8 +- ...ted_files_or_information_base64_decode.yml | 2 +- .../linux_octave_privilege_escalation.yml | 5 +- .../linux_openvpn_privilege_escalation.yml | 5 +- .../linux_php_privilege_escalation.yml | 5 +- .../linux_pkexec_privilege_escalation.yml | 2 +- ...ss_or_modification_of_sshd_config_file.yml | 5 +- ...ux_possible_access_to_credential_files.yml | 8 +- .../linux_possible_access_to_sudoers_file.yml | 8 +- ...append_command_to_at_allow_config_file.yml | 5 +- ..._append_command_to_profile_config_file.yml | 5 +- ...cronjob_entry_on_existing_cronjob_file.yml | 5 +- ...sible_cronjob_modification_with_editor.yml | 5 +- .../linux_possible_ssh_key_file_creation.yml | 5 +- .../linux_preload_hijack_library_calls.yml | 8 +- .../endpoint/linux_proxy_socks_curl.yml | 2 +- .../linux_puppet_privilege_escalation.yml | 5 +- .../linux_rpm_privilege_escalation.yml | 5 +- .../linux_ruby_privilege_escalation.yml | 5 +- ...vice_file_created_in_systemd_directory.yml | 5 +- .../endpoint/linux_service_restarted.yml | 5 +- .../linux_service_started_or_enabled.yml | 5 +- .../linux_setuid_using_chmod_utility.yml | 5 +- .../linux_setuid_using_setcap_utility.yml | 5 +- .../linux_sqlite3_privilege_escalation.yml | 5 +- ...linux_ssh_authorized_keys_modification.yml | 2 +- ...nux_ssh_remote_services_script_execute.yml | 2 +- ...ux_stdout_redirection_to_dev_null_file.yml | 5 +- .../endpoint/linux_sudo_or_su_execution.yml | 5 +- .../linux_sudoers_tmp_file_creation.yml | 8 +- ..._unix_shell_enable_all_sysrq_functions.yml | 5 +- .../linux_visudo_utility_execution.yml | 5 +- .../endpoint/loading_of_dynwrapx_module.yml | 5 +- .../local_account_discovery_with_wmic.yml | 5 +- .../logon_script_event_trigger_execution.yml | 5 +- detections/endpoint/macos_lolbin.yml | 5 +- .../endpoint/mailsniper_invoke_functions.yml | 5 +- ...cious_powershell_executed_as_a_service.yml | 5 +- ...hell_process___execution_policy_bypass.yml | 8 +- ...ll_process_with_obfuscation_techniques.yml | 5 +- .../microsoft_defender_atp_alerts.yml | 2 +- .../microsoft_defender_incident_alerts.yml | 2 +- ...z_passtheticket_commandline_parameters.yml | 5 +- .../mmc_lolbas_execution_process_spawn.yml | 5 +- ...nitor_registry_keys_for_print_monitors.yml | 5 +- ...on_service_writing_active_server_pages.yml | 9 +- ..._scripting_process_loading_ldap_module.yml | 5 +- ...s_scripting_process_loading_wmi_module.yml | 5 +- ...d_suspicious_spawned_by_script_process.yml | 5 +- ..._spawning_rundll32_or_regsvr32_process.yml | 5 +- ...msi_module_loaded_by_non_system_binary.yml | 5 +- .../msmpeng_application_dll_side_loading.yml | 5 +- .../endpoint/net_profiler_uac_bypass.yml | 5 +- ...work_discovery_using_route_windows_app.yml | 5 +- ...active_directory_web_services_protocol.yml | 12 +- .../endpoint/nishang_powershelltcponeline.yml | 5 +- ...e_process_accessing_chrome_default_dir.yml | 8 +- ...fox_process_access_firefox_profile_dir.yml | 5 +- ...notepad_with_no_command_line_arguments.yml | 2 +- detections/endpoint/ntdsutil_export_ntds.yml | 5 +- .../overwriting_accessibility_binaries.yml | 5 +- ...mission_modification_using_takeown_app.yml | 8 +- .../endpoint/ping_sleep_batch_command.yml | 5 +- .../possible_browser_pass_view_parameter.yml | 5 +- ...ible_lateral_movement_powershell_spawn.yml | 7 +- ...twork_configuration_discovery_activity.yml | 2 +- .../endpoint/powershell_4104_hunting.yml | 8 +- ...connect_to_internet_with_hidden_window.yml | 5 +- ..._hijacking_inprocserver32_modification.yml | 7 +- .../powershell_creating_thread_mutex.yml | 5 +- ...powershell_disable_security_monitoring.yml | 5 +- .../powershell_domain_enumeration.yml | 5 +- .../powershell_enable_powershell_remoting.yml | 5 +- ...powershell_enable_smb1protocol_feature.yml | 5 +- .../powershell_execute_com_object.yml | 7 +- ...s_process_injection_via_getprocaddress.yml | 5 +- ...script_contains_base64_encoded_content.yml | 5 +- .../powershell_get_localgroup_discovery.yml | 5 +- ...up_discovery_with_script_block_logging.yml | 5 +- .../powershell_load_module_in_meterpreter.yml | 5 +- ...ding_dotnet_into_memory_via_reflection.yml | 40 +++-- .../powershell_processing_stream_of_data.yml | 5 +- ...rshell_remote_services_add_trustedhost.yml | 5 +- ...hell_remove_windows_defender_directory.yml | 5 +- .../powershell_start_bitstransfer.yml | 2 +- ...wershell_using_memory_as_backing_store.yml | 5 +- ...ll_windows_defender_exclusion_commands.yml | 5 +- ...nt_automatic_repair_mode_using_bcdedit.yml | 2 +- .../print_processor_registry_autostart.yml | 5 +- .../print_spooler_adding_a_printer_driver.yml | 5 +- ...print_spooler_failed_to_load_a_plug_in.yml | 5 +- ...eating_lnk_file_in_suspicious_location.yml | 5 +- .../process_kill_base_on_file_path.yml | 5 +- .../endpoint/processes_launching_netsh.yml | 5 +- ...randomly_generated_scheduled_task_name.yml | 5 +- ...andomly_generated_windows_service_name.yml | 5 +- .../recon_avproduct_through_pwh_or_wmi.yml | 2 +- ...rsive_delete_of_directory_in_batch_cmd.yml | 5 +- ...ulating_windows_services_registry_keys.yml | 5 +- ...istry_keys_for_creating_shim_databases.yml | 5 +- .../registry_keys_used_for_persistence.yml | 8 +- ...try_keys_used_for_privilege_escalation.yml | 5 +- ...2_silent_and_install_param_dll_loading.yml | 5 +- ...svr32_with_known_silent_switch_cmdline.yml | 5 +- ...mote_desktop_process_running_on_system.yml | 5 +- ..._instantiation_via_dcom_and_powershell.yml | 5 +- ...n_via_dcom_and_powershell_script_block.yml | 5 +- ...instantiation_via_winrm_and_powershell.yml | 5 +- ..._via_winrm_and_powershell_script_block.yml | 5 +- ...cess_instantiation_via_winrm_and_winrs.yml | 5 +- .../rubeus_command_line_parameters.yml | 6 +- ...ticket_exports_through_winlogon_access.yml | 5 +- .../runas_execution_in_commandline.yml | 5 +- .../endpoint/rundll32_control_rundll_hunt.yml | 5 +- ...ontrol_rundll_world_writable_directory.yml | 5 +- detections/endpoint/rundll32_dnsquery.yml | 5 +- .../endpoint/rundll32_lockworkstation.yml | 5 +- ...undll32_process_creating_exe_dll_files.yml | 5 +- ...no_command_line_arguments_with_network.yml | 5 +- .../rundll_loading_dll_by_ordinal.yml | 5 +- .../endpoint/ryuk_wake_on_lan_command.yml | 5 +- .../sam_database_file_access_attempt.yml | 5 +- .../sc_exe_manipulating_windows_services.yml | 5 +- ..._by_app_connect_and_create_adsi_object.yml | 5 +- ...k_creation_on_remote_endpoint_using_at.yml | 5 +- ...eduled_task_deleted_or_created_via_cmd.yml | 8 +- ...led_task_initiation_on_remote_endpoint.yml | 5 +- ...htasks_scheduling_job_on_remote_system.yml | 5 +- .../schtasks_used_for_forcing_a_reboot.yml | 5 +- .../screensaver_event_trigger_execution.yml | 5 +- detections/endpoint/sdclt_uac_bypass.yml | 5 +- .../sdelete_application_execution.yml | 7 +- .../secretdumps_offline_ntds_dumping_tool.yml | 5 +- ...ceprincipalnames_discovery_with_setspn.yml | 2 +- ...ervices_lolbas_execution_process_spawn.yml | 5 +- ...ution_policy_to_unrestricted_or_bypass.yml | 5 +- .../endpoint/shim_database_file_creation.yml | 5 +- ...nstallation_with_suspicious_parameters.yml | 25 ++- .../endpoint/short_lived_windows_accounts.yml | 7 +- .../endpoint/silentcleanup_uac_bypass.yml | 5 +- .../single_letter_process_on_endpoint.yml | 5 +- detections/endpoint/slui_runas_elevated.yml | 5 +- .../endpoint/slui_spawning_a_process.yml | 5 +- .../endpoint/spoolsv_spawning_rundll32.yml | 5 +- .../spoolsv_suspicious_loaded_modules.yml | 5 +- .../spoolsv_suspicious_process_access.yml | 2 +- detections/endpoint/spoolsv_writing_a_dll.yml | 5 +- .../spoolsv_writing_a_dll___sysmon.yml | 5 +- ...uspicious_computer_account_name_change.yml | 5 +- .../endpoint/suspicious_copy_on_system32.yml | 5 +- .../suspicious_event_log_service_behavior.yml | 5 +- .../suspicious_icedid_rundll32_cmdline.yml | 5 +- ...icious_kerberos_service_ticket_request.yml | 5 +- ...ous_microsoft_workflow_compiler_rename.yml | 7 +- .../endpoint/suspicious_msbuild_path.yml | 6 +- .../endpoint/suspicious_msbuild_rename.yml | 6 +- .../endpoint/suspicious_msbuild_spawn.yml | 5 +- .../suspicious_mshta_child_process.yml | 5 +- .../endpoint/suspicious_mshta_spawn.yml | 5 +- .../endpoint/suspicious_plistbuddy_usage.yml | 5 +- ...uspicious_plistbuddy_usage_via_osquery.yml | 5 +- ...ess_dns_query_known_abuse_web_services.yml | 5 +- ...picious_process_with_discord_dns_query.yml | 5 +- .../endpoint/suspicious_reg_exe_process.yml | 2 +- ...ious_regsvr32_register_suspicious_path.yml | 8 +- .../suspicious_rundll32_dllregisterserver.yml | 5 +- ...ous_rundll32_no_command_line_arguments.yml | 5 +- .../suspicious_rundll32_plugininit.yml | 5 +- .../endpoint/suspicious_rundll32_startw.yml | 5 +- ...s_scheduled_task_from_public_directory.yml | 8 +- ...picious_ticket_granting_ticket_request.yml | 5 +- .../endpoint/suspicious_wevtutil_usage.yml | 5 +- ...svchost_lolbas_execution_process_spawn.yml | 5 +- ...rocesses_run_from_unexpected_locations.yml | 5 +- .../system_user_discovery_with_query.yml | 9 +- .../time_provider_persistence_registry.yml | 5 +- .../uac_bypass_mmc_load_unsigned_dll.yml | 7 +- .../uac_bypass_with_colorui_com_object.yml | 5 +- .../endpoint/uninstall_app_using_msiexec.yml | 5 +- .../endpoint/unload_sysmon_filter_driver.yml | 5 +- .../unloading_amsi_via_reflection.yml | 7 +- ..._of_kerberos_service_tickets_requested.yml | 5 +- .../vbscript_execution_using_wscript_app.yml | 5 +- .../endpoint/verclsid_clsid_execution.yml | 5 +- detections/endpoint/w3wp_spawning_shell.yml | 5 +- .../wbemprox_com_object_execution.yml | 5 +- ...ss_connecting_to_ip_check_web_services.yml | 5 +- ...ss_token_manipulation_sedebugprivilege.yml | 8 +- ...lation_winlogon_duplicate_token_handle.yml | 5 +- ...ogon_duplicate_handle_in_uncommon_path.yml | 5 +- ...account_access_removal_via_logoff_exec.yml | 41 +++-- ...iscovery_for_none_disable_user_account.yml | 5 +- ...ows_ad_abnormal_object_access_activity.yml | 5 +- .../windows_ad_adminsdholder_acl_modified.yml | 2 +- ...s_ad_cross_domain_sid_history_addition.yml | 5 +- ...ows_ad_domain_replication_acl_addition.yml | 2 +- ...rivileged_account_sid_history_addition.yml | 5 +- ...s_ad_privileged_object_access_activity.yml | 5 +- ...tion_request_initiated_by_user_account.yml | 5 +- ...t_initiated_from_unsanctioned_location.yml | 5 +- ...ws_ad_same_domain_sid_history_addition.yml | 5 +- ...dows_ad_sid_history_attribute_modified.yml | 5 +- ...n_default_group_policy_object_modified.yml | 5 +- ...dows_admon_group_policy_object_created.yml | 5 +- ..._alternate_datastream___base64_content.yml | 5 +- ...ernate_datastream___executable_content.yml | 5 +- ...ternate_datastream___process_execution.yml | 5 +- .../windows_apache_benchmark_binary.yml | 2 +- ...windows_archive_collected_data_via_rar.yml | 8 +- ...ndows_attempt_to_stop_security_service.yml | 47 ++++-- .../endpoint/windows_autoit3_execution.yml | 2 +- ...roxy_execution_mavinject_dll_injection.yml | 5 +- ...indows_bitlockertogo_process_execution.yml | 4 +- ..._autostart_execution_in_startup_folder.yml | 5 +- .../endpoint/windows_bootloader_inventory.yml | 5 +- ...ws_cached_domain_credentials_reg_query.yml | 5 +- ...ws_certutil_download_with_url_argument.yml | 2 +- ...fault_file_association_for_no_file_ext.yml | 5 +- ..._tool_execution_from_non_shell_process.yml | 47 ++++-- ..._hijacking_inprocserver32_modification.yml | 5 +- ...s_command_shell_dcrat_forkbomb_payload.yml | 5 +- .../endpoint/windows_create_local_account.yml | 5 +- ...te_local_administrator_account_via_net.yml | 44 +++++- ...ential_dumping_lsass_memory_createdump.yml | 2 +- ...sword_stores_chrome_copied_in_temp_dir.yml | 5 +- ...from_web_browsers_saved_in_temp_folder.yml | 5 +- ...dows_credentials_in_registry_reg_query.yml | 5 +- ...ndows_curl_download_to_suspicious_path.yml | 2 +- ...dows_curl_upload_to_remote_destination.yml | 2 +- ...s_default_group_policy_object_modified.yml | 5 +- ...group_policy_object_modified_with_gpme.yml | 5 +- ...dows_defender_exclusion_registry_entry.yml | 5 +- ...ndows_delete_or_modify_system_firewall.yml | 5 +- ...indows_detect_network_scanner_behavior.yml | 143 ++++++++++-------- .../windows_disable_memory_crash_dump.yml | 2 +- ...s_disable_or_modify_tools_via_taskkill.yml | 5 +- ...indows_disable_or_stop_browser_process.yml | 7 +- ...ows_event_logging_disable_http_logging.yml | 8 +- .../windows_disableantispyware_registry.yml | 5 +- .../endpoint/windows_dism_remove_defender.yml | 5 +- ...earch_order_hijacking_hunt_with_sysmon.yml | 5 +- ...l_search_order_hijacking_with_iscsicpl.yml | 2 +- .../windows_dll_side_loading_in_calc.yml | 5 +- ...dll_side_loading_process_child_of_calc.yml | 5 +- ..._dns_query_request_by_telegram_bot_api.yml | 39 +++-- ..._account_discovery_via_get_netcomputer.yml | 5 +- ...ows_dotnet_binary_in_non_standard_path.yml | 6 +- .../windows_driver_load_non_standard_path.yml | 6 +- ...dows_esx_admins_group_creation_via_net.yml | 2 +- ...x_admins_group_creation_via_powershell.yml | 2 +- .../windows_event_for_service_disabled.yml | 5 +- .../endpoint/windows_event_log_cleared.yml | 5 +- ...dows_excessive_disabled_services_event.yml | 5 +- .../windows_excessive_usage_of_net_app.yml | 2 +- ...s_execute_arbitrary_commands_with_msdt.yml | 2 +- .../endpoint/windows_export_certificate.yml | 5 +- ...er_protocol_in_non_common_process_path.yml | 5 +- ..._access_rights_modification_via_icacls.yml | 5 +- ..._organizational_units_with_getdomainou.yml | 5 +- ...ting_acl_with_findinterestingdomainacl.yml | 5 +- .../windows_findstr_gpp_discovery.yml | 5 +- ..._forest_discovery_with_getforestdomain.yml | 5 +- ..._gather_victim_host_information_camera.yml | 5 +- ...indows_gather_victim_identity_sam_info.yml | 5 +- ...ork_info_through_ip_check_web_services.yml | 5 +- ..._local_admin_with_findlocaladminaccess.yml | 5 +- .../windows_group_discovery_via_net.yml | 39 +++-- .../windows_group_policy_object_created.yml | 7 +- ...k_execution_flow_version_dll_side_load.yml | 5 +- ...ttp_network_communication_from_msiexec.yml | 2 +- ...hunting_system_account_targeting_lsass.yml | 5 +- .../windows_iis_components_add_new_module.yml | 5 +- ...nents_get_webglobalmodule_module_query.yml | 5 +- ...s_iis_components_module_failed_to_load.yml | 5 +- ...indows_iis_components_new_module_added.yml | 5 +- ...impair_defense_add_xml_applocker_rules.yml | 5 +- ...ge_win_defender_health_check_intervals.yml | 5 +- ...hange_win_defender_quick_scan_interval.yml | 5 +- ...ense_change_win_defender_throttle_rate.yml | 5 +- ...ense_change_win_defender_tracing_level.yml | 5 +- ..._defense_configure_app_install_control.yml | 5 +- ...ense_define_win_defender_threat_action.yml | 5 +- ...fense_delete_win_defender_context_menu.yml | 5 +- ...e_delete_win_defender_profile_registry.yml | 5 +- ..._deny_security_software_with_applocker.yml | 5 +- ...fense_disable_controlled_folder_access.yml | 5 +- ..._disable_defender_firewall_and_network.yml | 5 +- ..._disable_defender_protocol_recognition.yml | 5 +- ..._impair_defense_disable_pua_protection.yml | 5 +- ...se_disable_realtime_signature_delivery.yml | 5 +- ..._impair_defense_disable_web_evaluation.yml | 5 +- ...defense_disable_win_defender_app_guard.yml | 5 +- ...sable_win_defender_compute_file_hashes.yml | 5 +- ...fense_disable_win_defender_gen_reports.yml | 5 +- ...isable_win_defender_network_protection.yml | 5 +- ..._disable_win_defender_report_infection.yml | 5 +- ...se_disable_win_defender_scan_on_update.yml | 5 +- ...able_win_defender_signature_retirement.yml | 5 +- ...e_overide_win_defender_phishing_filter.yml | 5 +- ...ir_defense_override_smartscreen_prompt.yml | 5 +- ...in_defender_smart_screen_level_to_warn.yml | 5 +- ...r_defenses_disable_auto_logger_session.yml | 8 +- ...nses_disable_av_autostart_via_registry.yml | 2 +- .../windows_impair_defenses_disable_hvci.yml | 5 +- ...nses_disable_win_defender_auto_logging.yml | 5 +- ...s_ingress_tool_transfer_using_explorer.yml | 2 +- ..._input_capture_using_credential_ui_dll.yml | 5 +- .../windows_installutil_credential_theft.yml | 5 +- ...ndows_installutil_in_non_standard_path.yml | 6 +- ..._installutil_remote_network_connection.yml | 5 +- .../windows_installutil_uninstall_option.yml | 5 +- ...tallutil_uninstall_option_with_network.yml | 5 +- ...indows_installutil_url_in_command_line.yml | 5 +- .../windows_iso_lnk_file_creation.yml | 8 +- .../endpoint/windows_java_spawning_shells.yml | 2 +- .../windows_known_abused_dll_created.yml | 5 +- ...s_known_abused_dll_loaded_suspiciously.yml | 5 +- ...s_known_graphicalproton_loaded_modules.yml | 5 +- ...ndows_ldifde_directory_object_behavior.yml | 2 +- ...dows_linked_policies_in_adsi_discovery.yml | 5 +- ...ocal_administrator_credential_stuffing.yml | 5 +- ...indows_lolbas_executed_as_renamed_file.yml | 5 +- ..._lolbas_executed_outside_expected_path.yml | 5 +- ...il_protocol_in_non_common_process_path.yml | 5 +- ...masquerading_explorer_as_child_process.yml | 5 +- .../windows_mimikatz_binary_execution.yml | 2 +- ...ws_modify_registry_valleyrat_c2_config.yml | 2 +- ...odify_registry_valleyrat_pwn_reg_entry.yml | 2 +- ...tem_firewall_with_notable_process_path.yml | 5 +- ..._mof_event_triggered_execution_via_wmi.yml | 2 +- ...change_management_mailbox_cmdlet_usage.yml | 5 +- .../windows_msiexec_dllregisterserver.yml | 2 +- ..._msiexec_hidewindow_rundll32_execution.yml | 5 +- .../windows_msiexec_remote_download.yml | 2 +- ...indows_msiexec_spawn_discovery_command.yml | 2 +- .../endpoint/windows_msiexec_spawn_windbg.yml | 2 +- ...s_msiexec_unregister_dllregisterserver.yml | 2 +- ...dows_multi_hop_proxy_tor_website_query.yml | 5 +- ...rs_failed_to_authenticate_wth_kerberos.yml | 5 +- ...rs_fail_to_authenticate_using_kerberos.yml | 5 +- ...sers_failed_to_authenticate_using_ntlm.yml | 5 +- ...tiple_ntlm_null_domain_authentications.yml | 5 +- ...o_authenticate_wth_explicitcredentials.yml | 5 +- ...d_to_authenticate_from_host_using_ntlm.yml | 5 +- ...rs_failed_to_authenticate_from_process.yml | 5 +- ..._failed_to_authenticate_using_kerberos.yml | 5 +- ...otely_failed_to_authenticate_from_host.yml | 5 +- ...ity_descriptor_set_on_eventlog_channel.yml | 19 +-- ...new_default_file_association_value_set.yml | 42 +++-- .../windows_ngrok_reverse_proxy_usage.yml | 2 +- .../endpoint/windows_nirsoft_advancedrun.yml | 2 +- ...ws_njrat_fileless_storage_via_registry.yml | 5 +- ...ows_non_system_account_targeting_lsass.yml | 5 +- .../endpoint/windows_odbcconf_load_dll.yml | 2 +- .../windows_odbcconf_load_response_file.yml | 2 +- ...office_product_dropped_cab_or_inf_file.yml | 33 +++- ...s_office_product_dropped_uncommon_file.yml | 34 ++++- ...ws_office_product_loaded_mshtml_module.yml | 38 +++-- ...ws_office_product_loading_taskschd_dll.yml | 40 +++-- ...indows_office_product_loading_vbe7_dll.yml | 40 +++-- ...uct_spawned_child_process_for_download.yml | 42 ++++- ...windows_office_product_spawned_control.yml | 15 +- .../windows_office_product_spawned_msdt.yml | 15 +- ...e_product_spawned_rundll32_with_no_dll.yml | 15 +- ...ffice_product_spawned_uncommon_process.yml | 50 ++++-- .../windows_papercut_ng_spawn_shell.yml | 2 +- ...dows_parent_pid_spoofing_with_explorer.yml | 5 +- ...ws_phishing_pdf_file_executes_url_link.yml | 5 +- ...dows_phishing_recent_iso_exec_registry.yml | 5 +- .../windows_possible_credential_dumping.yml | 5 +- ...ll_add_module_to_global_assembly_cache.yml | 5 +- ...dows_powershell_cryptography_namespace.yml | 5 +- ...indows_powershell_disable_http_logging.yml | 8 +- .../windows_powershell_export_certificate.yml | 5 +- ...ndows_powershell_export_pfxcertificate.yml | 5 +- ...l_iis_components_webglobalmodule_usage.yml | 5 +- ...ows_powershell_import_applocker_policy.yml | 6 +- ...ndows_powershell_logoff_user_via_quser.yml | 42 +++-- .../windows_powershell_remotesigned_file.yml | 5 +- .../windows_powershell_scheduletask.yml | 5 +- ...dows_powershell_wmi_win32_scheduledjob.yml | 5 +- .../windows_powersploit_gpp_discovery.yml | 5 +- ...erview_kerberos_service_ticket_request.yml | 5 +- .../windows_powerview_spn_discovery.yml | 5 +- .../windows_private_keys_discovery.yml | 5 +- ...scalation_suspicious_process_elevation.yml | 2 +- ..._process_executed_from_removable_media.yml | 81 ++++++++++ .../windows_process_execution_in_temp_dir.yml | 87 +++++++++++ ...windows_process_injection_into_notepad.yml | 5 +- ...s_injection_of_wermgr_to_known_browser.yml | 5 +- ...indows_process_injection_remote_thread.yml | 5 +- ...cess_injection_with_public_source_path.yml | 5 +- ...s_with_netexec_command_line_parameters.yml | 138 +++++++++-------- .../windows_protocol_tunneling_with_plink.yml | 2 +- .../endpoint/windows_proxy_via_netsh.yml | 5 +- .../endpoint/windows_proxy_via_registry.yml | 5 +- ...indows_raccine_scheduled_task_deletion.yml | 2 +- .../windows_rasautou_dll_execution.yml | 5 +- ...ws_raw_access_to_disk_volume_partition.yml | 10 +- ...raw_access_to_master_boot_record_drive.yml | 10 +- .../windows_registry_certificate_added.yml | 5 +- ...y_dotnet_etw_disabled_via_env_variable.yml | 5 +- ...modification_for_safe_mode_persistence.yml | 5 +- .../windows_registry_payload_injection.yml | 5 +- .../windows_regsvr32_renamed_binary.yml | 5 +- ...ows_remote_assistance_spawning_process.yml | 2 +- .../windows_remote_create_service.yml | 5 +- ...remote_service_rdpwinst_tool_execution.yml | 5 +- ..._remote_services_allow_rdp_in_firewall.yml | 5 +- ...emote_services_allow_remote_assistance.yml | 5 +- .../windows_remote_services_rdp_enable.yml | 5 +- ..._root_domain_linked_policies_discovery.yml | 5 +- ...s_rundll32_apply_user_settings_changes.yml | 5 +- .../windows_rundll32_webdav_request.yml | 2 +- ...undll32_webdav_with_network_connection.yml | 2 +- ...windows_scheduled_task_created_via_xml.yml | 5 +- ...scheduled_task_with_highest_privileges.yml | 5 +- .../windows_schtasks_create_run_as_system.yml | 5 +- ...dows_security_and_backup_services_stop.yml | 78 ++++++++++ ...ws_security_support_provider_reg_query.yml | 5 +- ...ows_sensitive_group_discovery_with_net.yml | 43 +++++- ...ive_registry_hive_dump_via_commandline.yml | 46 ++++-- ...tware_component_gacutil_install_to_gac.yml | 5 +- ...dows_service_create_kernel_mode_driver.yml | 7 +- .../windows_service_create_remcomsvc.yml | 5 +- .../windows_service_create_sliverc2.yml | 5 +- .../windows_service_create_with_tscon.yml | 7 +- ...e_created_with_suspicious_service_path.yml | 8 +- ...ows_service_created_within_public_path.yml | 5 +- ...ws_service_creation_on_remote_endpoint.yml | 5 +- .../windows_service_execution_remcom.yml | 2 +- ..._service_initiation_on_remote_endpoint.yml | 5 +- .../windows_soaphound_binary_execution.yml | 12 +- ...hment_connect_to_none_ms_office_domain.yml | 5 +- ...hishing_attachment_onenote_spawn_mshta.yml | 5 +- .../windows_sql_spawning_certutil.yml | 2 +- ...thentication_certificates___esc1_abuse.yml | 2 +- ...ion_certificates___esc1_authentication.yml | 2 +- ...ntication_certificates_certutil_backup.yml | 2 +- ...cation_certificates_export_certificate.yml | 2 +- ...ion_certificates_export_pfxcertificate.yml | 2 +- ...ct_process_with_authentication_traffic.yml | 6 +- ...s_child_process_spawned_from_webserver.yml | 5 +- .../windows_suspicious_driver_loaded_path.yml | 75 +++++++++ .../windows_suspicious_process_file_path.yml | 121 +++++++++++++++ ...execution_compiled_html_file_decompile.yml | 5 +- ...ows_system_remote_discovery_with_query.yml | 64 ++++++++ ...oxy_execution_syncappvpublishingserver.yml | 2 +- .../windows_terminating_lsass_process.yml | 5 +- .../endpoint/windows_time_based_evasion.yml | 5 +- ...ows_time_based_evasion_via_choice_exec.yml | 5 +- ...ws_uac_bypass_suspicious_child_process.yml | 5 +- ..._bypass_suspicious_escalation_behavior.yml | 5 +- ..._dll_side_loading_in_same_process_path.yml | 8 +- ...abled_users_failed_auth_using_kerberos.yml | 5 +- ...alid_users_fail_to_auth_using_kerberos.yml | 5 +- ...nvalid_users_failed_to_auth_using_ntlm.yml | 5 +- ...s_fail_to_auth_wth_explicitcredentials.yml | 5 +- ...of_users_failed_to_auth_using_kerberos.yml | 5 +- ...rs_failed_to_authenticate_from_process.yml | 5 +- ...sers_failed_to_authenticate_using_ntlm.yml | 5 +- ...sers_remotely_failed_to_auth_from_host.yml | 5 +- ..._authentication_destinations_by_source.yml | 5 +- ...lm_authentication_destinations_by_user.yml | 5 +- ...lm_authentication_users_by_destination.yml | 5 +- ...al_ntlm_authentication_users_by_source.yml | 5 +- ...dows_usbstor_registry_key_modification.yml | 67 ++++++++ .../windows_user_deletion_via_net.yml | 2 +- .../windows_user_disabled_via_net.yml | 2 +- .../windows_user_discovery_via_net.yml | 23 ++- ..._execution_malicious_url_shortcut_file.yml | 5 +- .../windows_windbg_spawning_autoit3.yml | 2 +- ...s_wpdbusenum_registry_key_modification.yml | 67 ++++++++ ..._scheduled_task_created_to_spawn_shell.yml | 8 +- ...eduled_task_created_within_public_path.yml | 8 +- .../endpoint/winhlp32_spawning_a_process.yml | 2 +- .../winrar_spawning_shell_application.yml | 2 +- ..._permanent_event_subscription___sysmon.yml | 5 +- detections/endpoint/wmic_group_discovery.yml | 5 +- ...wmic_noninteractive_app_uninstallation.yml | 5 +- .../endpoint/wmic_xsl_execution_via_url.yml | 2 +- ...pt_or_cscript_suspicious_child_process.yml | 7 +- ...rovhost_lolbas_execution_process_spawn.yml | 5 +- detections/endpoint/wsreset_uac_bypass.yml | 5 +- detections/endpoint/xmrig_driver_loaded.yml | 5 +- .../xsl_script_execution_with_wmic.yml | 2 +- detections/network/detect_arp_poisoning.yml | 5 +- ...ct_ipv6_network_infrastructure_threats.yml | 5 +- .../detect_large_outbound_icmp_packets.yml | 2 +- .../network/detect_outbound_smb_traffic.yml | 13 +- .../detect_port_security_violation.yml | 5 +- ...etect_remote_access_software_usage_dns.yml | 11 +- ...t_remote_access_software_usage_traffic.yml | 14 +- ...ct_software_download_to_network_device.yml | 5 +- .../network/detect_traffic_mirroring.yml | 9 +- .../dns_query_length_outliers___mltk.yml | 5 +- ...ry_length_with_high_standard_deviation.yml | 5 +- detections/network/excessive_dns_failures.yml | 5 +- ...e_of_network_traffic_from_email_server.yml | 5 +- .../large_volume_of_dns_any_queries.yml | 5 +- .../network/protocol_or_port_mismatch.yml | 5 +- .../remote_desktop_network_bruteforce.yml | 51 ------- .../remote_desktop_network_traffic.yml | 5 +- detections/network/smb_traffic_spike.yml | 5 +- .../network/smb_traffic_spike___mltk.yml | 14 +- detections/network/tor_traffic.yml | 5 +- ...windows_ad_replication_service_traffic.yml | 5 +- ...ote_desktop_network_bruteforce_attempt.yml | 60 ++++++++ ...etect_remote_access_software_usage_url.yml | 9 +- ...ng_application_via_apache_commons_text.yml | 9 +- ...ltiple_archive_files_http_post_traffic.yml | 5 +- .../web/plain_http_post_exfiltrated_data.yml | 5 +- .../web/spring4shell_payload_url_request.yml | 9 +- detections/web/web_jsp_request_via_url.yml | 9 +- ...caler_adware_activities_threat_blocked.yml | 2 +- ...caler_behavior_analysis_threat_blocked.yml | 2 +- .../web/zscaler_exploit_threat_blocked.yml | 2 +- ...scaler_malware_activity_threat_blocked.yml | 2 +- ...caler_potentially_abused_file_download.yml | 2 +- ...ivacy_risk_destinations_threat_blocked.yml | 2 +- ...caler_scam_destinations_threat_blocked.yml | 2 +- .../zscaler_virus_download_threat_blocked.yml | 2 +- 1033 files changed, 4864 insertions(+), 3734 deletions(-) create mode 100644 detections/cloud/o365_email_transport_rule_changed.yml create mode 100644 detections/cloud/o365_multiple_os_vendors_authenticating_from_user.yml create mode 100644 detections/cloud/o365_sharepoint_suspicious_search_behavior.yml rename detections/{endpoint => deprecated}/known_services_killed_by_ransomware.yml (93%) create mode 100644 detections/deprecated/remote_desktop_network_bruteforce.yml rename detections/{endpoint => deprecated}/suspicious_driver_loaded_path.yml (93%) rename detections/{endpoint => deprecated}/suspicious_process_file_path.yml (95%) create mode 100644 detections/endpoint/windows_process_executed_from_removable_media.yml create mode 100644 detections/endpoint/windows_process_execution_in_temp_dir.yml create mode 100644 detections/endpoint/windows_security_and_backup_services_stop.yml create mode 100644 detections/endpoint/windows_suspicious_driver_loaded_path.yml create mode 100644 detections/endpoint/windows_suspicious_process_file_path.yml create mode 100644 detections/endpoint/windows_system_remote_discovery_with_query.yml create mode 100644 detections/endpoint/windows_usbstor_registry_key_modification.yml create mode 100644 detections/endpoint/windows_wpdbusenum_registry_key_modification.yml delete mode 100644 detections/network/remote_desktop_network_bruteforce.yml create mode 100644 detections/network/windows_remote_desktop_network_bruteforce_attempt.yml diff --git a/detections/application/detect_distributed_password_spray_attempts.yml b/detections/application/detect_distributed_password_spray_attempts.yml index a25a797b90..db367690c3 100644 --- a/detections/application/detect_distributed_password_spray_attempts.yml +++ b/detections/application/detect_distributed_password_spray_attempts.yml @@ -1,7 +1,7 @@ name: Detect Distributed Password Spray Attempts id: b1a82fc8-8a9f-4344-9ec2-bde5c5331b57 -version: 3 -date: '2025-01-21' +version: 4 +date: '2025-02-10' author: Dean Luxton status: production type: Hunting @@ -65,7 +65,6 @@ tags: - 90bc2e54-6c84-47a5-9439-0a2a92b4b175 mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/detect_password_spray_attempts.yml b/detections/application/detect_password_spray_attempts.yml index 9089026b9d..62c51cbc0e 100644 --- a/detections/application/detect_password_spray_attempts.yml +++ b/detections/application/detect_password_spray_attempts.yml @@ -1,7 +1,7 @@ name: Detect Password Spray Attempts id: 086ab581-8877-42b3-9aee-4a7ecb0923af -version: 5 -date: '2025-01-21' +version: 6 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -83,7 +83,6 @@ tags: - 90bc2e54-6c84-47a5-9439-0a2a92b4b175 mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/email_files_written_outside_of_the_outlook_directory.yml b/detections/application/email_files_written_outside_of_the_outlook_directory.yml index b60204ed4f..0530cd1aa9 100644 --- a/detections/application/email_files_written_outside_of_the_outlook_directory.yml +++ b/detections/application/email_files_written_outside_of_the_outlook_directory.yml @@ -1,7 +1,7 @@ name: Email files written outside of the Outlook directory id: 8d52cf03-ba25-4101-aa78-07994aed4f74 -version: 6 -date: '2025-01-21' +version: 7 +date: '2025-02-10' author: Bhavin Patel, Splunk status: experimental type: TTP @@ -44,7 +44,6 @@ tags: - Collection and Staging asset_type: Endpoint mitre_attack_id: - - T1114 - T1114.001 product: - Splunk Enterprise diff --git a/detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml b/detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml index 7a4e2f7bd3..ccbe394899 100644 --- a/detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml +++ b/detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml @@ -1,7 +1,7 @@ name: Email servers sending high volume traffic to hosts id: 7f5fb3e1-4209-4914-90db-0ec21b556378 -version: 5 -date: '2025-01-21' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Splunk status: experimental type: Anomaly @@ -51,7 +51,6 @@ tags: - HAFNIUM Group asset_type: Endpoint mitre_attack_id: - - T1114 - T1114.002 product: - Splunk Enterprise diff --git a/detections/application/okta_authentication_failed_during_mfa_challenge.yml b/detections/application/okta_authentication_failed_during_mfa_challenge.yml index 48faea347a..67546ddaf4 100644 --- a/detections/application/okta_authentication_failed_during_mfa_challenge.yml +++ b/detections/application/okta_authentication_failed_during_mfa_challenge.yml @@ -1,7 +1,7 @@ name: Okta Authentication Failed During MFA Challenge id: e2b99e7d-d956-411a-a120-2b14adfdde93 -version: 4 -date: '2025-01-21' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk data_source: - Okta @@ -59,10 +59,8 @@ tags: - Okta Account Takeover asset_type: Okta Tenant mitre_attack_id: - - T1586 - - T1586.003 - - T1078 - T1078.004 + - T1586.003 - T1621 product: - Splunk Enterprise diff --git a/detections/application/okta_multi_factor_authentication_disabled.yml b/detections/application/okta_multi_factor_authentication_disabled.yml index fbef02e3e1..96cda4186d 100644 --- a/detections/application/okta_multi_factor_authentication_disabled.yml +++ b/detections/application/okta_multi_factor_authentication_disabled.yml @@ -1,7 +1,7 @@ name: Okta Multi-Factor Authentication Disabled id: 7c0348ce-bdf9-45f6-8a57-c18b5976f00a -version: 5 -date: '2025-01-21' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: - Okta @@ -57,7 +57,6 @@ tags: - Okta Account Takeover asset_type: Okta Tenant mitre_attack_id: - - T1556 - T1556.006 product: - Splunk Enterprise diff --git a/detections/application/okta_new_api_token_created.yml b/detections/application/okta_new_api_token_created.yml index 7a8e0e78e3..27e4bf7c50 100644 --- a/detections/application/okta_new_api_token_created.yml +++ b/detections/application/okta_new_api_token_created.yml @@ -1,7 +1,7 @@ name: Okta New API Token Created id: c3d22720-35d3-4da4-bd0a-740d37192bd4 -version: 6 -date: '2025-01-21' +version: 7 +date: '2025-02-10' author: Michael Haag, Mauricio Velazco, Splunk status: production type: TTP @@ -54,7 +54,6 @@ tags: - Okta Account Takeover asset_type: Okta Tenant mitre_attack_id: - - T1078 - T1078.001 product: - Splunk Enterprise diff --git a/detections/application/okta_new_device_enrolled_on_account.yml b/detections/application/okta_new_device_enrolled_on_account.yml index a95db4b8ce..0b28586594 100644 --- a/detections/application/okta_new_device_enrolled_on_account.yml +++ b/detections/application/okta_new_device_enrolled_on_account.yml @@ -1,7 +1,7 @@ name: Okta New Device Enrolled on Account id: bb27cbce-d4de-432c-932f-2e206e9130fb -version: 6 -date: '2025-01-21' +version: 7 +date: '2025-02-10' author: Michael Haag, Mauricio Velazco, Splunk status: production type: TTP @@ -54,7 +54,6 @@ tags: - Okta Account Takeover asset_type: Okta Tenant mitre_attack_id: - - T1098 - T1098.005 product: - Splunk Enterprise diff --git a/detections/application/okta_phishing_detection_with_fastpass_origin_check.yml b/detections/application/okta_phishing_detection_with_fastpass_origin_check.yml index 8171b96c75..f2fe0f1b3c 100644 --- a/detections/application/okta_phishing_detection_with_fastpass_origin_check.yml +++ b/detections/application/okta_phishing_detection_with_fastpass_origin_check.yml @@ -1,7 +1,7 @@ name: Okta Phishing Detection with FastPass Origin Check id: f4ca0057-cbf3-44f8-82ea-4e330ee901d3 -version: 4 -date: '2025-01-21' +version: 5 +date: '2025-02-10' author: Okta, Inc, Michael Haag, Splunk type: TTP status: experimental @@ -38,7 +38,6 @@ tags: - Okta Account Takeover asset_type: Infrastructure mitre_attack_id: - - T1078 - T1078.001 - T1556 product: diff --git a/detections/application/okta_successful_single_factor_authentication.yml b/detections/application/okta_successful_single_factor_authentication.yml index 1c0f03def8..a5a4a3bf14 100644 --- a/detections/application/okta_successful_single_factor_authentication.yml +++ b/detections/application/okta_successful_single_factor_authentication.yml @@ -1,7 +1,7 @@ name: Okta Successful Single Factor Authentication id: 98f6ad4f-4325-4096-9d69-45dc8e638e82 -version: 4 -date: '2025-01-21' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk data_source: - Okta @@ -55,10 +55,8 @@ tags: - Okta Account Takeover asset_type: Okta Tenant mitre_attack_id: - - T1586 - - T1586.003 - - T1078 - T1078.004 + - T1586.003 - T1621 product: - Splunk Enterprise diff --git a/detections/application/okta_suspicious_activity_reported.yml b/detections/application/okta_suspicious_activity_reported.yml index 363f2487b6..1f2662268e 100644 --- a/detections/application/okta_suspicious_activity_reported.yml +++ b/detections/application/okta_suspicious_activity_reported.yml @@ -1,7 +1,7 @@ name: Okta Suspicious Activity Reported id: bfc840f5-c9c6-454c-aa13-b46fd0bf1e79 -version: 5 -date: '2025-01-21' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -55,7 +55,6 @@ tags: - Okta Account Takeover asset_type: Okta Tenant mitre_attack_id: - - T1078 - T1078.001 product: - Splunk Enterprise diff --git a/detections/application/okta_threatinsight_threat_detected.yml b/detections/application/okta_threatinsight_threat_detected.yml index 04d5e1e5fe..264bf76c91 100644 --- a/detections/application/okta_threatinsight_threat_detected.yml +++ b/detections/application/okta_threatinsight_threat_detected.yml @@ -1,7 +1,7 @@ name: Okta ThreatInsight Threat Detected id: 140504ae-5fe2-4d65-b2bc-a211813fbca6 -version: 5 -date: '2025-01-21' +version: 6 +date: '2025-02-10' author: Michael Haag, Mauricio Velazco, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: - Okta Account Takeover asset_type: Infrastructure mitre_attack_id: - - T1078 - T1078.004 product: - Splunk Enterprise diff --git a/detections/application/pingid_mismatch_auth_source_and_verification_response.yml b/detections/application/pingid_mismatch_auth_source_and_verification_response.yml index 021ec93c2e..17e059d927 100644 --- a/detections/application/pingid_mismatch_auth_source_and_verification_response.yml +++ b/detections/application/pingid_mismatch_auth_source_and_verification_response.yml @@ -1,6 +1,6 @@ name: PingID Mismatch Auth Source and Verification Response id: 15b0694e-caa2-4009-8d83-a1f98b86d086 -version: 4 +version: 5 date: '2025-01-21' author: Steven Dick status: production diff --git a/detections/application/suspicious_email_attachment_extensions.yml b/detections/application/suspicious_email_attachment_extensions.yml index 3a44f76bfa..f557b97bca 100644 --- a/detections/application/suspicious_email_attachment_extensions.yml +++ b/detections/application/suspicious_email_attachment_extensions.yml @@ -1,7 +1,7 @@ name: Suspicious Email Attachment Extensions id: 473bd65f-06ca-4dfe-a2b8-ba04ab4a0084 -version: 6 -date: '2025-01-21' +version: 7 +date: '2025-02-10' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -48,7 +48,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1566.001 - - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_dangerous_deny_acl_modification.yml b/detections/application/windows_ad_dangerous_deny_acl_modification.yml index 40076288f5..29ab4c180d 100644 --- a/detections/application/windows_ad_dangerous_deny_acl_modification.yml +++ b/detections/application/windows_ad_dangerous_deny_acl_modification.yml @@ -1,7 +1,7 @@ name: Windows AD Dangerous Deny ACL Modification id: 8e897153-2ebd-4cb2-85d3-09ad57db2fb7 -version: 3 -date: '2025-01-21' +version: 4 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -76,9 +76,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1222 - T1222.001 + - T1484 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_dangerous_group_acl_modification.yml b/detections/application/windows_ad_dangerous_group_acl_modification.yml index c6bffd639e..047d9274eb 100644 --- a/detections/application/windows_ad_dangerous_group_acl_modification.yml +++ b/detections/application/windows_ad_dangerous_group_acl_modification.yml @@ -1,7 +1,7 @@ name: Windows AD Dangerous Group ACL Modification id: 59b0fc85-7a0d-4585-97ec-06a382801990 -version: 3 -date: '2025-01-21' +version: 4 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -85,9 +85,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1222 - T1222.001 + - T1484 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_dangerous_user_acl_modification.yml b/detections/application/windows_ad_dangerous_user_acl_modification.yml index f298e0616d..7163e0aa3a 100644 --- a/detections/application/windows_ad_dangerous_user_acl_modification.yml +++ b/detections/application/windows_ad_dangerous_user_acl_modification.yml @@ -1,7 +1,7 @@ name: Windows AD Dangerous User ACL Modification id: ec5b6790-595a-4fb8-ad43-56e5b55a9617 -version: 3 -date: '2025-01-21' +version: 4 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -82,9 +82,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1222 - T1222.001 + - T1484 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_domain_root_acl_deletion.yml b/detections/application/windows_ad_domain_root_acl_deletion.yml index c4bfa9c916..8ca60c13b1 100644 --- a/detections/application/windows_ad_domain_root_acl_deletion.yml +++ b/detections/application/windows_ad_domain_root_acl_deletion.yml @@ -1,7 +1,7 @@ name: Windows AD Domain Root ACL Deletion id: 3cb56e57-5642-4638-907f-8dfde9afb889 -version: 3 -date: '2025-01-21' +version: 4 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -75,9 +75,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1222 - T1222.001 + - T1484 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_domain_root_acl_modification.yml b/detections/application/windows_ad_domain_root_acl_modification.yml index 56d121c7d2..4b30ed7b3a 100644 --- a/detections/application/windows_ad_domain_root_acl_modification.yml +++ b/detections/application/windows_ad_domain_root_acl_modification.yml @@ -1,7 +1,7 @@ name: Windows AD Domain Root ACL Modification id: 4981e2db-1372-440d-816e-3e7e2ed74433 -version: 3 -date: '2025-01-21' +version: 4 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -75,9 +75,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1222 - T1222.001 + - T1484 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_gpo_new_cse_addition.yml b/detections/application/windows_ad_gpo_new_cse_addition.yml index 4f0f4fce8f..194bf251ab 100644 --- a/detections/application/windows_ad_gpo_new_cse_addition.yml +++ b/detections/application/windows_ad_gpo_new_cse_addition.yml @@ -1,7 +1,7 @@ name: Windows AD GPO New CSE Addition id: 700c11d1-da09-47b2-81aa-358c143c7986 -version: 3 -date: '2025-01-21' +version: 4 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -64,10 +64,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1484.001 - - T1222 - T1222.001 + - T1484.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_hidden_ou_creation.yml b/detections/application/windows_ad_hidden_ou_creation.yml index 2885f00678..358a32bc0f 100644 --- a/detections/application/windows_ad_hidden_ou_creation.yml +++ b/detections/application/windows_ad_hidden_ou_creation.yml @@ -1,7 +1,7 @@ name: Windows AD Hidden OU Creation id: 66b6ad5e-339a-40af-b721-dacefc7bdb75 -version: 3 -date: '2025-01-21' +version: 4 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -74,9 +74,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1222 - T1222.001 + - T1484 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_object_owner_updated.yml b/detections/application/windows_ad_object_owner_updated.yml index fb234c3f1a..51abfc6ca8 100644 --- a/detections/application/windows_ad_object_owner_updated.yml +++ b/detections/application/windows_ad_object_owner_updated.yml @@ -1,7 +1,7 @@ name: Windows AD Object Owner Updated id: 4af01f6b-d8d4-4f96-8635-758a01557130 -version: 4 -date: '2025-01-21' +version: 5 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -66,9 +66,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1222 - T1222.001 + - T1484 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_suspicious_attribute_modification.yml b/detections/application/windows_ad_suspicious_attribute_modification.yml index df005bfae6..da62dd68ba 100644 --- a/detections/application/windows_ad_suspicious_attribute_modification.yml +++ b/detections/application/windows_ad_suspicious_attribute_modification.yml @@ -1,7 +1,7 @@ name: Windows AD Suspicious Attribute Modification id: 5682052e-ce55-4f9f-8d28-59191420b7e0 -version: 3 -date: '2025-01-21' +version: 5 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -62,9 +62,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1550 - - T1222 - T1222.001 + - T1550 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_suspicious_gpo_modification.yml b/detections/application/windows_ad_suspicious_gpo_modification.yml index 976ed7ea7d..c70acfb5ed 100644 --- a/detections/application/windows_ad_suspicious_gpo_modification.yml +++ b/detections/application/windows_ad_suspicious_gpo_modification.yml @@ -1,7 +1,7 @@ name: Windows AD Suspicious GPO Modification id: 0a2afc18-a3b5-4452-b60a-2e774214f9bf -version: 3 -date: '2025-01-21' +version: 5 +date: '2025-02-10' author: Dean Luxton status: experimental type: TTP @@ -70,10 +70,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1484.001 - - T1222 - T1222.001 + - T1484.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml index 969f05f721..6581d23fca 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml @@ -1,7 +1,7 @@ name: Abnormally High Number Of Cloud Infrastructure API Calls id: 0840ddf1-8c89-46ff-b730-c8d6722478c0 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -46,7 +46,6 @@ tags: asset_type: AWS Instance mitre_attack_id: - T1078.004 - - T1078 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml b/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml index 8175e9709c..e9bcb75db0 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml @@ -1,7 +1,7 @@ name: Abnormally High Number Of Cloud Instances Destroyed id: ef629fc9-1583-4590-b62a-f2247fbf7bbf -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -48,7 +48,6 @@ tags: asset_type: Cloud Instance mitre_attack_id: - T1078.004 - - T1078 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml b/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml index e88f2c8f16..9edf6d5b9a 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml @@ -1,7 +1,7 @@ name: Abnormally High Number Of Cloud Instances Launched id: f2361e9f-3928-496c-a556-120cd4223a65 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -48,7 +48,6 @@ tags: asset_type: Cloud Instance mitre_attack_id: - T1078.004 - - T1078 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml index 2360113251..761e9de23d 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml @@ -1,7 +1,7 @@ name: Abnormally High Number Of Cloud Security Group API Calls id: d4dfb7f3-7a37-498a-b5df-f19334e871af -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -46,7 +46,6 @@ tags: asset_type: AWS Instance mitre_attack_id: - T1078.004 - - T1078 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/asl_aws_create_access_key.yml b/detections/cloud/asl_aws_create_access_key.yml index eeb433eaa8..f73e4719af 100644 --- a/detections/cloud/asl_aws_create_access_key.yml +++ b/detections/cloud/asl_aws_create_access_key.yml @@ -1,16 +1,33 @@ name: ASL AWS Create Access Key id: 81a9f2fe-1697-473c-af1d-086b0d8b63c8 -version: 1 -date: '2024-12-12' +version: 2 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Hunting -description: The following analytic identifies the creation of AWS IAM access keys by a user for another user, which can indicate privilege escalation. It leverages AWS CloudTrail logs to detect instances where the user creating the access key is different from the user for whom the key is created. This activity is significant because unauthorized access key creation can allow attackers to establish persistence or exfiltrate data via AWS APIs. If confirmed malicious, this could lead to unauthorized access to AWS services, data exfiltration, and long-term persistence in the environment. -data_source: +description: The following analytic identifies the creation of AWS IAM access keys + by a user for another user, which can indicate privilege escalation. It leverages + AWS CloudTrail logs to detect instances where the user creating the access key is + different from the user for whom the key is created. This activity is significant + because unauthorized access key creation can allow attackers to establish persistence + or exfiltrate data via AWS APIs. If confirmed malicious, this could lead to unauthorized + access to AWS services, data exfiltration, and long-term persistence in the environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=CreateAccessKey | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`asl_aws_create_access_key_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. +search: '`amazon_security_lake` api.operation=CreateAccessKey | fillnull | stats count + min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid + http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as + user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + |`asl_aws_create_access_key_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has legitimately created keys for another user. references: - https://bishopfox.com/blog/privilege-escalation-in-aws - https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ @@ -20,7 +37,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1136.003 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security @@ -29,6 +45,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_create_policy_version_to_allow_all_resources.yml b/detections/cloud/asl_aws_create_policy_version_to_allow_all_resources.yml index d4620bd070..d7f2b0d689 100644 --- a/detections/cloud/asl_aws_create_policy_version_to_allow_all_resources.yml +++ b/detections/cloud/asl_aws_create_policy_version_to_allow_all_resources.yml @@ -1,16 +1,36 @@ name: ASL AWS Create Policy Version to allow all resources id: 22cc7a62-3884-48c4-82da-592b8199b72f -version: 1 -date: '2024-12-12' +version: 2 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP -description: The following analytic identifies the creation of a new AWS IAM policy version that allows access to all resources. It detects this activity by analyzing AWS CloudTrail logs for the CreatePolicyVersion event with a policy document that grants broad permissions. This behavior is significant because it violates the principle of least privilege, potentially exposing the environment to misuse or abuse. If confirmed malicious, an attacker could gain extensive access to AWS resources, leading to unauthorized actions, data exfiltration, or further compromise of the AWS environment. -data_source: +description: The following analytic identifies the creation of a new AWS IAM policy + version that allows access to all resources. It detects this activity by analyzing + AWS CloudTrail logs for the CreatePolicyVersion event with a policy document that + grants broad permissions. This behavior is significant because it violates the principle + of least privilege, potentially exposing the environment to misuse or abuse. If + confirmed malicious, an attacker could gain extensive access to AWS resources, leading + to unauthorized actions, data exfiltration, or further compromise of the AWS environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=CreatePolicy | spath input=api.request.data | spath input=policyDocument | regex Statement{}.Action="\*" | regex Statement{}.Resource="\*" | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region api.request.data | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|`asl_aws_create_policy_version_to_allow_all_resources_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: While this search has no known false positives, it is possible that an AWS admin has legitimately created a policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources and you must verify this activity. +search: '`amazon_security_lake` api.operation=CreatePolicy | spath input=api.request.data + | spath input=policyDocument | regex Statement{}.Action="\*" | regex Statement{}.Resource="\*" + | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation + actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region + api.request.data | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region + as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`|`asl_aws_create_policy_version_to_allow_all_resources_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has legitimately created a policy to allow a user to access all + resources. That said, AWS strongly advises against granting full control to all + AWS resources and you must verify this activity. references: - https://bishopfox.com/blog/privilege-escalation-in-aws - https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ @@ -20,11 +40,17 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: User $user$ created a policy version that allows them to access any resource in their account + message: User $user$ created a policy version that allows them to access any resource + in their account risk_objects: - field: user type: user @@ -36,7 +62,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1078.004 - - T1078 product: - Splunk Enterprise - Splunk Enterprise Security @@ -45,6 +70,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_credential_access_getpassworddata.yml b/detections/cloud/asl_aws_credential_access_getpassworddata.yml index 4c112af04c..808dfd47e7 100644 --- a/detections/cloud/asl_aws_credential_access_getpassworddata.yml +++ b/detections/cloud/asl_aws_credential_access_getpassworddata.yml @@ -1,16 +1,34 @@ name: ASL AWS Credential Access GetPasswordData id: a79b607a-50cc-4704-bb9d-eff280cb78c2 -version: 1 -date: '2024-12-12' +version: 2 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly -description: The following analytic identifiesGetPasswordData API calls in your AWS account. It leverages CloudTrail logs from Amazon Security Lake to detect this activity by counting the distinct instance IDs accessed. This behavior is significant as it may indicate an attempt to retrieve encrypted administrator passwords for running Windows instances, which is a critical security concern. If confirmed malicious, attackers could gain unauthorized access to administrative credentials, potentially leading to full control over the affected instances and further compromise of the AWS environment. -data_source: +description: The following analytic identifiesGetPasswordData API calls in your AWS + account. It leverages CloudTrail logs from Amazon Security Lake to detect this + activity by counting the distinct instance IDs accessed. This behavior is significant + as it may indicate an attempt to retrieve encrypted administrator passwords for + running Windows instances, which is a critical security concern. If confirmed malicious, + attackers could gain unauthorized access to administrative credentials, potentially + leading to full control over the affected instances and further compromise of the + AWS environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=GetPasswordData | spath input=api.request.data | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region instanceId | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`asl_aws_credential_access_getpassworddata_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: Administrator tooling or automated scripts may make these calls but it is highly unlikely to make several calls in a short period of time. +search: '`amazon_security_lake` api.operation=GetPasswordData | spath input=api.request.data + | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation + actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region + instanceId | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region + as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` |`asl_aws_credential_access_getpassworddata_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: Administrator tooling or automated scripts may make these calls + but it is highly unlikely to make several calls in a short period of time. references: - https://attack.mitre.org/techniques/T1552/ - https://stratus-red-team.cloud/attack-techniques/AWS/aws.credential-access.ec2-get-password-data/ @@ -20,7 +38,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -37,10 +60,8 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.001 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security @@ -49,6 +70,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552/aws_getpassworddata/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552/aws_getpassworddata/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_credential_access_rds_password_reset.yml b/detections/cloud/asl_aws_credential_access_rds_password_reset.yml index 300892fee9..c7248c18e7 100644 --- a/detections/cloud/asl_aws_credential_access_rds_password_reset.yml +++ b/detections/cloud/asl_aws_credential_access_rds_password_reset.yml @@ -1,15 +1,34 @@ name: ASL AWS Credential Access RDS Password reset id: d15e9bd9-ef64-4d84-bc04-f62955a9fee8 -version: 1 -date: '2024-12-12' +version: 2 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP -description: The following analytic detects the resetting of the master user password for an Amazon RDS DB instance. It leverages AWS CloudTrail logs from Amazon Security Lake to identify events where the `ModifyDBInstance` API call includes a new `masterUserPassword` parameter. This activity is significant because unauthorized password resets can grant attackers access to sensitive data stored in production databases, such as credit card information, PII, and healthcare data. If confirmed malicious, this could lead to data breaches, regulatory non-compliance, and significant reputational damage. Immediate investigation is required to determine the legitimacy of the password reset. -data_source: +description: The following analytic detects the resetting of the master user password + for an Amazon RDS DB instance. It leverages AWS CloudTrail logs from Amazon Security + Lake to identify events where the `ModifyDBInstance` API call includes a new `masterUserPassword` + parameter. This activity is significant because unauthorized password resets can + grant attackers access to sensitive data stored in production databases, such as + credit card information, PII, and healthcare data. If confirmed malicious, this + could lead to data breaches, regulatory non-compliance, and significant reputational + damage. Immediate investigation is required to determine the legitimacy of the password + reset. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=ModifyDBInstance OR api.operation=ModifyDBCluster | spath input=api.request.data | search masterUserPassword=* | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region api.request.data | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`asl_aws_credential_access_rds_password_reset_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. +search: '`amazon_security_lake` api.operation=ModifyDBInstance OR api.operation=ModifyDBCluster + | spath input=api.request.data | search masterUserPassword=* | fillnull | stats + count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid + actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region api.request.data + | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, + http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + |`asl_aws_credential_access_rds_password_reset_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. known_false_positives: Users may genuinely reset the RDS password. references: - https://aws.amazon.com/premiumsupport/knowledge-center/reset-master-user-password-rds @@ -19,7 +38,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -36,9 +60,8 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 - - T1586.003 - T1110 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security @@ -47,6 +70,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.002/aws_rds_password_reset/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.002/aws_rds_password_reset/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_defense_evasion_delete_cloudtrail.yml b/detections/cloud/asl_aws_defense_evasion_delete_cloudtrail.yml index bc99f507d0..a04efd1649 100644 --- a/detections/cloud/asl_aws_defense_evasion_delete_cloudtrail.yml +++ b/detections/cloud/asl_aws_defense_evasion_delete_cloudtrail.yml @@ -1,16 +1,33 @@ name: ASL AWS Defense Evasion Delete Cloudtrail id: 1f0b47e5-0134-43eb-851c-e3258638945e -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP -description: The following analytic detects AWS `DeleteTrail` events within CloudTrail logs. It leverages Amazon Security Lake logs parsed in the Open Cybersecurity Schema Framework (OCSF) format to identify when a CloudTrail is deleted. This activity is significant because adversaries may delete CloudTrail logs to evade detection and operate with stealth. If confirmed malicious, this action could allow attackers to cover their tracks, making it difficult to trace their activities and investigate other potential compromises within the AWS environment. -data_source: +description: The following analytic detects AWS `DeleteTrail` events within CloudTrail + logs. It leverages Amazon Security Lake logs parsed in the Open Cybersecurity Schema + Framework (OCSF) format to identify when a CloudTrail is deleted. This activity + is significant because adversaries may delete CloudTrail logs to evade detection + and operate with stealth. If confirmed malicious, this action could allow attackers + to cover their tracks, making it difficult to trace their activities and investigate + other potential compromises within the AWS environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=DeleteTrail | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `asl_aws_defense_evasion_delete_cloudtrail_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: While this search has no known false positives, it is possible that an AWS admin has stopped cloudTrail logging. Please investigate this activity. +search: '`amazon_security_lake` api.operation=DeleteTrail | fillnull | stats count + min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid + http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as + user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| + `asl_aws_defense_evasion_delete_cloudtrail_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has stopped cloudTrail logging. Please investigate this activity. references: - https://attack.mitre.org/techniques/T1562/008/ drilldown_searches: @@ -42,7 +59,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1562.008 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security @@ -51,6 +67,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_defense_evasion_delete_cloudwatch_log_group.yml b/detections/cloud/asl_aws_defense_evasion_delete_cloudwatch_log_group.yml index 7a1806f3c9..cccf09434f 100644 --- a/detections/cloud/asl_aws_defense_evasion_delete_cloudwatch_log_group.yml +++ b/detections/cloud/asl_aws_defense_evasion_delete_cloudwatch_log_group.yml @@ -1,16 +1,34 @@ name: ASL AWS Defense Evasion Delete CloudWatch Log Group id: 0f701b38-a0fb-43fd-a83d-d12265f71f33 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP -description: The following analytic detects the deletion of CloudWatch log groups in AWS, identified through `DeleteLogGroup` events in CloudTrail logs. This method leverages Amazon Security Lake logs parsed in the OCSF format. The activity is significant because attackers may delete log groups to evade detection and disrupt logging capabilities, hindering incident response efforts. If confirmed malicious, this action could allow attackers to cover their tracks, making it difficult to trace their activities and potentially leading to undetected data breaches or further malicious actions within the compromised AWS environment. -data_source: +description: The following analytic detects the deletion of CloudWatch log groups + in AWS, identified through `DeleteLogGroup` events in CloudTrail logs. This method + leverages Amazon Security Lake logs parsed in the OCSF format. The activity is significant + because attackers may delete log groups to evade detection and disrupt logging capabilities, + hindering incident response efforts. If confirmed malicious, this action could allow + attackers to cover their tracks, making it difficult to trace their activities and + potentially leading to undetected data breaches or further malicious actions within + the compromised AWS environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=DeleteLogGroup | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `asl_aws_defense_evasion_delete_cloudwatch_log_group_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: While this search has no known false positives, it is possible that an AWS admin has deleted CloudWatch logging. Please investigate this activity. +search: '`amazon_security_lake` api.operation=DeleteLogGroup | fillnull | stats count + min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid + http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as + user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| + `asl_aws_defense_evasion_delete_cloudwatch_log_group_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has deleted CloudWatch logging. Please investigate this activity. references: - https://attack.mitre.org/techniques/T1562/008/ drilldown_searches: @@ -41,7 +59,6 @@ tags: - AWS Defense Evasion asset_type: AWS Account mitre_attack_id: - - T1562 - T1562.008 product: - Splunk Enterprise diff --git a/detections/cloud/asl_aws_defense_evasion_impair_security_services.yml b/detections/cloud/asl_aws_defense_evasion_impair_security_services.yml index a6a76f9130..33368956c8 100644 --- a/detections/cloud/asl_aws_defense_evasion_impair_security_services.yml +++ b/detections/cloud/asl_aws_defense_evasion_impair_security_services.yml @@ -1,16 +1,35 @@ name: ASL AWS Defense Evasion Impair Security Services id: 5029b681-0462-47b7-82e7-f7e3d37f5a2d -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Bhavin Patel, Gowthamaraj Rajendran, Splunk status: production type: Hunting -description: The following analytic detects the deletion of critical AWS Security Services configurations, such as CloudWatch alarms, GuardDuty detectors, and Web Application Firewall rules. It leverages Amazon Security Lake logs to identify specific API calls like "DeleteLogStream" and "DeleteDetector." This activity is significant because adversaries often use these actions to disable security monitoring and evade detection. If confirmed malicious, this could allow attackers to operate undetected, leading to potential data breaches, unauthorized access, and prolonged persistence within the AWS environment. -data_source: +description: The following analytic detects the deletion of critical AWS Security + Services configurations, such as CloudWatch alarms, GuardDuty detectors, and Web + Application Firewall rules. It leverages Amazon Security Lake logs to identify specific + API calls like "DeleteLogStream" and "DeleteDetector." This activity is significant + because adversaries often use these actions to disable security monitoring and evade + detection. If confirmed malicious, this could allow attackers to operate undetected, + leading to potential data breaches, unauthorized access, and prolonged persistence + within the AWS environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation IN ("DeleteLogStream","DeleteDetector","DeleteIPSet","DeleteWebACL","DeleteRule","DeleteRuleGroup","DeleteLoggingConfiguration","DeleteAlarms") | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account_uid as aws_account_id | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_impair_security_services_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names. +search: '`amazon_security_lake` api.operation IN ("DeleteLogStream","DeleteDetector","DeleteIPSet","DeleteWebACL","DeleteRule","DeleteRuleGroup","DeleteLoggingConfiguration","DeleteAlarms") + | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation + actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region + | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, + http_request.user_agent as user_agent, actor.user.account_uid as aws_account_id + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_impair_security_services_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: While this search has no known false positives, it is possible + that it is a legitimate admin activity. Please consider filtering out these noisy + events using userAgent, user_arn field names. references: - https://docs.aws.amazon.com/cli/latest/reference/guardduty/index.html - https://docs.aws.amazon.com/cli/latest/reference/waf/index.html @@ -21,7 +40,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1562.008 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security @@ -30,6 +48,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/aws_delete_security_services/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/aws_delete_security_services/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_defense_evasion_putbucketlifecycle.yml b/detections/cloud/asl_aws_defense_evasion_putbucketlifecycle.yml index 2b843cd24f..1ae40f392d 100644 --- a/detections/cloud/asl_aws_defense_evasion_putbucketlifecycle.yml +++ b/detections/cloud/asl_aws_defense_evasion_putbucketlifecycle.yml @@ -1,16 +1,36 @@ name: ASL AWS Defense Evasion PutBucketLifecycle id: 986565a2-7707-48ea-9590-37929cebc938 -version: 1 -date: '2024-12-16' +version: 2 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Hunting -description: The following analytic detects `PutBucketLifecycle` events in AWS CloudTrail logs where a user sets a lifecycle rule for an S3 bucket with an expiration period of fewer than three days. This detection leverages CloudTrail logs to identify suspicious lifecycle configurations. This activity is significant because attackers may use it to delete CloudTrail logs quickly, thereby evading detection and impairing forensic investigations. If confirmed malicious, this could allow attackers to cover their tracks, making it difficult to trace their actions and respond to the breach effectively. +description: The following analytic detects `PutBucketLifecycle` events in AWS CloudTrail + logs where a user sets a lifecycle rule for an S3 bucket with an expiration period + of fewer than three days. This detection leverages CloudTrail logs to identify suspicious + lifecycle configurations. This activity is significant because attackers may use + it to delete CloudTrail logs quickly, thereby evading detection and impairing forensic + investigations. If confirmed malicious, this could allow attackers to cover their + tracks, making it difficult to trace their actions and respond to the breach effectively. data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=PutBucketLifecycle | spath input=api.request.data path=LifecycleConfiguration.Rule.NoncurrentVersionExpiration.NoncurrentDays output=NoncurrentDays | where NoncurrentDays < 3 | spath input=api.request.data | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region NoncurrentDays bucketName | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_putbucketlifecycle_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names. +search: '`amazon_security_lake` api.operation=PutBucketLifecycle | spath input=api.request.data + path=LifecycleConfiguration.Rule.NoncurrentVersionExpiration.NoncurrentDays output=NoncurrentDays + | where NoncurrentDays < 3 | spath input=api.request.data | fillnull | stats count + min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid + http_request.user_agent src_endpoint.ip cloud.region NoncurrentDays bucketName | + rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, + http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `asl_aws_defense_evasion_putbucketlifecycle_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: While this search has no known false positives, it is possible + that it is a legitimate admin activity. Please consider filtering out these noisy + events using userAgent, user_arn field names. references: - https://stratus-red-team.cloud/attack-techniques/AWS/aws.defense-evasion.cloudtrail-lifecycle-rule/ tags: @@ -18,10 +38,8 @@ tags: - AWS Defense Evasion asset_type: AWS Account mitre_attack_id: - - T1562.008 - - T1562 - T1485.001 - - T1485 + - T1562.008 product: - Splunk Enterprise - Splunk Enterprise Security @@ -30,6 +48,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/put_bucketlifecycle/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/put_bucketlifecycle/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_defense_evasion_stop_logging_cloudtrail.yml b/detections/cloud/asl_aws_defense_evasion_stop_logging_cloudtrail.yml index 28a9d9a628..ab0b74e5d6 100644 --- a/detections/cloud/asl_aws_defense_evasion_stop_logging_cloudtrail.yml +++ b/detections/cloud/asl_aws_defense_evasion_stop_logging_cloudtrail.yml @@ -1,17 +1,36 @@ name: ASL AWS Defense Evasion Stop Logging Cloudtrail id: 0b78a8f9-1d31-4d23-85c8-56ad13d5b4c1 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP -description: The following analytic detects `StopLogging` events within AWS CloudTrail logs, a critical action that adversaries may use to evade detection. By halting the logging of their malicious activities, attackers aim to operate undetected within a compromised AWS environment. This detection is achieved by monitoring for specific CloudTrail log entries that indicate the cessation of logging activities. Identifying such behavior is crucial for a Security Operations Center (SOC), as it signals an attempt to undermine the integrity of logging mechanisms, potentially allowing malicious activities to proceed without observation. The impact of this evasion tactic is significant, as it can severely hamper incident response and forensic investigations by obscuring the attacker's actions. -data_source: +description: The following analytic detects `StopLogging` events within AWS CloudTrail + logs, a critical action that adversaries may use to evade detection. By halting + the logging of their malicious activities, attackers aim to operate undetected within + a compromised AWS environment. This detection is achieved by monitoring for specific + CloudTrail log entries that indicate the cessation of logging activities. Identifying + such behavior is crucial for a Security Operations Center (SOC), as it signals an + attempt to undermine the integrity of logging mechanisms, potentially allowing malicious + activities to proceed without observation. The impact of this evasion tactic is + significant, as it can severely hamper incident response and forensic investigations + by obscuring the attacker's actions. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=StopLogging | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid - as aws_account_id | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_stop_logging_cloudtrail_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: While this search has no known false positives, it is possible that an AWS admin has stopped cloudtrail logging. Please investigate this activity. +search: '`amazon_security_lake` api.operation=StopLogging | fillnull | stats count + min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid + http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as + user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent, actor.user.account.uid as aws_account_id | `security_content_ctime(firstTime)`| + `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_stop_logging_cloudtrail_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has stopped cloudtrail logging. Please investigate this activity. references: - https://attack.mitre.org/techniques/T1562/008/ drilldown_searches: @@ -44,7 +63,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1562.008 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security @@ -53,6 +71,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail_2.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail_2.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_defense_evasion_update_cloudtrail.yml b/detections/cloud/asl_aws_defense_evasion_update_cloudtrail.yml index 1b45a81b7f..55888e23cc 100644 --- a/detections/cloud/asl_aws_defense_evasion_update_cloudtrail.yml +++ b/detections/cloud/asl_aws_defense_evasion_update_cloudtrail.yml @@ -1,16 +1,35 @@ name: ASL AWS Defense Evasion Update Cloudtrail id: f3eb471c-16d0-404d-897c-7653f0a78cba -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP -description: The following analytic detects `UpdateTrail` events within AWS CloudTrail logs, aiming to identify attempts by attackers to evade detection by altering logging configurations. By updating CloudTrail settings with incorrect parameters, such as changing multi-regional logging to a single region, attackers can impair the logging of their activities across other regions. This behavior is crucial for Security Operations Centers (SOCs) to identify, as it indicates an adversary's intent to operate undetected within a compromised AWS environment. The impact of such evasion tactics is significant, potentially allowing malicious activities to proceed without being logged, thereby hindering incident response and forensic investigations. -data_source: +description: The following analytic detects `UpdateTrail` events within AWS CloudTrail + logs, aiming to identify attempts by attackers to evade detection by altering logging + configurations. By updating CloudTrail settings with incorrect parameters, such + as changing multi-regional logging to a single region, attackers can impair the + logging of their activities across other regions. This behavior is crucial for Security + Operations Centers (SOCs) to identify, as it indicates an adversary's intent to + operate undetected within a compromised AWS environment. The impact of such evasion + tactics is significant, potentially allowing malicious activities to proceed without + being logged, thereby hindering incident response and forensic investigations. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=UpdateTrail | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid as aws_account_id | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_update_cloudtrail_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: While this search has no known false positives, it is possible that an AWS admin has updated cloudtrail logging. Please investigate this activity. +search: '`amazon_security_lake` api.operation=UpdateTrail | fillnull | stats count + min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid + http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as + user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent, actor.user.account.uid as aws_account_id | `security_content_ctime(firstTime)`| + `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_update_cloudtrail_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has updated cloudtrail logging. Please investigate this activity. references: - https://attack.mitre.org/techniques/T1562/008/ drilldown_searches: @@ -42,7 +61,6 @@ tags: - AWS Defense Evasion asset_type: AWS Account mitre_attack_id: - - T1562 - T1562.008 product: - Splunk Enterprise @@ -52,6 +70,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/update_cloudtrail/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/update_cloudtrail/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_ecr_container_upload_outside_business_hours.yml b/detections/cloud/asl_aws_ecr_container_upload_outside_business_hours.yml index 6222a0b4f0..c4a461916e 100644 --- a/detections/cloud/asl_aws_ecr_container_upload_outside_business_hours.yml +++ b/detections/cloud/asl_aws_ecr_container_upload_outside_business_hours.yml @@ -1,16 +1,35 @@ name: ASL AWS ECR Container Upload Outside Business Hours id: 739ed682-27e9-4ba0-80e5-a91b97698213 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly -description: The following analytic detects the upload of new containers to AWS Elastic Container Service (ECR) outside of standard business hours through AWS CloudTrail events. It identifies this behavior by monitoring for `PutImage` events occurring before 8 AM or after 8 PM, as well as any uploads on weekends. This activity is significant for a SOC to investigate as it may indicate unauthorized access or malicious deployments, potentially leading to compromised services or data breaches. Identifying and addressing such uploads promptly can mitigate the risk of security incidents and their associated impacts. -data_source: +description: The following analytic detects the upload of new containers to AWS Elastic + Container Service (ECR) outside of standard business hours through AWS CloudTrail + events. It identifies this behavior by monitoring for `PutImage` events occurring + before 8 AM or after 8 PM, as well as any uploads on weekends. This activity is + significant for a SOC to investigate as it may indicate unauthorized access or malicious + deployments, potentially leading to compromised services or data breaches. Identifying + and addressing such uploads promptly can mitigate the risk of security incidents + and their associated impacts. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=PutImage | eval hour=strftime(time/pow(10,3), "%H"), weekday=strftime(time/pow(10,3), "%A") | where hour >= 20 OR hour < 8 OR weekday=Saturday OR weekday=Sunday | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent cloud.region | rename actor.user.uid as user, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_ecr_container_upload_outside_business_hours_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: When your development is spreaded in different time zones, applying this rule can be difficult. +search: '`amazon_security_lake` api.operation=PutImage | eval hour=strftime(time/pow(10,3), + "%H"), weekday=strftime(time/pow(10,3), "%A") | where hour >= 20 OR hour < 8 OR + weekday=Saturday OR weekday=Sunday | fillnull | stats count min(_time) as firstTime + max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent + cloud.region | rename actor.user.uid as user, cloud.region as region, http_request.user_agent + as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `asl_aws_ecr_container_upload_outside_business_hours_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: When your development is spreaded in different time zones, + applying this rule can be difficult. references: - https://attack.mitre.org/techniques/T1204/003/ drilldown_searches: @@ -40,16 +59,17 @@ tags: asset_type: AWS Account mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud security_domain: network - manual_test: Can't be tested automatically because of outside of business hours time + manual_test: Can't be tested automatically because of outside of business hours + time tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_ecr_container_upload_unknown_user.yml b/detections/cloud/asl_aws_ecr_container_upload_unknown_user.yml index 156aab0bc0..9f92aaa8b3 100644 --- a/detections/cloud/asl_aws_ecr_container_upload_unknown_user.yml +++ b/detections/cloud/asl_aws_ecr_container_upload_unknown_user.yml @@ -1,15 +1,34 @@ name: ASL AWS ECR Container Upload Unknown User id: 886a8f46-d7e2-4439-b9ba-aec238e31732 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly -description: The following analytic detects unauthorized container uploads to AWS Elastic Container Service (ECR) by monitoring AWS CloudTrail events. It identifies instances where a new container is uploaded by a user not previously recognized as authorized. This detection is crucial for a SOC as it can indicate a potential compromise or misuse of AWS ECR, which could lead to unauthorized access to sensitive data or the deployment of malicious containers. By identifying and investigating these events, organizations can mitigate the risk of data breaches or other security incidents resulting from unauthorized container uploads. The impact of such an attack could be significant, compromising the integrity and security of the organization's cloud environment. -data_source: +description: The following analytic detects unauthorized container uploads to AWS + Elastic Container Service (ECR) by monitoring AWS CloudTrail events. It identifies + instances where a new container is uploaded by a user not previously recognized + as authorized. This detection is crucial for a SOC as it can indicate a potential + compromise or misuse of AWS ECR, which could lead to unauthorized access to sensitive + data or the deployment of malicious containers. By identifying and investigating + these events, organizations can mitigate the risk of data breaches or other security + incidents resulting from unauthorized container uploads. The impact of such an attack + could be significant, compromising the integrity and security of the organization's + cloud environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=PutImage NOT `aws_ecr_users_asl` | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_ecr_container_upload_unknown_user_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. +search: '`amazon_security_lake` api.operation=PutImage NOT `aws_ecr_users_asl` | stats + count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid + actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename + actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `asl_aws_ecr_container_upload_unknown_user_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. known_false_positives: unknown references: - https://attack.mitre.org/techniques/T1204/003/ @@ -42,7 +61,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security @@ -51,6 +69,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_iam_successful_group_deletion.yml b/detections/cloud/asl_aws_iam_successful_group_deletion.yml index 0eb874ecb5..c6b0e18965 100644 --- a/detections/cloud/asl_aws_iam_successful_group_deletion.yml +++ b/detections/cloud/asl_aws_iam_successful_group_deletion.yml @@ -1,16 +1,32 @@ name: ASL AWS IAM Successful Group Deletion id: 1bbe54f1-93d7-4764-8a01-ddaa12ece7ac -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Hunting -description: The following analytic detects the successful deletion of a group within AWS IAM, leveraging CloudTrail IAM events. This action, while not inherently malicious, can serve as a precursor to more sinister activities, such as unauthorized access or privilege escalation attempts. By monitoring for such deletions, the analytic aids in identifying potential preparatory steps towards an attack, allowing for early detection and mitigation. The identification of this behavior is crucial for a SOC to prevent the potential impact of an attack, which could include unauthorized access to sensitive resources or disruption of AWS environment operations. -data_source: +description: The following analytic detects the successful deletion of a group within + AWS IAM, leveraging CloudTrail IAM events. This action, while not inherently malicious, + can serve as a precursor to more sinister activities, such as unauthorized access + or privilege escalation attempts. By monitoring for such deletions, the analytic + aids in identifying potential preparatory steps towards an attack, allowing for + early detection and mitigation. The identification of this behavior is crucial for + a SOC to prevent the potential impact of an attack, which could include unauthorized + access to sensitive resources or disruption of AWS environment operations. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=DeleteGroup status=Success | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_iam_successful_group_deletion_filter`' -how_to_implement: You must install the Data Lake Federated Analytics App and ingest the logs into Splunk. -known_false_positives: This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users. Not every user with AWS access should have permission to delete groups (least privilege). +search: '`amazon_security_lake` api.operation=DeleteGroup status=Success | fillnull + | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid + actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename + actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `asl_aws_iam_successful_group_deletion_filter`' +how_to_implement: You must install the Data Lake Federated Analytics App and ingest + the logs into Splunk. +known_false_positives: This detection will require tuning to provide high fidelity + detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) + or by groups of users. Not every user with AWS access should have permission to + delete groups (least privilege). references: - https://awscli.amazonaws.com/v2/documentation/api/latest/reference/iam/delete-group.html - https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteGroup.html @@ -21,7 +37,6 @@ tags: mitre_attack_id: - T1069.003 - T1098 - - T1069 product: - Splunk Enterprise - Splunk Enterprise Security @@ -30,6 +45,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_successful_group_deletion/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_successful_group_deletion/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml b/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml index a26e3c1500..0a6a467261 100644 --- a/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml +++ b/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml @@ -1,16 +1,34 @@ name: ASL AWS Multi-Factor Authentication Disabled id: 4d2df5e0-1092-4817-88a8-79c7fa054668 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP -description: The following analytic detects attempts to disable multi-factor authentication (MFA) for an AWS IAM user. It leverages Amazon Security Lake logs, specifically monitoring for `DeleteVirtualMFADevice` or `DeactivateMFADevice` API operations. This activity is significant as disabling MFA can indicate an adversary attempting to weaken account security to maintain persistence using a compromised account. If confirmed malicious, this action could allow attackers to retain access to the AWS environment without detection, potentially leading to unauthorized access to sensitive resources and prolonged compromise. -data_source: +description: The following analytic detects attempts to disable multi-factor authentication + (MFA) for an AWS IAM user. It leverages Amazon Security Lake logs, specifically + monitoring for `DeleteVirtualMFADevice` or `DeactivateMFADevice` API operations. + This activity is significant as disabling MFA can indicate an adversary attempting + to weaken account security to maintain persistence using a compromised account. + If confirmed malicious, this action could allow attackers to retain access to the + AWS environment without detection, potentially leading to unauthorized access to + sensitive resources and prolonged compromise. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` (api.operation=DeleteVirtualMFADevice OR api.operation=DeactivateMFADevice) | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_multi_factor_authentication_disabled_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: AWS Administrators may disable MFA but it is highly unlikely for this event to occur without prior notice to the company +search: '`amazon_security_lake` (api.operation=DeleteVirtualMFADevice OR api.operation=DeactivateMFADevice) + | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation + actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region + | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, + http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `asl_aws_multi_factor_authentication_disabled_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: AWS Administrators may disable MFA but it is highly unlikely + for this event to occur without prior notice to the company references: - https://attack.mitre.org/techniques/T1621/ - https://aws.amazon.com/what-is/mfa/ @@ -42,11 +60,9 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 + - T1556.006 - T1586.003 - T1621 - - T1556 - - T1556.006 product: - Splunk Enterprise - Splunk Enterprise Security @@ -55,6 +71,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/aws_mfa_disabled/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/aws_mfa_disabled/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_network_access_control_list_created_with_all_open_ports.yml b/detections/cloud/asl_aws_network_access_control_list_created_with_all_open_ports.yml index 7d42dfa04e..62a56cf3bb 100644 --- a/detections/cloud/asl_aws_network_access_control_list_created_with_all_open_ports.yml +++ b/detections/cloud/asl_aws_network_access_control_list_created_with_all_open_ports.yml @@ -1,26 +1,41 @@ name: ASL AWS Network Access Control List Created with All Open Ports id: a2625034-c2de-44fc-b45c-7bac9c4a7974 -version: 1 -date: '2025-01-09' +version: 2 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP -description: The following analytic detects the creation of AWS Network Access Control Lists (ACLs) with all ports open to a specified CIDR. It leverages AWS CloudTrail events, specifically monitoring for `CreateNetworkAclEntry` or `ReplaceNetworkAclEntry` actions with rules allowing all traffic. This activity is significant because it can expose the network to unauthorized access, increasing the risk of data breaches and other malicious activities. If confirmed malicious, an attacker could exploit this misconfiguration to gain unrestricted access to the network, potentially leading to data exfiltration, service disruption, or further compromise of the AWS environment. -data_source: +description: The following analytic detects the creation of AWS Network Access Control + Lists (ACLs) with all ports open to a specified CIDR. It leverages AWS CloudTrail + events, specifically monitoring for `CreateNetworkAclEntry` or `ReplaceNetworkAclEntry` + actions with rules allowing all traffic. This activity is significant because it + can expose the network to unauthorized access, increasing the risk of data breaches + and other malicious activities. If confirmed malicious, an attacker could exploit + this misconfiguration to gain unrestricted access to the network, potentially leading + to data exfiltration, service disruption, or further compromise of the AWS environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=CreateNetworkAclEntry OR api.operation=ReplaceNetworkAclEntry status=Success - | spath input=api.request.data path=ruleAction output=ruleAction - | spath input=api.request.data path=egress output=egress - | spath input=api.request.data path=aclProtocol output=aclProtocol - | spath input=api.request.data path=cidrBlock output=cidrBlock - | spath input=api.request.data path=networkAclId output=networkAclId +search: '`amazon_security_lake` api.operation=CreateNetworkAclEntry OR api.operation=ReplaceNetworkAclEntry + status=Success | spath input=api.request.data path=ruleAction output=ruleAction + | spath input=api.request.data path=egress output=egress | spath input=api.request.data + path=aclProtocol output=aclProtocol | spath input=api.request.data path=cidrBlock + output=cidrBlock | spath input=api.request.data path=networkAclId output=networkAclId | search ruleAction=allow AND egress=false AND aclProtocol=-1 AND cidrBlock=0.0.0.0/0 - | fillnull - | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region networkAclId cidrBlock - | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid as aws_account_id - | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_network_access_control_list_created_with_all_open_ports_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: It's possible that an admin has created this ACL with all ports open for some legitimate purpose however, this should be scoped and not allowed in production environment. + | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation + actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region + networkAclId cidrBlock | rename actor.user.uid as user, src_endpoint.ip as src_ip, + cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid + as aws_account_id | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` + | `asl_aws_network_access_control_list_created_with_all_open_ports_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: It's possible that an admin has created this ACL with all ports + open for some legitimate purpose however, this should be scoped and not allowed + in production environment. references: [] drilldown_searches: - name: View the detection results for - "$user$" @@ -28,7 +43,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -46,7 +66,6 @@ tags: asset_type: AWS Instance mitre_attack_id: - T1562.007 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security @@ -55,6 +74,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_create_acl/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_create_acl/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_network_access_control_list_deleted.yml b/detections/cloud/asl_aws_network_access_control_list_deleted.yml index 067e4b543f..23067c2c55 100644 --- a/detections/cloud/asl_aws_network_access_control_list_deleted.yml +++ b/detections/cloud/asl_aws_network_access_control_list_deleted.yml @@ -1,23 +1,35 @@ name: ASL AWS Network Access Control List Deleted id: e010ddf5-e9a5-44e5-bdd6-0c919ba8fc8b -version: 1 -date: '2025-01-09' +version: 2 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly -description: The following analytic detects the deletion of AWS Network Access Control Lists (ACLs). It leverages AWS CloudTrail logs to identify events where a user deletes a network ACL entry. This activity is significant because deleting a network ACL can remove critical access restrictions, potentially allowing unauthorized access to cloud instances. If confirmed malicious, this action could enable attackers to bypass network security controls, leading to unauthorized access, data exfiltration, or further compromise of the cloud environment. -data_source: +description: The following analytic detects the deletion of AWS Network Access Control + Lists (ACLs). It leverages AWS CloudTrail logs to identify events where a user deletes + a network ACL entry. This activity is significant because deleting a network ACL + can remove critical access restrictions, potentially allowing unauthorized access + to cloud instances. If confirmed malicious, this action could enable attackers to + bypass network security controls, leading to unauthorized access, data exfiltration, + or further compromise of the cloud environment. +data_source: - ASL AWS CloudTrail search: '`amazon_security_lake` api.operation=DeleteNetworkAclEntry status=Success - | spath input=api.request.data path=egress output=egress - | spath input=api.request.data path=networkAclId output=networkAclId - | search egress=false - | fillnull - | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region networkAclId - | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account_uid as aws_account_id - | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_network_access_control_list_deleted_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: It's possible that a user has legitimately deleted a network ACL. + | spath input=api.request.data path=egress output=egress | spath input=api.request.data + path=networkAclId output=networkAclId | search egress=false | fillnull | stats count + min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid + http_request.user_agent src_endpoint.ip cloud.region networkAclId | rename actor.user.uid + as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent, actor.user.account_uid as aws_account_id | `security_content_ctime(firstTime)`| + `security_content_ctime(lastTime)` | `asl_aws_network_access_control_list_deleted_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: It's possible that a user has legitimately deleted a network + ACL. references: [] drilldown_searches: - name: View the detection results for - "$user$" @@ -25,7 +37,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -43,7 +60,6 @@ tags: asset_type: AWS Instance mitre_attack_id: - T1562.007 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security @@ -52,6 +68,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_delete_acl/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_delete_acl/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_new_mfa_method_registered_for_user.yml b/detections/cloud/asl_aws_new_mfa_method_registered_for_user.yml index bf67c362b9..e787dbcf30 100644 --- a/detections/cloud/asl_aws_new_mfa_method_registered_for_user.yml +++ b/detections/cloud/asl_aws_new_mfa_method_registered_for_user.yml @@ -1,16 +1,34 @@ name: ASL AWS New MFA Method Registered For User id: 33ae0931-2a03-456b-b1d7-b016c5557fbd -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: experimental type: TTP -description: The following analytic identifies the registration of a new Multi-Factor Authentication (MFA) method for an AWS account, as logged through Amazon Security Lake (ASL). It detects this activity by monitoring the `CreateVirtualMFADevice` API operation within ASL logs. This behavior is significant because adversaries who gain unauthorized access to an AWS account may register a new MFA method to maintain persistence. If confirmed malicious, this activity could allow attackers to secure their access, making it harder to detect and remove their presence from the compromised environment. -data_source: +description: The following analytic identifies the registration of a new Multi-Factor + Authentication (MFA) method for an AWS account, as logged through Amazon Security + Lake (ASL). It detects this activity by monitoring the `CreateVirtualMFADevice` + API operation within ASL logs. This behavior is significant because adversaries + who gain unauthorized access to an AWS account may register a new MFA method to + maintain persistence. If confirmed malicious, this activity could allow attackers + to secure their access, making it harder to detect and remove their presence from + the compromised environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=CreateVirtualMFADevice | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_new_mfa_method_registered_for_user_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: Newly onboarded users who are registering an MFA method for the first time will also trigger this detection. +search: '`amazon_security_lake` api.operation=CreateVirtualMFADevice | fillnull | + stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid + actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename + actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `asl_aws_new_mfa_method_registered_for_user_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: Newly onboarded users who are registering an MFA method for + the first time will also trigger this detection. references: - https://aws.amazon.com/blogs/security/you-can-now-assign-multiple-mfa-devices-in-iam/ - https://attack.mitre.org/techniques/T1556/ @@ -30,7 +48,6 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1556 - T1556.006 product: - Splunk Enterprise @@ -40,6 +57,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.006/aws_new_mfa_method_registered_for_user/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.006/aws_new_mfa_method_registered_for_user/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_updateloginprofile.yml b/detections/cloud/asl_aws_updateloginprofile.yml index eab3050952..c6f1588db7 100644 --- a/detections/cloud/asl_aws_updateloginprofile.yml +++ b/detections/cloud/asl_aws_updateloginprofile.yml @@ -1,20 +1,34 @@ name: ASL AWS UpdateLoginProfile id: 5b3f63a3-865b-4637-9941-f98bd1a50c0d -version: 1 -date: '2025-01-09' +version: 2 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP -description: The following analytic detects an AWS CloudTrail event where a user with permissions updates the login profile of another user. It leverages CloudTrail logs to identify instances where the user making the change is different from the user whose profile is being updated. This activity is significant because it can indicate privilege escalation attempts, where an attacker uses a compromised account to gain higher privileges. If confirmed malicious, this could allow the attacker to escalate their privileges, potentially leading to unauthorized access and control over sensitive resources within the AWS environment. -data_source: +description: The following analytic detects an AWS CloudTrail event where a user with + permissions updates the login profile of another user. It leverages CloudTrail logs + to identify instances where the user making the change is different from the user + whose profile is being updated. This activity is significant because it can indicate + privilege escalation attempts, where an attacker uses a compromised account to gain + higher privileges. If confirmed malicious, this could allow the attacker to escalate + their privileges, potentially leading to unauthorized access and control over sensitive + resources within the AWS environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=UpdateLoginProfile - | fillnull - | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region - | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent - | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_updateloginprofile_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. +search: '`amazon_security_lake` api.operation=UpdateLoginProfile | fillnull | stats + count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid + actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename + actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `asl_aws_updateloginprofile_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has legitimately created keys for another user. references: - https://bishopfox.com/blog/privilege-escalation-in-aws - https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ @@ -24,12 +38,18 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: User $user$ from IP address $src_ip$ updated the login profile of another user - risk_objects: + message: User $user$ from IP address $src_ip$ updated the login profile of another + user + risk_objects: - field: user type: user score: 30 @@ -42,7 +62,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1136.003 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security @@ -51,6 +70,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_updateloginprofile/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_updateloginprofile/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml b/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml index 7938f15e75..f8f6815c8d 100644 --- a/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml +++ b/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml @@ -1,7 +1,7 @@ name: AWS Console Login Failed During MFA Challenge id: 55349868-5583-466f-98ab-d3beb321961e -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - Compromised User Account asset_type: AWS Account mitre_attack_id: - - T1586 - T1586.003 - T1621 product: diff --git a/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml b/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml index 5f46f6eb98..13339e55f9 100644 --- a/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml +++ b/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml @@ -1,7 +1,7 @@ name: AWS Create Policy Version to allow all resources id: 2a9b80d3-6340-4345-b5ad-212bf3d0dac4 -version: 7 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1078.004 - - T1078 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_createaccesskey.yml b/detections/cloud/aws_createaccesskey.yml index 5e4a3636e3..8e4db2dd78 100644 --- a/detections/cloud/aws_createaccesskey.yml +++ b/detections/cloud/aws_createaccesskey.yml @@ -1,7 +1,7 @@ name: AWS CreateAccessKey id: 2a9b80d3-6340-4345-11ad-212bf3d0d111 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: Hunting @@ -33,7 +33,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1136.003 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_createloginprofile.yml b/detections/cloud/aws_createloginprofile.yml index d72c2ed8a9..8e8b47aab4 100644 --- a/detections/cloud/aws_createloginprofile.yml +++ b/detections/cloud/aws_createloginprofile.yml @@ -1,7 +1,7 @@ name: AWS CreateLoginProfile id: 2a9b80d3-6340-4345-11ad-212bf444d111 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1136.003 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_credential_access_failed_login.yml b/detections/cloud/aws_credential_access_failed_login.yml index 7b19d32062..4034c85a31 100644 --- a/detections/cloud/aws_credential_access_failed_login.yml +++ b/detections/cloud/aws_credential_access_failed_login.yml @@ -1,7 +1,7 @@ name: AWS Credential Access Failed Login id: a19b354d-0d7f-47f3-8ea6-1a7c36434968 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Gowthamaraj Rajendran, Bhavin Patel, Splunk status: production type: TTP @@ -54,10 +54,8 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.001 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_credential_access_getpassworddata.yml b/detections/cloud/aws_credential_access_getpassworddata.yml index 24b5b4f9f6..78e473d83e 100644 --- a/detections/cloud/aws_credential_access_getpassworddata.yml +++ b/detections/cloud/aws_credential_access_getpassworddata.yml @@ -1,7 +1,7 @@ name: AWS Credential Access GetPasswordData id: 4d347c4a-306e-41db-8d10-b46baf71b3e2 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: Anomaly @@ -57,10 +57,8 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.001 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_credential_access_rds_password_reset.yml b/detections/cloud/aws_credential_access_rds_password_reset.yml index 16d5d8fce2..344ab68bfa 100644 --- a/detections/cloud/aws_credential_access_rds_password_reset.yml +++ b/detections/cloud/aws_credential_access_rds_password_reset.yml @@ -1,7 +1,7 @@ name: AWS Credential Access RDS Password reset id: 6153c5ea-ed30-4878-81e6-21ecdb198189 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -52,9 +52,8 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 - - T1586.003 - T1110 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml b/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml index 15acf34a9a..94cb3378c3 100644 --- a/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml +++ b/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml @@ -1,7 +1,7 @@ name: AWS Defense Evasion Delete Cloudtrail id: 82092925-9ca1-4e06-98b8-85a2d3889552 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1562.008 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml b/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml index 50d8d4f9f7..1ed54c1b07 100644 --- a/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml +++ b/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml @@ -1,7 +1,7 @@ name: AWS Defense Evasion Delete CloudWatch Log Group id: d308b0f1-edb7-4a62-a614-af321160710f -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -55,7 +55,6 @@ tags: - AWS Defense Evasion asset_type: AWS Account mitre_attack_id: - - T1562 - T1562.008 product: - Splunk Enterprise diff --git a/detections/cloud/aws_defense_evasion_impair_security_services.yml b/detections/cloud/aws_defense_evasion_impair_security_services.yml index 1f05298c2f..e4575b1b7d 100644 --- a/detections/cloud/aws_defense_evasion_impair_security_services.yml +++ b/detections/cloud/aws_defense_evasion_impair_security_services.yml @@ -1,7 +1,7 @@ name: AWS Defense Evasion Impair Security Services id: b28c4957-96a6-47e0-a965-6c767aac1458 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Gowthamaraj Rajendran, Splunk status: production type: Hunting @@ -42,7 +42,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1562.008 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml b/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml index 4d98499ce9..036da0fa9e 100644 --- a/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml +++ b/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml @@ -1,7 +1,7 @@ name: AWS Defense Evasion PutBucketLifecycle id: ce1c0e2b-9303-4903-818b-0d9002fc6ea4 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel status: production type: Hunting @@ -33,10 +33,8 @@ tags: - AWS Defense Evasion asset_type: AWS Account mitre_attack_id: - - T1562.008 - - T1562 - T1485.001 - - T1485 + - T1562.008 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml b/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml index e59c2100ae..e459980cb4 100644 --- a/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml +++ b/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml @@ -1,7 +1,7 @@ name: AWS Defense Evasion Stop Logging Cloudtrail id: 8a2f3ca2-4eb5-4389-a549-14063882e537 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1562.008 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_defense_evasion_update_cloudtrail.yml b/detections/cloud/aws_defense_evasion_update_cloudtrail.yml index 89559d06de..8e6052f1b5 100644 --- a/detections/cloud/aws_defense_evasion_update_cloudtrail.yml +++ b/detections/cloud/aws_defense_evasion_update_cloudtrail.yml @@ -1,7 +1,7 @@ name: AWS Defense Evasion Update Cloudtrail id: 7c921d28-ef48-4f1b-85b3-0af8af7697db -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -55,7 +55,6 @@ tags: - AWS Defense Evasion asset_type: AWS Account mitre_attack_id: - - T1562 - T1562.008 product: - Splunk Enterprise diff --git a/detections/cloud/aws_ecr_container_scanning_findings_high.yml b/detections/cloud/aws_ecr_container_scanning_findings_high.yml index 2d8b0c01a9..5725fbb00d 100644 --- a/detections/cloud/aws_ecr_container_scanning_findings_high.yml +++ b/detections/cloud/aws_ecr_container_scanning_findings_high.yml @@ -1,7 +1,7 @@ name: AWS ECR Container Scanning Findings High id: 30a0e9f8-f1dd-4f9d-8fc2-c622461d781c -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml b/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml index 12c75e5cdc..b9aa8443f3 100644 --- a/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml +++ b/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml @@ -1,7 +1,7 @@ name: AWS ECR Container Scanning Findings Low Informational Unknown id: cbc95e44-7c22-443f-88fd-0424478f5589 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Eric McGinnis Splunk status: production type: Anomaly @@ -57,7 +57,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_ecr_container_scanning_findings_medium.yml b/detections/cloud/aws_ecr_container_scanning_findings_medium.yml index 74e533680f..92b1b9ea7d 100644 --- a/detections/cloud/aws_ecr_container_scanning_findings_medium.yml +++ b/detections/cloud/aws_ecr_container_scanning_findings_medium.yml @@ -1,7 +1,7 @@ name: AWS ECR Container Scanning Findings Medium id: 0b80e2c8-c746-4ddb-89eb-9efd892220cf -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml b/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml index 0f3a5de777..c72dfc4012 100644 --- a/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml +++ b/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml @@ -1,7 +1,7 @@ name: AWS ECR Container Upload Outside Business Hours id: d4c4d4eb-3994-41ca-a25e-a82d64e125bb -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_ecr_container_upload_unknown_user.yml b/detections/cloud/aws_ecr_container_upload_unknown_user.yml index bdb09cde4c..345bf6d589 100644 --- a/detections/cloud/aws_ecr_container_upload_unknown_user.yml +++ b/detections/cloud/aws_ecr_container_upload_unknown_user.yml @@ -1,7 +1,7 @@ name: AWS ECR Container Upload Unknown User id: 300688e4-365c-4486-a065-7c884462b31d -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly @@ -54,7 +54,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml b/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml index 58d7a9e5e7..330c094796 100644 --- a/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml +++ b/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml @@ -1,7 +1,7 @@ name: AWS High Number Of Failed Authentications From Ip id: f75b7f1a-b8eb-4975-a214-ff3e0a944757 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: Anomaly @@ -55,7 +55,6 @@ tags: - Compromised User Account asset_type: AWS Account mitre_attack_id: - - T1110 - T1110.003 - T1110.004 product: diff --git a/detections/cloud/aws_iam_successful_group_deletion.yml b/detections/cloud/aws_iam_successful_group_deletion.yml index 82f8c5e8fb..cc47b126e9 100644 --- a/detections/cloud/aws_iam_successful_group_deletion.yml +++ b/detections/cloud/aws_iam_successful_group_deletion.yml @@ -1,7 +1,7 @@ name: AWS IAM Successful Group Deletion id: e776d06c-9267-11eb-819b-acde48001122 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -36,7 +36,6 @@ tags: mitre_attack_id: - T1069.003 - T1098 - - T1069 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_multi_factor_authentication_disabled.yml b/detections/cloud/aws_multi_factor_authentication_disabled.yml index 827af91c86..6d85bd5101 100644 --- a/detections/cloud/aws_multi_factor_authentication_disabled.yml +++ b/detections/cloud/aws_multi_factor_authentication_disabled.yml @@ -1,7 +1,7 @@ name: AWS Multi-Factor Authentication Disabled id: 374832b1-3603-420c-b456-b373e24d34c0 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -56,11 +56,9 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 + - T1556.006 - T1586.003 - T1621 - - T1556 - - T1556.006 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml b/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml index 0e087f273c..4f1a8a187f 100644 --- a/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml +++ b/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml @@ -1,7 +1,7 @@ name: AWS Multiple Failed MFA Requests For User id: 1fece617-e614-4329-9e61-3ba228c0f353 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel status: production type: Anomaly @@ -54,7 +54,6 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 - T1586.003 - T1621 product: diff --git a/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml b/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml index 7fdb466244..82e904fe15 100644 --- a/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml +++ b/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml @@ -1,7 +1,7 @@ name: AWS Multiple Users Failing To Authenticate From Ip id: 71e1fb89-dd5f-4691-8523-575420de4630 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel status: production type: Anomaly @@ -57,7 +57,6 @@ tags: - Compromised User Account asset_type: AWS Account mitre_attack_id: - - T1110 - T1110.003 - T1110.004 product: diff --git a/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml b/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml index 9c3254ca93..a392435e99 100644 --- a/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml +++ b/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml @@ -1,7 +1,7 @@ name: AWS Network Access Control List Created with All Open Ports id: ada0f478-84a8-4641-a3f1-d82362d6bd75 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Patrick Bareiss, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: AWS Instance mitre_attack_id: - T1562.007 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_network_access_control_list_deleted.yml b/detections/cloud/aws_network_access_control_list_deleted.yml index 8499371040..fe044edec0 100644 --- a/detections/cloud/aws_network_access_control_list_deleted.yml +++ b/detections/cloud/aws_network_access_control_list_deleted.yml @@ -1,7 +1,7 @@ name: AWS Network Access Control List Deleted id: ada0f478-84a8-4641-a3f1-d82362d6fd75 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Patrick Bareiss, Splunk status: production type: Anomaly @@ -54,7 +54,6 @@ tags: asset_type: AWS Instance mitre_attack_id: - T1562.007 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_new_mfa_method_registered_for_user.yml b/detections/cloud/aws_new_mfa_method_registered_for_user.yml index 1891036414..50a9b9bc57 100644 --- a/detections/cloud/aws_new_mfa_method_registered_for_user.yml +++ b/detections/cloud/aws_new_mfa_method_registered_for_user.yml @@ -1,7 +1,7 @@ name: AWS New MFA Method Registered For User id: 4e3c26f2-4fb9-4bd7-ab46-1b76ffa2a23b -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1556 - T1556.006 product: - Splunk Enterprise diff --git a/detections/cloud/aws_setdefaultpolicyversion.yml b/detections/cloud/aws_setdefaultpolicyversion.yml index b927809aa5..a1fef13c96 100644 --- a/detections/cloud/aws_setdefaultpolicyversion.yml +++ b/detections/cloud/aws_setdefaultpolicyversion.yml @@ -1,7 +1,7 @@ name: AWS SetDefaultPolicyVersion id: 2a9b80d3-6340-4345-11ad-212bf3d0dac4 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1078.004 - - T1078 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_successful_single_factor_authentication.yml b/detections/cloud/aws_successful_single_factor_authentication.yml index 0e3b986294..86f0eff62a 100644 --- a/detections/cloud/aws_successful_single_factor_authentication.yml +++ b/detections/cloud/aws_successful_single_factor_authentication.yml @@ -1,7 +1,7 @@ name: AWS Successful Single-Factor Authentication id: a520b1fe-cc9e-4f56-b762-18354594c52f -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -56,10 +56,8 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 - - T1586.003 - - T1078 - T1078.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml b/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml index 6e86b15927..1ba8b2c8a4 100644 --- a/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml +++ b/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml @@ -1,7 +1,7 @@ name: AWS Unusual Number of Failed Authentications From Ip id: 0b5c9c2b-e2cb-4831-b4f1-af125ceb1386 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: Anomaly @@ -57,11 +57,9 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.003 - T1110.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_updateloginprofile.yml b/detections/cloud/aws_updateloginprofile.yml index a8ffb62a72..c90f5d742a 100644 --- a/detections/cloud/aws_updateloginprofile.yml +++ b/detections/cloud/aws_updateloginprofile.yml @@ -1,7 +1,7 @@ name: AWS UpdateLoginProfile id: 2a9b80d3-6a40-4115-11ad-212bf3d0d111 -version: 7 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1136.003 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/azure_active_directory_high_risk_sign_in.yml b/detections/cloud/azure_active_directory_high_risk_sign_in.yml index 0153fff2b2..a7a0c90d5f 100644 --- a/detections/cloud/azure_active_directory_high_risk_sign_in.yml +++ b/detections/cloud/azure_active_directory_high_risk_sign_in.yml @@ -1,7 +1,7 @@ name: Azure Active Directory High Risk Sign-in id: 1ecff169-26d7-4161-9a7b-2ac4c8e61bea -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -58,10 +58,8 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Active Directory mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.003 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/azure_ad_application_administrator_role_assigned.yml b/detections/cloud/azure_ad_application_administrator_role_assigned.yml index 33eb6d2a8d..6cad0084c7 100644 --- a/detections/cloud/azure_ad_application_administrator_role_assigned.yml +++ b/detections/cloud/azure_ad_application_administrator_role_assigned.yml @@ -1,7 +1,7 @@ name: Azure AD Application Administrator Role Assigned id: eac4de87-7a56-4538-a21b-277897af6d8d -version: 6 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Azure Active Directory atomic_guid: [] mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml b/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml index 0ccbb9b85a..85366a53f5 100644 --- a/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml +++ b/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml @@ -1,7 +1,7 @@ name: Azure AD Authentication Failed During MFA Challenge id: e62c9c2e-bf51-4719-906c-3074618fcc1c -version: 7 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk, 0xC0FFEEEE status: production type: TTP @@ -70,10 +70,8 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Active Directory mitre_attack_id: - - T1586 - - T1586.003 - - T1078 - T1078.004 + - T1586.003 - T1621 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_azurehound_useragent_detected.yml b/detections/cloud/azure_ad_azurehound_useragent_detected.yml index 12b044f4c3..b81c81b399 100644 --- a/detections/cloud/azure_ad_azurehound_useragent_detected.yml +++ b/detections/cloud/azure_ad_azurehound_useragent_detected.yml @@ -1,6 +1,6 @@ name: Azure AD AzureHound UserAgent Detected id: d62852db-a1f1-40db-a7fc-c3d56fa8bda3 -version: 1 +version: 2 date: '2025-01-06' author: Dean Luxton data_source: diff --git a/detections/cloud/azure_ad_device_code_authentication.yml b/detections/cloud/azure_ad_device_code_authentication.yml index dbe2c55afe..42e16cab04 100644 --- a/detections/cloud/azure_ad_device_code_authentication.yml +++ b/detections/cloud/azure_ad_device_code_authentication.yml @@ -1,7 +1,7 @@ name: Azure AD Device Code Authentication id: d68d8732-6f7e-4ee5-a6eb-737f2b990b91 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: asset_type: Azure Tenant mitre_attack_id: - T1528 - - T1566 - T1566.002 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_external_guest_user_invited.yml b/detections/cloud/azure_ad_external_guest_user_invited.yml index 0a30335c00..b21df736a9 100644 --- a/detections/cloud/azure_ad_external_guest_user_invited.yml +++ b/detections/cloud/azure_ad_external_guest_user_invited.yml @@ -1,6 +1,6 @@ name: Azure AD External Guest User Invited id: c1fb4edb-cab1-4359-9b40-925ffd797fb5 -version: 5 +version: 6 date: '2024-11-14' author: Gowthamaraj Rajendran, Mauricio Velazco, Splunk status: production diff --git a/detections/cloud/azure_ad_high_number_of_failed_authentications_for_user.yml b/detections/cloud/azure_ad_high_number_of_failed_authentications_for_user.yml index 2ebfe3128c..f095735f34 100644 --- a/detections/cloud/azure_ad_high_number_of_failed_authentications_for_user.yml +++ b/detections/cloud/azure_ad_high_number_of_failed_authentications_for_user.yml @@ -1,7 +1,7 @@ name: Azure AD High Number Of Failed Authentications For User id: 630b1694-210a-48ee-a450-6f79e7679f2c -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Tenant mitre_attack_id: - - T1110 - T1110.001 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_high_number_of_failed_authentications_from_ip.yml b/detections/cloud/azure_ad_high_number_of_failed_authentications_from_ip.yml index 9829ad4b7a..27095cce04 100644 --- a/detections/cloud/azure_ad_high_number_of_failed_authentications_from_ip.yml +++ b/detections/cloud/azure_ad_high_number_of_failed_authentications_from_ip.yml @@ -1,7 +1,7 @@ name: Azure AD High Number Of Failed Authentications From Ip id: e5ab41bf-745d-4f72-a393-2611151afd8e -version: 7 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Bhavin Patel, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: - NOBELIUM Group asset_type: Azure Tenant mitre_attack_id: - - T1110 - T1110.001 - T1110.003 product: diff --git a/detections/cloud/azure_ad_multi_factor_authentication_disabled.yml b/detections/cloud/azure_ad_multi_factor_authentication_disabled.yml index 9ede5d603b..850e70b076 100644 --- a/detections/cloud/azure_ad_multi_factor_authentication_disabled.yml +++ b/detections/cloud/azure_ad_multi_factor_authentication_disabled.yml @@ -1,7 +1,7 @@ name: Azure AD Multi-Factor Authentication Disabled id: 482dd42a-acfa-486b-a0bb-d6fcda27318e -version: 5 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -60,10 +60,8 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Active Directory mitre_attack_id: - - T1586 - - T1586.003 - - T1556 - T1556.006 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/azure_ad_multi_source_failed_authentications_spike.yml b/detections/cloud/azure_ad_multi_source_failed_authentications_spike.yml index 01e3e46116..c0d6bedc46 100644 --- a/detections/cloud/azure_ad_multi_source_failed_authentications_spike.yml +++ b/detections/cloud/azure_ad_multi_source_failed_authentications_spike.yml @@ -1,7 +1,7 @@ name: Azure AD Multi-Source Failed Authentications Spike id: 116e11a9-63ea-41eb-a66a-6a13bdc7d2c7 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -53,11 +53,9 @@ tags: asset_type: Azure Tenant atomic_guid: [] mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.003 - T1110.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml b/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml index c132716d7b..19537e44b7 100644 --- a/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml +++ b/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml @@ -1,7 +1,7 @@ name: Azure AD Multiple Failed MFA Requests For User id: 264ea131-ab1f-41b8-90e0-33ad1a1888ea -version: 7 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -62,11 +62,9 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Active Directory mitre_attack_id: - - T1586 + - T1078.004 - T1586.003 - T1621 - - T1078 - - T1078.004 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml b/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml index db156f8d6c..6e6a789764 100644 --- a/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml +++ b/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml @@ -1,7 +1,7 @@ name: Azure AD Multiple Users Failing To Authenticate From Ip id: 94481a6a-8f59-4c86-957f-55a71e3612a6 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -60,11 +60,9 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Active Directory mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.003 - T1110.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/azure_ad_new_custom_domain_added.yml b/detections/cloud/azure_ad_new_custom_domain_added.yml index 9e8a4514bd..07d389a8a6 100644 --- a/detections/cloud/azure_ad_new_custom_domain_added.yml +++ b/detections/cloud/azure_ad_new_custom_domain_added.yml @@ -1,7 +1,7 @@ name: Azure AD New Custom Domain Added id: 30c47f45-dd6a-4720-9963-0bca6c8686ef -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: - Azure Active Directory Persistence asset_type: Azure Active Directory mitre_attack_id: - - T1484 - T1484.002 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_new_federated_domain_added.yml b/detections/cloud/azure_ad_new_federated_domain_added.yml index 18765ab8c2..0f9a57ccca 100644 --- a/detections/cloud/azure_ad_new_federated_domain_added.yml +++ b/detections/cloud/azure_ad_new_federated_domain_added.yml @@ -1,7 +1,7 @@ name: Azure AD New Federated Domain Added id: a87cd633-076d-4ab2-9047-977751a3c1a0 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Azure Active Directory Persistence asset_type: Azure Active Directory mitre_attack_id: - - T1484 - T1484.002 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_new_mfa_method_registered.yml b/detections/cloud/azure_ad_new_mfa_method_registered.yml index 548366097d..7519b45a46 100644 --- a/detections/cloud/azure_ad_new_mfa_method_registered.yml +++ b/detections/cloud/azure_ad_new_mfa_method_registered.yml @@ -1,7 +1,7 @@ name: Azure AD New MFA Method Registered id: 0488e814-eb81-42c3-9f1f-b2244973e3a3 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: - Azure Active Directory Persistence asset_type: Azure Tenant mitre_attack_id: - - T1098 - T1098.005 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_new_mfa_method_registered_for_user.yml b/detections/cloud/azure_ad_new_mfa_method_registered_for_user.yml index aa0fd57ecc..5192c93cff 100644 --- a/detections/cloud/azure_ad_new_mfa_method_registered_for_user.yml +++ b/detections/cloud/azure_ad_new_mfa_method_registered_for_user.yml @@ -1,7 +1,7 @@ name: Azure AD New MFA Method Registered For User id: 2628b087-4189-403f-9044-87403f777a1b -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Active Directory mitre_attack_id: - - T1556 - T1556.006 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_pim_role_assigned.yml b/detections/cloud/azure_ad_pim_role_assigned.yml index 62cf108b66..51d57975fc 100644 --- a/detections/cloud/azure_ad_pim_role_assigned.yml +++ b/detections/cloud/azure_ad_pim_role_assigned.yml @@ -1,7 +1,7 @@ name: Azure AD PIM Role Assigned id: fcd6dfeb-191c-46a0-a29c-c306382145ab -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - Azure Active Directory Persistence asset_type: Azure Active Directory mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_pim_role_assignment_activated.yml b/detections/cloud/azure_ad_pim_role_assignment_activated.yml index 7904b536f7..08536eba75 100644 --- a/detections/cloud/azure_ad_pim_role_assignment_activated.yml +++ b/detections/cloud/azure_ad_pim_role_assignment_activated.yml @@ -1,7 +1,7 @@ name: Azure AD PIM Role Assignment Activated id: 952e80d0-e343-439b-83f4-808c3e6fbf2e -version: 7 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Azure Active Directory Persistence asset_type: Azure Active Directory mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_privileged_role_assigned.yml b/detections/cloud/azure_ad_privileged_role_assigned.yml index e08cfb1eea..c1316e7829 100644 --- a/detections/cloud/azure_ad_privileged_role_assigned.yml +++ b/detections/cloud/azure_ad_privileged_role_assigned.yml @@ -1,7 +1,7 @@ name: Azure AD Privileged Role Assigned id: a28f0bc3-3400-4a6e-a2da-89b9e95f0d2a -version: 6 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: - NOBELIUM Group asset_type: Azure Active Directory mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml b/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml index 5cc46e6989..e054e3954c 100644 --- a/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml +++ b/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml @@ -1,7 +1,7 @@ name: Azure AD Privileged Role Assigned to Service Principal id: 5dfaa3d3-e2e4-4053-8252-16d9ee528c41 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - NOBELIUM Group asset_type: Azure Active Directory mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_service_principal_enumeration.yml b/detections/cloud/azure_ad_service_principal_enumeration.yml index 67af2a74cc..67efb06d67 100644 --- a/detections/cloud/azure_ad_service_principal_enumeration.yml +++ b/detections/cloud/azure_ad_service_principal_enumeration.yml @@ -1,6 +1,6 @@ name: Azure AD Service Principal Enumeration id: 3f0647ce-add5-4436-8039-cbd1abe74563 -version: 1 +version: 2 date: '2025-01-06' author: Dean Luxton data_source: diff --git a/detections/cloud/azure_ad_service_principal_new_client_credentials.yml b/detections/cloud/azure_ad_service_principal_new_client_credentials.yml index c737df98b8..d61c4114f4 100644 --- a/detections/cloud/azure_ad_service_principal_new_client_credentials.yml +++ b/detections/cloud/azure_ad_service_principal_new_client_credentials.yml @@ -1,7 +1,7 @@ name: Azure AD Service Principal New Client Credentials id: e3adc0d3-9e4b-4b5d-b662-12cec1adff2a -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: - NOBELIUM Group asset_type: Azure Active Directory mitre_attack_id: - - T1098 - T1098.001 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_service_principal_owner_added.yml b/detections/cloud/azure_ad_service_principal_owner_added.yml index 652d5977ff..70759d0bbc 100644 --- a/detections/cloud/azure_ad_service_principal_owner_added.yml +++ b/detections/cloud/azure_ad_service_principal_owner_added.yml @@ -1,6 +1,6 @@ name: Azure AD Service Principal Owner Added id: 7ddf2084-6cf3-4a44-be83-474f7b73c701 -version: 7 +version: 8 date: '2024-11-14' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production diff --git a/detections/cloud/azure_ad_service_principal_privilege_escalation.yml b/detections/cloud/azure_ad_service_principal_privilege_escalation.yml index 29720e929f..ea9b383f6a 100644 --- a/detections/cloud/azure_ad_service_principal_privilege_escalation.yml +++ b/detections/cloud/azure_ad_service_principal_privilege_escalation.yml @@ -1,24 +1,35 @@ name: Azure AD Service Principal Privilege Escalation id: 29eb39d3-2bc8-49cc-99b3-35593191a588 -version: 1 -date: '2025-01-06' +version: 2 +date: '2025-02-10' author: Dean Luxton data_source: - Azure Active Directory Add app role assignment to service principal type: TTP status: production -description: This detection identifies when an Azure Service Principal elevates privileges by adding themself to a new app role assignment. +description: This detection identifies when an Azure Service Principal elevates privileges + by adding themself to a new app role assignment. search: >- - `azure_monitor_aad` category=AuditLogs operationName="Add app role assignment to service principal" properties.initiatedBy.app.displayName=* properties.result=Success - | spath path=properties{}.targetResources{}.modifiedProperties{} output=targetResources - | stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value")))) as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName")))) as targetServicePrincipal values(eval(mvindex('properties.targetResources{}.displayName',0))) as targetAppContext values(user_agent) as user_agent values(identity) as servicePrincipal values(properties.initiatedBy.app.servicePrincipalId) as servicePrincipalId by operationName tenantId correlationId + `azure_monitor_aad` category=AuditLogs operationName="Add app role assignment to + service principal" properties.initiatedBy.app.displayName=* properties.result=Success | + spath path=properties{}.targetResources{}.modifiedProperties{} output=targetResources + | stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value")))) + as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName")))) + as targetServicePrincipal values(eval(mvindex('properties.targetResources{}.displayName',0))) + as targetAppContext values(user_agent) as user_agent values(identity) as servicePrincipal + values(properties.initiatedBy.app.servicePrincipalId) as servicePrincipalId by operationName + tenantId correlationId | spath input=appRole path=newValue output=appRole | spath input=targetServicePrincipal path=newValue output=targetServicePrincipal - | eval appRole=trim(replace(appRole, "\"", "")), targetServicePrincipal=trim(replace(targetServicePrincipal, "\"", "")) + | eval appRole=trim(replace(appRole, "\"", "")), targetServicePrincipal=trim(replace(targetServicePrincipal, + "\"", "")) | where servicePrincipal=targetServicePrincipal - | table _time operationName servicePrincipal servicePrincipalId appRole targetAppContext user_agent tenantId correlationId + | table _time operationName servicePrincipal servicePrincipalId appRole targetAppContext + user_agent tenantId correlationId | `azure_ad_service_principal_privilege_escalation_filter` -how_to_implement: The Splunk Add-on for Microsoft Cloud Services add-on is required to ingest EntraID audit logs via Azure EventHub. See reference for links for further details on how to onboard this log source. +how_to_implement: The Splunk Add-on for Microsoft Cloud Services add-on is required + to ingest EntraID audit logs via Azure EventHub. See reference for links for further + details on how to onboard this log source. known_false_positives: Unknown references: - https://splunkbase.splunk.com/app/3110 @@ -32,11 +43,17 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$servicePrincipal$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$servicePrincipal$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$servicePrincipal$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ -rba: - message: Service Principal $servicePrincipal$ has elevated privileges by adding themself to app role $appRole$ +rba: + message: Service Principal $servicePrincipal$ has elevated privileges by adding + themself to app role $appRole$ risk_objects: - field: servicePrincipal type: user @@ -50,7 +67,6 @@ tags: asset_type: Azure Tenant mitre_attack_id: - T1098.003 - - T1098 product: - Splunk Enterprise - Splunk Enterprise Security @@ -59,6 +75,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/azure_ad_spn_privesc/azure_ad_spn_privesc.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/azure_ad_spn_privesc/azure_ad_spn_privesc.log sourcetype: azure:monitor:aad source: Azure AD diff --git a/detections/cloud/azure_ad_successful_authentication_from_different_ips.yml b/detections/cloud/azure_ad_successful_authentication_from_different_ips.yml index 84f19bd9f2..a8a8cf0127 100644 --- a/detections/cloud/azure_ad_successful_authentication_from_different_ips.yml +++ b/detections/cloud/azure_ad_successful_authentication_from_different_ips.yml @@ -1,7 +1,7 @@ name: Azure AD Successful Authentication From Different Ips id: be6d868d-33b6-4aaa-912e-724fb555b11a -version: 7 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Tenant mitre_attack_id: - - T1110 - T1110.001 - T1110.003 product: diff --git a/detections/cloud/azure_ad_successful_powershell_authentication.yml b/detections/cloud/azure_ad_successful_powershell_authentication.yml index 40fc93f31e..47cb6d8ad7 100644 --- a/detections/cloud/azure_ad_successful_powershell_authentication.yml +++ b/detections/cloud/azure_ad_successful_powershell_authentication.yml @@ -1,7 +1,7 @@ name: Azure AD Successful PowerShell Authentication id: 62f10052-d7b3-4e48-b57b-56f8e3ac7ceb -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -60,10 +60,8 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Active Directory mitre_attack_id: - - T1586 - - T1586.003 - - T1078 - T1078.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/azure_ad_successful_single_factor_authentication.yml b/detections/cloud/azure_ad_successful_single_factor_authentication.yml index 08b55c21be..0df441eb5a 100644 --- a/detections/cloud/azure_ad_successful_single_factor_authentication.yml +++ b/detections/cloud/azure_ad_successful_single_factor_authentication.yml @@ -1,7 +1,7 @@ name: Azure AD Successful Single-Factor Authentication id: a560e7f6-1711-4353-885b-40be53101fcd -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -57,10 +57,8 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Active Directory mitre_attack_id: - - T1586 - - T1586.003 - - T1078 - T1078.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/azure_ad_tenant_wide_admin_consent_granted.yml b/detections/cloud/azure_ad_tenant_wide_admin_consent_granted.yml index af3e2f430f..9e187787e0 100644 --- a/detections/cloud/azure_ad_tenant_wide_admin_consent_granted.yml +++ b/detections/cloud/azure_ad_tenant_wide_admin_consent_granted.yml @@ -1,7 +1,7 @@ name: Azure AD Tenant Wide Admin Consent Granted id: dc02c0ee-6ac0-4c7f-87ba-8ce43a4e4418 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: - NOBELIUM Group asset_type: Azure Tenant mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml b/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml index 24fdfff29f..b8d2b2b680 100644 --- a/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml +++ b/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml @@ -1,7 +1,7 @@ name: Azure AD Unusual Number of Failed Authentications From Ip id: 3d8d3a36-93b8-42d7-8d91-c5f24cec223d -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -62,11 +62,9 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Active Directory mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.003 - T1110.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/azure_ad_user_enabled_and_password_reset.yml b/detections/cloud/azure_ad_user_enabled_and_password_reset.yml index 5cd6090c48..f3601f5b68 100644 --- a/detections/cloud/azure_ad_user_enabled_and_password_reset.yml +++ b/detections/cloud/azure_ad_user_enabled_and_password_reset.yml @@ -1,6 +1,6 @@ name: Azure AD User Enabled And Password Reset id: 1347b9e8-2daa-4a6f-be73-b421d3d9e268 -version: 6 +version: 7 date: '2024-11-14' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production diff --git a/detections/cloud/azure_ad_user_immutableid_attribute_updated.yml b/detections/cloud/azure_ad_user_immutableid_attribute_updated.yml index 597d44032d..bb46d01420 100644 --- a/detections/cloud/azure_ad_user_immutableid_attribute_updated.yml +++ b/detections/cloud/azure_ad_user_immutableid_attribute_updated.yml @@ -1,6 +1,6 @@ name: Azure AD User ImmutableId Attribute Updated id: 0c0badad-4536-4a84-a561-5ff760f3c00e -version: 5 +version: 6 date: '2024-11-14' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production diff --git a/detections/cloud/azure_automation_account_created.yml b/detections/cloud/azure_automation_account_created.yml index 61c90cb7d6..9bbaf90a45 100644 --- a/detections/cloud/azure_automation_account_created.yml +++ b/detections/cloud/azure_automation_account_created.yml @@ -1,7 +1,7 @@ name: Azure Automation Account Created id: 860902fd-2e76-46b3-b050-ba548dab576c -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: - Azure Active Directory Persistence asset_type: Azure Tenant mitre_attack_id: - - T1136 - T1136.003 product: - Splunk Enterprise diff --git a/detections/cloud/azure_automation_runbook_created.yml b/detections/cloud/azure_automation_runbook_created.yml index 30cd14ac36..2188fcc83f 100644 --- a/detections/cloud/azure_automation_runbook_created.yml +++ b/detections/cloud/azure_automation_runbook_created.yml @@ -1,7 +1,7 @@ name: Azure Automation Runbook Created id: 178d696d-6dc6-4ee8-9d25-93fee34eaf5b -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: - Azure Active Directory Persistence asset_type: Azure Tenant mitre_attack_id: - - T1136 - T1136.003 product: - Splunk Enterprise diff --git a/detections/cloud/azure_runbook_webhook_created.yml b/detections/cloud/azure_runbook_webhook_created.yml index f380d8cff2..d53e163981 100644 --- a/detections/cloud/azure_runbook_webhook_created.yml +++ b/detections/cloud/azure_runbook_webhook_created.yml @@ -1,7 +1,7 @@ name: Azure Runbook Webhook Created id: e98944a9-92e4-443c-81b8-a322e33ce75a -version: 7 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: - Azure Active Directory Persistence asset_type: Azure Tenant mitre_attack_id: - - T1078 - T1078.004 product: - Splunk Enterprise diff --git a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml index 4608e0889a..67198da281 100644 --- a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml +++ b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml @@ -1,7 +1,7 @@ name: Cloud Compute Instance Created By Previously Unseen User id: 37a0ec8d-827e-4d6d-8025-cedf31f3a149 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Rico Valdez, Splunk status: experimental type: Anomaly @@ -46,7 +46,6 @@ tags: asset_type: Cloud Compute Instance mitre_attack_id: - T1078.004 - - T1078 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml b/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml index d3189b230e..ffe314acbf 100644 --- a/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml +++ b/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml @@ -1,7 +1,7 @@ name: Cloud Instance Modified By Previously Unseen User id: 7fb15084-b14e-405a-bd61-a6de15a40722 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Rico Valdez, Splunk status: experimental type: Anomaly @@ -44,7 +44,6 @@ tags: asset_type: AWS Instance mitre_attack_id: - T1078.004 - - T1078 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/detect_aws_console_login_by_new_user.yml b/detections/cloud/detect_aws_console_login_by_new_user.yml index ac6587474d..135b7f9126 100644 --- a/detections/cloud/detect_aws_console_login_by_new_user.yml +++ b/detections/cloud/detect_aws_console_login_by_new_user.yml @@ -1,7 +1,7 @@ name: Detect AWS Console Login by New User id: bc91a8cd-35e7-4bb2-6140-e756cc46fd71 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Rico Valdez, Splunk status: experimental type: Hunting @@ -38,9 +38,8 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Instance mitre_attack_id: - - T1586 - - T1586.003 - T1552 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml index 2fea4b9d13..041ef49278 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml @@ -1,7 +1,7 @@ name: Detect AWS Console Login by User from New City id: 121b0b11-f8ac-4ed6-a132-3800ca4fc07a -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Eric McGinnis Splunk status: production type: Hunting @@ -45,9 +45,8 @@ tags: - Compromised User Account asset_type: AWS Instance mitre_attack_id: - - T1586 - - T1586.003 - T1535 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml index afbc290db7..11effae0f4 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml @@ -1,7 +1,7 @@ name: Detect AWS Console Login by User from New Country id: 67bd3def-c41c-4bf6-837b-ae196b4257c6 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Eric McGinnis Splunk status: production type: Hunting @@ -45,9 +45,8 @@ tags: - Compromised User Account asset_type: AWS Instance mitre_attack_id: - - T1586 - - T1586.003 - T1535 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml index 8c47e6e6a9..9fc447b49b 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml @@ -1,7 +1,7 @@ name: Detect AWS Console Login by User from New Region id: 9f31aa8e-e37c-46bc-bce1-8b3be646d026 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Eric McGinnis Splunk status: production type: Hunting @@ -46,9 +46,8 @@ tags: - Compromised User Account asset_type: AWS Instance mitre_attack_id: - - T1586 - - T1586.003 - T1535 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml b/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml index 86cae6e982..be2a129f28 100644 --- a/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml +++ b/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml @@ -1,7 +1,7 @@ name: GCP Authentication Failed During MFA Challenge id: 345f7e1d-a3fe-4158-abd8-e630f9878323 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Bhavin Patel, Mauricio Velazco, Splunk status: production type: TTP @@ -55,10 +55,8 @@ tags: - GCP Account Takeover asset_type: Google Cloud Platform tenant mitre_attack_id: - - T1586 - - T1586.003 - - T1078 - T1078.004 + - T1586.003 - T1621 product: - Splunk Enterprise diff --git a/detections/cloud/gcp_multi_factor_authentication_disabled.yml b/detections/cloud/gcp_multi_factor_authentication_disabled.yml index dc6b0479ea..adb0fa638a 100644 --- a/detections/cloud/gcp_multi_factor_authentication_disabled.yml +++ b/detections/cloud/gcp_multi_factor_authentication_disabled.yml @@ -1,7 +1,7 @@ name: GCP Multi-Factor Authentication Disabled id: b9bc5513-6fc1-4821-85a3-e1d81e451c83 -version: 5 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Bhavin Patel, Mauricio Velazco, Splunk status: production type: TTP @@ -58,10 +58,8 @@ tags: - GCP Account Takeover asset_type: GCP mitre_attack_id: - - T1586 - - T1586.003 - - T1556 - T1556.006 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml b/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml index 613b536a54..1a8d679b8a 100644 --- a/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml +++ b/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml @@ -1,7 +1,7 @@ name: GCP Multiple Failed MFA Requests For User id: cbb3cb84-c06f-4393-adcc-5cb6195621f1 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -60,11 +60,9 @@ tags: - GCP Account Takeover asset_type: Google Cloud Platform tenant mitre_attack_id: - - T1586 + - T1078.004 - T1586.003 - T1621 - - T1078 - - T1078.004 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml b/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml index e5b02c1c25..3d44e59505 100644 --- a/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml +++ b/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml @@ -1,7 +1,7 @@ name: GCP Multiple Users Failing To Authenticate From Ip id: da20828e-d6fb-4ee5-afb7-d0ac200923d5 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: Anomaly @@ -61,11 +61,9 @@ tags: - GCP Account Takeover asset_type: Google Cloud Platform tenant mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.003 - T1110.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gcp_successful_single_factor_authentication.yml b/detections/cloud/gcp_successful_single_factor_authentication.yml index 3f13fa8928..8f1d80ddae 100644 --- a/detections/cloud/gcp_successful_single_factor_authentication.yml +++ b/detections/cloud/gcp_successful_single_factor_authentication.yml @@ -1,7 +1,7 @@ name: GCP Successful Single-Factor Authentication id: 40e17d88-87da-414e-b253-8dc1e4f9555b -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Mauricio Velazco, Splunk status: production type: TTP @@ -57,10 +57,8 @@ tags: - GCP Account Takeover asset_type: Google Cloud Platform tenant mitre_attack_id: - - T1586 - - T1586.003 - - T1078 - T1078.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml b/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml index 7e59b0346a..1ab7a9b099 100644 --- a/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml +++ b/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml @@ -1,7 +1,7 @@ name: GCP Unusual Number of Failed Authentications From Ip id: bd8097ed-958a-4873-87d9-44f2b4d85705 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: Anomaly @@ -63,11 +63,9 @@ tags: - GCP Account Takeover asset_type: Google Cloud Platform tenant mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.003 - T1110.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/github_actions_disable_security_workflow.yml b/detections/cloud/github_actions_disable_security_workflow.yml index 8d8f8d8c2a..e9e0bdb045 100644 --- a/detections/cloud/github_actions_disable_security_workflow.yml +++ b/detections/cloud/github_actions_disable_security_workflow.yml @@ -1,7 +1,7 @@ name: GitHub Actions Disable Security Workflow id: 0459f1a5-c0ac-4987-82d6-65081209f854 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly @@ -57,7 +57,6 @@ tags: asset_type: GitHub mitre_attack_id: - T1195.002 - - T1195 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/github_dependabot_alert.yml b/detections/cloud/github_dependabot_alert.yml index 0e93d69aae..b4e1b2b108 100644 --- a/detections/cloud/github_dependabot_alert.yml +++ b/detections/cloud/github_dependabot_alert.yml @@ -1,7 +1,7 @@ name: GitHub Dependabot Alert id: 05032b04-4469-4034-9df7-05f607d75cba -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly @@ -52,7 +52,6 @@ tags: asset_type: GitHub mitre_attack_id: - T1195.001 - - T1195 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/github_pull_request_from_unknown_user.yml b/detections/cloud/github_pull_request_from_unknown_user.yml index 8cfcb7f5fc..44fcbc501e 100644 --- a/detections/cloud/github_pull_request_from_unknown_user.yml +++ b/detections/cloud/github_pull_request_from_unknown_user.yml @@ -1,7 +1,7 @@ name: GitHub Pull Request from Unknown User id: 9d7b9100-8878-4404-914e-ca5e551a641e -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly @@ -53,7 +53,6 @@ tags: asset_type: GitHub mitre_attack_id: - T1195.001 - - T1195 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gsuite_drive_share_in_external_email.yml b/detections/cloud/gsuite_drive_share_in_external_email.yml index 469c97577b..0ad1ce1463 100644 --- a/detections/cloud/gsuite_drive_share_in_external_email.yml +++ b/detections/cloud/gsuite_drive_share_in_external_email.yml @@ -1,7 +1,7 @@ name: Gsuite Drive Share In External Email id: f6ee02d6-fea0-11eb-b2c2-acde48001122 -version: 4 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: experimental type: Anomaly @@ -49,7 +49,6 @@ tags: asset_type: GSuite mitre_attack_id: - T1567.002 - - T1567 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gsuite_email_suspicious_attachment.yml b/detections/cloud/gsuite_email_suspicious_attachment.yml index 7c29d2848b..36963d2120 100644 --- a/detections/cloud/gsuite_email_suspicious_attachment.yml +++ b/detections/cloud/gsuite_email_suspicious_attachment.yml @@ -1,7 +1,7 @@ name: GSuite Email Suspicious Attachment id: 6d663014-fe92-11eb-ab07-acde48001122 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -59,7 +59,6 @@ tags: asset_type: GSuite mitre_attack_id: - T1566.001 - - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml b/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml index 9a0e32f6bd..014b621125 100644 --- a/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml +++ b/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml @@ -1,7 +1,7 @@ name: Gsuite Email Suspicious Subject With Attachment id: 8ef3971e-00f2-11ec-b54f-acde48001122 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: GSuite mitre_attack_id: - T1566.001 - - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml b/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml index cc41adee08..6d4f09108b 100644 --- a/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml +++ b/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml @@ -1,7 +1,7 @@ name: Gsuite Email With Known Abuse Web Service Link id: 8630aa22-042b-11ec-af39-acde48001122 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: asset_type: GSuite mitre_attack_id: - T1566.001 - - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml b/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml index e154a605f3..196839b387 100644 --- a/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml +++ b/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml @@ -1,7 +1,7 @@ name: Gsuite Outbound Email With Attachment To External Domain id: dc4dc3a8-ff54-11eb-8bf7-acde48001122 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Stanislav Miskovic, Splunk status: production type: Hunting @@ -37,7 +37,6 @@ tags: asset_type: GSuite mitre_attack_id: - T1048.003 - - T1048 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gsuite_suspicious_shared_file_name.yml b/detections/cloud/gsuite_suspicious_shared_file_name.yml index 311f449b7f..a660e05c8c 100644 --- a/detections/cloud/gsuite_suspicious_shared_file_name.yml +++ b/detections/cloud/gsuite_suspicious_shared_file_name.yml @@ -1,7 +1,7 @@ name: Gsuite Suspicious Shared File Name id: 07eed200-03f5-11ec-98fb-acde48001122 -version: 4 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -65,7 +65,6 @@ tags: asset_type: GSuite mitre_attack_id: - T1566.001 - - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/high_number_of_login_failures_from_a_single_source.yml b/detections/cloud/high_number_of_login_failures_from_a_single_source.yml index a42e10bb7f..7f6fe588f5 100644 --- a/detections/cloud/high_number_of_login_failures_from_a_single_source.yml +++ b/detections/cloud/high_number_of_login_failures_from_a_single_source.yml @@ -1,7 +1,7 @@ name: High Number of Login Failures from a single source id: 7f398cfb-918d-41f4-8db8-2e2474e02222 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Mauricio Velazco, Splunk status: production type: Anomaly @@ -60,7 +60,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1110.001 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_add_app_role_assignment_grant_user.yml b/detections/cloud/o365_add_app_role_assignment_grant_user.yml index 40dbc0137d..4137c89c71 100644 --- a/detections/cloud/o365_add_app_role_assignment_grant_user.yml +++ b/detections/cloud/o365_add_app_role_assignment_grant_user.yml @@ -1,7 +1,7 @@ name: O365 Add App Role Assignment Grant User id: b2c81cc6-6040-11eb-ae93-0242ac130002 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Rod Soto, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1136.003 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_added_service_principal.yml b/detections/cloud/o365_added_service_principal.yml index 239d6317b9..ead8633c06 100644 --- a/detections/cloud/o365_added_service_principal.yml +++ b/detections/cloud/o365_added_service_principal.yml @@ -1,7 +1,7 @@ name: O365 Added Service Principal id: 1668812a-6047-11eb-ae93-0242ac130002 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Rod Soto, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1136.003 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_advanced_audit_disabled.yml b/detections/cloud/o365_advanced_audit_disabled.yml index fde6c3a0f8..ac2211f458 100644 --- a/detections/cloud/o365_advanced_audit_disabled.yml +++ b/detections/cloud/o365_advanced_audit_disabled.yml @@ -1,7 +1,7 @@ name: O365 Advanced Audit Disabled id: 49862dd4-9cb2-4c48-a542-8c8a588d9361 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Michael Haag, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Office 365 Persistence Mechanisms asset_type: O365 Tenant mitre_attack_id: - - T1562 - T1562.008 product: - Splunk Enterprise diff --git a/detections/cloud/o365_application_available_to_other_tenants.yml b/detections/cloud/o365_application_available_to_other_tenants.yml index 0ecc7bab04..1f1a06b147 100644 --- a/detections/cloud/o365_application_available_to_other_tenants.yml +++ b/detections/cloud/o365_application_available_to_other_tenants.yml @@ -1,7 +1,7 @@ name: O365 Application Available To Other Tenants id: 942548a3-0273-47a4-8dbd-e5202437395c -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1098.003 - - T1098 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_applicationimpersonation_role_assigned.yml b/detections/cloud/o365_applicationimpersonation_role_assigned.yml index 777f8755aa..ece9018152 100644 --- a/detections/cloud/o365_applicationimpersonation_role_assigned.yml +++ b/detections/cloud/o365_applicationimpersonation_role_assigned.yml @@ -1,7 +1,7 @@ name: O365 ApplicationImpersonation Role Assigned id: 49cdce75-f814-4d56-a7a4-c64ec3a481f2 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - NOBELIUM Group asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.002 product: - Splunk Enterprise diff --git a/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml b/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml index 6ad687a266..e0b6f6f7fc 100644 --- a/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml +++ b/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml @@ -1,7 +1,7 @@ name: O365 Bypass MFA via Trusted IP id: c783dd98-c703-4252-9e8a-f19d9f66949e -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Bhavin Patel, Mauricio Velazco, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1562.007 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_compliance_content_search_exported.yml b/detections/cloud/o365_compliance_content_search_exported.yml index 74ff0f6355..56cbf61d9c 100644 --- a/detections/cloud/o365_compliance_content_search_exported.yml +++ b/detections/cloud/o365_compliance_content_search_exported.yml @@ -1,7 +1,7 @@ name: O365 Compliance Content Search Exported id: 2ce9f31d-ab4f-4179-b2b7-c77a9652e1d8 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: [] type: TTP @@ -53,7 +53,6 @@ tags: - Office 365 Collection Techniques asset_type: O365 Tenant mitre_attack_id: - - T1114 - T1114.002 product: - Splunk Enterprise diff --git a/detections/cloud/o365_compliance_content_search_started.yml b/detections/cloud/o365_compliance_content_search_started.yml index 2b4440c1d1..554aaf4c15 100644 --- a/detections/cloud/o365_compliance_content_search_started.yml +++ b/detections/cloud/o365_compliance_content_search_started.yml @@ -1,7 +1,7 @@ name: O365 Compliance Content Search Started id: f4cabbc7-c19a-4e41-8be5-98daeaccbb50 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: [] type: TTP @@ -53,7 +53,6 @@ tags: - Office 365 Collection Techniques asset_type: O365 Tenant mitre_attack_id: - - T1114 - T1114.002 product: - Splunk Enterprise diff --git a/detections/cloud/o365_elevated_mailbox_permission_assigned.yml b/detections/cloud/o365_elevated_mailbox_permission_assigned.yml index 361a0b8cf7..3b9ff5e1f8 100644 --- a/detections/cloud/o365_elevated_mailbox_permission_assigned.yml +++ b/detections/cloud/o365_elevated_mailbox_permission_assigned.yml @@ -1,7 +1,7 @@ name: O365 Elevated Mailbox Permission Assigned id: 2246c142-a678-45f8-8546-aaed7e0efd30 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Mauricio Velazco, Splunk data_source: [] type: TTP @@ -53,7 +53,6 @@ tags: - Office 365 Collection Techniques asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.002 product: - Splunk Enterprise diff --git a/detections/cloud/o365_email_access_by_security_administrator.yml b/detections/cloud/o365_email_access_by_security_administrator.yml index 99d7b99204..df598e1fa9 100644 --- a/detections/cloud/o365_email_access_by_security_administrator.yml +++ b/detections/cloud/o365_email_access_by_security_administrator.yml @@ -1,7 +1,7 @@ name: O365 Email Access By Security Administrator id: c6998a30-fef4-4e89-97ac-3bb0123719b4 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -54,9 +54,8 @@ tags: - Office 365 Account Takeover asset_type: O365 Tenant mitre_attack_id: - - T1567 - - T1114 - T1114.002 + - T1567 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_email_reported_by_admin_found_malicious.yml b/detections/cloud/o365_email_reported_by_admin_found_malicious.yml index 0a5d4aa0fa..405e008e80 100644 --- a/detections/cloud/o365_email_reported_by_admin_found_malicious.yml +++ b/detections/cloud/o365_email_reported_by_admin_found_malicious.yml @@ -1,7 +1,7 @@ name: O365 Email Reported By Admin Found Malicious id: 94396c3e-7728-422a-9956-e4b77b53dbdf -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -57,7 +57,6 @@ tags: - Suspicious Emails asset_type: O365 Tenant mitre_attack_id: - - T1566 - T1566.001 - T1566.002 product: diff --git a/detections/cloud/o365_email_reported_by_user_found_malicious.yml b/detections/cloud/o365_email_reported_by_user_found_malicious.yml index edbf3a10b7..685ecb2198 100644 --- a/detections/cloud/o365_email_reported_by_user_found_malicious.yml +++ b/detections/cloud/o365_email_reported_by_user_found_malicious.yml @@ -1,7 +1,7 @@ name: O365 Email Reported By User Found Malicious id: 7698b945-238e-4bb9-b172-81f5ca1685a1 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -59,7 +59,6 @@ tags: - Suspicious Emails asset_type: O365 Tenant mitre_attack_id: - - T1566 - T1566.001 - T1566.002 product: diff --git a/detections/cloud/o365_email_security_feature_changed.yml b/detections/cloud/o365_email_security_feature_changed.yml index 9afe560662..983ce4e11a 100644 --- a/detections/cloud/o365_email_security_feature_changed.yml +++ b/detections/cloud/o365_email_security_feature_changed.yml @@ -1,7 +1,7 @@ name: O365 Email Security Feature Changed id: 4d28013d-3a0f-4d65-a33f-4e8009fee0ae -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -51,9 +51,8 @@ tags: - Office 365 Account Takeover asset_type: O365 Tenant mitre_attack_id: - - T1562 - - T1562.008 - T1562.001 + - T1562.008 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_email_suspicious_behavior_alert.yml b/detections/cloud/o365_email_suspicious_behavior_alert.yml index f6770028e1..5714addcec 100644 --- a/detections/cloud/o365_email_suspicious_behavior_alert.yml +++ b/detections/cloud/o365_email_suspicious_behavior_alert.yml @@ -1,7 +1,7 @@ name: O365 Email Suspicious Behavior Alert id: 85c7555a-05af-4322-81aa-76b4ddf52baa -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -54,7 +54,6 @@ tags: - Office 365 Account Takeover asset_type: O365 Tenant mitre_attack_id: - - T1114 - T1114.003 product: - Splunk Enterprise diff --git a/detections/cloud/o365_email_transport_rule_changed.yml b/detections/cloud/o365_email_transport_rule_changed.yml new file mode 100644 index 0000000000..bd7a4f1ee2 --- /dev/null +++ b/detections/cloud/o365_email_transport_rule_changed.yml @@ -0,0 +1,67 @@ +name: O365 Email Transport Rule Changed +id: 11ebb7c2-46bd-41c9-81e1-d0b4b34583a2 +version: 1 +date: '2025-01-15' +author: Steven Dick +status: production +type: Anomaly +description: The following analytic identifies when a user with sufficient access to Exchange Online alters the mail flow/transport rule configuration of the organization. Transport rules are a set of rules that can be used by attackers to modify or delete emails based on specific conditions, this activity could indicate an attacker hiding or exfiltrated data. +data_source: +- Office 365 Universal Audit Log +search: |- + `o365_management_activity` Workload=Exchange AND Operation IN ("Set-*","Disable-*","New-*","Remove-*") AND Operation="*TransportRule" + | eval object_name = case('Parameters{}.Name'=="Name",mvindex('Parameters{}.Value',mvfind('Parameters{}.Name',"^Name$")),true(),ObjectId), object_id = case('Parameters{}.Name'=="Identity",mvindex('Parameters{}.Value',mvfind('Parameters{}.Name',"^Identity$")),true(),Id) + | stats values(object_name) as object_name, min(_time) as firstTime, max(_time) as lastTime, count by object_id, UserId, Operation + | rename UserId as user, Operation as signature + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `o365_email_transport_rule_changed_filter` +how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest Office 365 management activity events. +known_false_positives: Legitimate administrative changes for business needs. +references: +- https://attack.mitre.org/techniques/T1114/003/ +- https://cardinalops.com/blog/cardinalops-contributes-new-mitre-attck-techniques-related-to-abuse-of-mail-transport-rules/ +- https://www.microsoft.com/en-us/security/blog/2022/09/22/malicious-OAuth-applications-used-to-compromise-email-servers-and-spread-spam/ +drilldown_searches: +- name: View the detection results for - "$user$" + search: '%original_detection_search% | search user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: Investigate changes by $user$ + search: '`o365_management_activity` Workload=Exchange AND Operation IN ("Set-*","Disable-*","New-*","Remove-*") AND Operation="*Transport*" UserId=$user$' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The user [$user$] altered the exchange transport rule id [$object_name$] + risk_objects: + - field: user + type: user + score: 25 + threat_objects: + - field: object_id + type: signature + - field: object_name + type: signature +tags: + analytic_story: + - Data Exfiltration + - Office 365 Account Takeover + asset_type: O365 Tenant + mitre_attack_id: + - T1114.003 + - T1564.008 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: threat +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114.003/transport_rule_change/transport_rule_change.log + source: o365 + sourcetype: o365:management:activity diff --git a/detections/cloud/o365_high_number_of_failed_authentications_for_user.yml b/detections/cloud/o365_high_number_of_failed_authentications_for_user.yml index 41d867d860..259430989e 100644 --- a/detections/cloud/o365_high_number_of_failed_authentications_for_user.yml +++ b/detections/cloud/o365_high_number_of_failed_authentications_for_user.yml @@ -1,7 +1,7 @@ name: O365 High Number Of Failed Authentications for User id: 31641378-2fa9-42b1-948e-25e281cb98f7 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -54,7 +54,6 @@ tags: - Office 365 Account Takeover asset_type: O365 Tenant mitre_attack_id: - - T1110 - T1110.001 product: - Splunk Enterprise diff --git a/detections/cloud/o365_high_privilege_role_granted.yml b/detections/cloud/o365_high_privilege_role_granted.yml index bbe4d281d2..57d53359d0 100644 --- a/detections/cloud/o365_high_privilege_role_granted.yml +++ b/detections/cloud/o365_high_privilege_role_granted.yml @@ -1,7 +1,7 @@ name: O365 High Privilege Role Granted id: e78a1037-4548-4072-bb1b-ad99ae416426 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: - Office 365 Persistence Mechanisms asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/o365_mailbox_email_forwarding_enabled.yml b/detections/cloud/o365_mailbox_email_forwarding_enabled.yml index 28c3e91e3f..d4f69f2bd4 100644 --- a/detections/cloud/o365_mailbox_email_forwarding_enabled.yml +++ b/detections/cloud/o365_mailbox_email_forwarding_enabled.yml @@ -1,7 +1,7 @@ name: O365 Mailbox Email Forwarding Enabled id: 0b6bc75c-05d1-4101-9fc3-97e706168f24 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Mauricio Velazco, Splunk data_source: [] type: TTP @@ -54,7 +54,6 @@ tags: - Office 365 Collection Techniques asset_type: O365 Tenant mitre_attack_id: - - T1114 - T1114.003 product: - Splunk Enterprise diff --git a/detections/cloud/o365_mailbox_folder_read_permission_assigned.yml b/detections/cloud/o365_mailbox_folder_read_permission_assigned.yml index e3f85487ae..867df0355e 100644 --- a/detections/cloud/o365_mailbox_folder_read_permission_assigned.yml +++ b/detections/cloud/o365_mailbox_folder_read_permission_assigned.yml @@ -1,7 +1,7 @@ name: O365 Mailbox Folder Read Permission Assigned id: 1435475e-2128-4417-a34f-59770733b0d5 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: [] type: TTP @@ -55,7 +55,6 @@ tags: - Office 365 Collection Techniques asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.002 product: - Splunk Enterprise diff --git a/detections/cloud/o365_mailbox_folder_read_permission_granted.yml b/detections/cloud/o365_mailbox_folder_read_permission_granted.yml index 6b0939ee72..b6ad3e3269 100644 --- a/detections/cloud/o365_mailbox_folder_read_permission_granted.yml +++ b/detections/cloud/o365_mailbox_folder_read_permission_granted.yml @@ -1,7 +1,7 @@ name: O365 Mailbox Folder Read Permission Granted id: cd15c0a8-470e-4b12-9517-046e4927db30 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: [] type: TTP @@ -54,7 +54,6 @@ tags: - Office 365 Collection Techniques asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.002 product: - Splunk Enterprise diff --git a/detections/cloud/o365_mailbox_inbox_folder_shared_with_all_users.yml b/detections/cloud/o365_mailbox_inbox_folder_shared_with_all_users.yml index 253de4acee..079ba2b14a 100644 --- a/detections/cloud/o365_mailbox_inbox_folder_shared_with_all_users.yml +++ b/detections/cloud/o365_mailbox_inbox_folder_shared_with_all_users.yml @@ -1,7 +1,7 @@ name: O365 Mailbox Inbox Folder Shared with All Users id: 21421896-a692-4594-9888-5faeb8a53106 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: - Office 365 Persistence Mechanisms asset_type: O365 Tenant mitre_attack_id: - - T1114 - T1114.002 product: - Splunk Enterprise diff --git a/detections/cloud/o365_mailbox_read_access_granted_to_application.yml b/detections/cloud/o365_mailbox_read_access_granted_to_application.yml index 73b115897f..ea65305c88 100644 --- a/detections/cloud/o365_mailbox_read_access_granted_to_application.yml +++ b/detections/cloud/o365_mailbox_read_access_granted_to_application.yml @@ -1,7 +1,7 @@ name: O365 Mailbox Read Access Granted to Application id: 27ab61c5-f08a-438a-b4d3-325e666490b3 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -59,10 +59,8 @@ tags: - Office 365 Persistence Mechanisms asset_type: O365 Tenant mitre_attack_id: - - T1114.002 - - T1114 - - T1098 - T1098.003 + - T1114.002 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_multi_source_failed_authentications_spike.yml b/detections/cloud/o365_multi_source_failed_authentications_spike.yml index 3c21195c01..275cba424d 100644 --- a/detections/cloud/o365_multi_source_failed_authentications_spike.yml +++ b/detections/cloud/o365_multi_source_failed_authentications_spike.yml @@ -1,7 +1,7 @@ name: O365 Multi-Source Failed Authentications Spike id: ea4e2c41-dbfb-4f5f-a7b6-9ac1b7f104aa -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -45,11 +45,9 @@ tags: asset_type: O365 Tenant atomic_guid: [] mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.003 - T1110.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_multiple_os_vendors_authenticating_from_user.yml b/detections/cloud/o365_multiple_os_vendors_authenticating_from_user.yml new file mode 100644 index 0000000000..743aca09e9 --- /dev/null +++ b/detections/cloud/o365_multiple_os_vendors_authenticating_from_user.yml @@ -0,0 +1,66 @@ +name: O365 Multiple OS Vendors Authenticating From User +id: 3451e58a-9457-4985-a600-b616b0cbfda1 +version: 1 +date: '2024-12-19' +author: Steven Dick +status: production +type: TTP +description: The following analytic identifies when multiple operating systems are used to authenticate to Azure/EntraID/Office 365 by the same user account over a short period of time. This activity could be indicative of attackers enumerating various logon capabilities of Azure/EntraID/Office 365 and attempting to discover weaknesses in the organizational MFA or conditional access configurations. Usage of the tools like "MFASweep" will trigger this detection. +data_source: +- Office 365 Universal Audit Log +search: |- + `o365_management_activity` Operation IN (UserLoginFailed,UserLoggedIn) + | eval -time = _time + | bin _time span=15m + | stats values(Operation) as signature, values(ErrorNumber) as signature_id, values(OS) as os_name, dc(OS) as os_count, count, min(-time) as firstTime, max(-time) as lastTime by ClientIP, UserId, _time + | where os_count >= 4 + | eval src = ClientIP, user = UserId + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `o365_multiple_os_vendors_authenticating_from_user_filter` +how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest Office 365 management activity events. The thresholds set within the analytic (such as unique OS) are initial guidelines and should be customized based on the organization's user behavior and risk profile. Security teams are encouraged to adjust these thresholds to optimize the balance between detecting genuine threats and minimizing false positives, ensuring the detection is tailored to their specific environment. +known_false_positives: IP or users where the usage of multiple Operating systems is expected, filter accordingly. +references: +- https://attack.mitre.org/techniques/T1110 +- https://www.blackhillsinfosec.com/exploiting-mfa-inconsistencies-on-microsoft-services/ +- https://sra.io/blog/msspray-wait-how-many-endpoints-dont-have-mfa/ +- https://github.com/dafthack/MFASweep/tree/master +drilldown_searches: +- name: View the detection results for - "$user$" + search: '%original_detection_search% | search user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: Investigate logons from $user$ + search: '`o365_management_activity` Operation IN (UserLoginFailed,UserLoggedIn) "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The user account $user$ authenticated with $os_count$ unique operating system types over a short period from $src$. + risk_objects: + - field: user + type: user + score: 60 + threat_objects: + - field: src + type: ip_address +tags: + analytic_story: + - Office 365 Account Takeover + asset_type: O365 Tenant + mitre_attack_id: + - T1110 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: threat +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110/azure_mfasweep_events/azure_mfasweep_events.log + source: o365 + sourcetype: o365:management:activity diff --git a/detections/cloud/o365_multiple_users_failing_to_authenticate_from_ip.yml b/detections/cloud/o365_multiple_users_failing_to_authenticate_from_ip.yml index 24496ddc87..70df08df04 100644 --- a/detections/cloud/o365_multiple_users_failing_to_authenticate_from_ip.yml +++ b/detections/cloud/o365_multiple_users_failing_to_authenticate_from_ip.yml @@ -1,7 +1,7 @@ name: O365 Multiple Users Failing To Authenticate From Ip id: 8d486e2e-3235-4cfe-ac35-0d042e24ecb4 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -58,11 +58,9 @@ tags: - NOBELIUM Group asset_type: O365 Tenant mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.003 - T1110.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_new_email_forwarding_rule_created.yml b/detections/cloud/o365_new_email_forwarding_rule_created.yml index cee90dcbdc..2ec1c2eb73 100644 --- a/detections/cloud/o365_new_email_forwarding_rule_created.yml +++ b/detections/cloud/o365_new_email_forwarding_rule_created.yml @@ -1,7 +1,7 @@ name: O365 New Email Forwarding Rule Created id: 68469fd0-1315-44ba-b7e4-e92847bb76d6 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: [] type: TTP @@ -53,7 +53,6 @@ tags: - Office 365 Collection Techniques asset_type: O365 Tenant mitre_attack_id: - - T1114 - T1114.003 product: - Splunk Enterprise diff --git a/detections/cloud/o365_new_email_forwarding_rule_enabled.yml b/detections/cloud/o365_new_email_forwarding_rule_enabled.yml index dcc6b1b909..f6ca3b2785 100644 --- a/detections/cloud/o365_new_email_forwarding_rule_enabled.yml +++ b/detections/cloud/o365_new_email_forwarding_rule_enabled.yml @@ -1,7 +1,7 @@ name: O365 New Email Forwarding Rule Enabled id: ac7c4d0a-06a3-4278-aa59-88a5e537f981 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: [] type: TTP @@ -57,7 +57,6 @@ tags: - Office 365 Collection Techniques asset_type: O365 Tenant mitre_attack_id: - - T1114 - T1114.003 product: - Splunk Enterprise diff --git a/detections/cloud/o365_new_federated_domain_added.yml b/detections/cloud/o365_new_federated_domain_added.yml index 6dcebc1fbe..c2cd3a3f0e 100644 --- a/detections/cloud/o365_new_federated_domain_added.yml +++ b/detections/cloud/o365_new_federated_domain_added.yml @@ -1,7 +1,7 @@ name: O365 New Federated Domain Added id: e155876a-6048-11eb-ae93-0242ac130002 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Rod Soto, Mauricio Velazco Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1136.003 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_new_mfa_method_registered.yml b/detections/cloud/o365_new_mfa_method_registered.yml index f5278b8e52..25bcbb5336 100644 --- a/detections/cloud/o365_new_mfa_method_registered.yml +++ b/detections/cloud/o365_new_mfa_method_registered.yml @@ -1,7 +1,7 @@ name: O365 New MFA Method Registered id: 4e12db1f-f7c7-486d-8152-a221cad6ac2b -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Office 365 Persistence Mechanisms asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.005 product: - Splunk Enterprise diff --git a/detections/cloud/o365_privileged_role_assigned.yml b/detections/cloud/o365_privileged_role_assigned.yml index 975cdaa4a0..349eb0ce48 100644 --- a/detections/cloud/o365_privileged_role_assigned.yml +++ b/detections/cloud/o365_privileged_role_assigned.yml @@ -1,7 +1,7 @@ name: O365 Privileged Role Assigned id: db435700-4ddc-4c23-892e-49e7525d7d39 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -62,7 +62,6 @@ tags: - Azure Active Directory Persistence asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/o365_privileged_role_assigned_to_service_principal.yml b/detections/cloud/o365_privileged_role_assigned_to_service_principal.yml index f984d8f1de..cc56ca9835 100644 --- a/detections/cloud/o365_privileged_role_assigned_to_service_principal.yml +++ b/detections/cloud/o365_privileged_role_assigned_to_service_principal.yml @@ -1,7 +1,7 @@ name: O365 Privileged Role Assigned To Service Principal id: 80f3fc1b-705f-4080-bf08-f61bf013b900 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -66,7 +66,6 @@ tags: - Azure Active Directory Privilege Escalation asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/o365_safe_links_detection.yml b/detections/cloud/o365_safe_links_detection.yml index 1c85c2120c..48f5edc84e 100644 --- a/detections/cloud/o365_safe_links_detection.yml +++ b/detections/cloud/o365_safe_links_detection.yml @@ -1,7 +1,7 @@ name: O365 Safe Links Detection id: 711d9e8c-2cb0-45cf-8813-5f191ecb9b26 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -52,7 +52,6 @@ tags: - Spearphishing Attachments asset_type: O365 Tenant mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/cloud/o365_security_and_compliance_alert_triggered.yml b/detections/cloud/o365_security_and_compliance_alert_triggered.yml index f7a2340203..b479777630 100644 --- a/detections/cloud/o365_security_and_compliance_alert_triggered.yml +++ b/detections/cloud/o365_security_and_compliance_alert_triggered.yml @@ -1,7 +1,7 @@ name: O365 Security And Compliance Alert Triggered id: 5b367cdd-8dfc-49ac-a9b7-6406cf27f33e -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: [] type: TTP @@ -58,7 +58,6 @@ tags: - Office 365 Account Takeover asset_type: O365 Tenant mitre_attack_id: - - T1078 - T1078.004 product: - Splunk Enterprise diff --git a/detections/cloud/o365_service_principal_new_client_credentials.yml b/detections/cloud/o365_service_principal_new_client_credentials.yml index 702f8ee8f9..fbb1bcb8bd 100644 --- a/detections/cloud/o365_service_principal_new_client_credentials.yml +++ b/detections/cloud/o365_service_principal_new_client_credentials.yml @@ -1,7 +1,7 @@ name: O365 Service Principal New Client Credentials id: a1b229e9-d962-4222-8c62-905a8a010453 -version: 5 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - NOBELIUM Group asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.001 product: - Splunk Enterprise diff --git a/detections/cloud/o365_service_principal_privilege_escalation.yml b/detections/cloud/o365_service_principal_privilege_escalation.yml index ee93c75401..899a257bb4 100644 --- a/detections/cloud/o365_service_principal_privilege_escalation.yml +++ b/detections/cloud/o365_service_principal_privilege_escalation.yml @@ -1,23 +1,32 @@ name: O365 Service Principal Privilege Escalation id: b686d0bd-cca7-44ca-ae07-87f6465131d9 -version: 1 -date: '2025-01-06' +version: 2 +date: '2025-02-10' author: Dean Luxton data_source: - O365 Add app role assignment grant to user type: TTP status: production -description: This detection identifies when an Azure Service Principal elevates privileges by adding themself to a new app role assignment. -search: >- - `o365_management_activity` Operation="Add app role assignment to service principal." "Actor{}.ID"=ServicePrincipal ResultStatus=Success +description: This detection identifies when an Azure Service Principal elevates privileges + by adding themself to a new app role assignment. +search: >- + `o365_management_activity` Operation="Add app role assignment to service principal." + "Actor{}.ID"=ServicePrincipal ResultStatus=Success | spath path=ModifiedProperties{} output=targetResources - | stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value")))) as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName")))) as targetServicePrincipal values(object) as targetAppContext values(user_agent) as user_agent values(user) as servicePrincipal values(UserId) as servicePrincipalId by Operation InterSystemsId tenant_id + | stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value")))) + as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName")))) + as targetServicePrincipal values(object) as targetAppContext values(user_agent) + as user_agent values(user) as servicePrincipal values(UserId) as servicePrincipalId by + Operation InterSystemsId tenant_id | spath input=appRole path=NewValue output=appRole | spath input=targetServicePrincipal path=NewValue output=targetServicePrincipal | where servicePrincipal=targetServicePrincipal - | table _time Operation servicePrincipal servicePrincipalId appRole targetAppContext user_agent tenant_id InterSystemsId + | table _time Operation servicePrincipal servicePrincipalId appRole targetAppContext + user_agent tenant_id InterSystemsId | `o365_service_principal_privilege_escalation_filter` -how_to_implement: The Splunk Add-on for Microsoft Office 365 add-on is required to ingest EntraID audit logs via the 365 API. See references for links for further details on how to onboard this log source. +how_to_implement: The Splunk Add-on for Microsoft Office 365 add-on is required to + ingest EntraID audit logs via the 365 API. See references for links for further + details on how to onboard this log source. known_false_positives: Unknown references: - https://splunkbase.splunk.com/app/4055 @@ -30,11 +39,17 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$servicePrincipal$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$servicePrincipal$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$servicePrincipal$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: Service Principal $servicePrincipal$ has elevated privileges by adding themself to app role $appRole$ + message: Service Principal $servicePrincipal$ has elevated privileges by adding + themself to app role $appRole$ risk_objects: - field: servicePrincipal type: user @@ -49,7 +64,6 @@ tags: asset_type: Azure Tenant mitre_attack_id: - T1098.003 - - T1098 product: - Splunk Enterprise - Splunk Enterprise Security @@ -58,6 +72,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/o365_spn_privesc/o365_spn_privesc.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/o365_spn_privesc/o365_spn_privesc.log sourcetype: o365:management:activity source: Office 365 diff --git a/detections/cloud/o365_sharepoint_malware_detection.yml b/detections/cloud/o365_sharepoint_malware_detection.yml index a3136a5595..e3ec3d7abc 100644 --- a/detections/cloud/o365_sharepoint_malware_detection.yml +++ b/detections/cloud/o365_sharepoint_malware_detection.yml @@ -1,7 +1,7 @@ name: O365 SharePoint Malware Detection id: 583c5de3-7709-44cb-abfc-0e828d301b59 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -53,7 +53,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1204.002 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml b/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml new file mode 100644 index 0000000000..52449ed52b --- /dev/null +++ b/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml @@ -0,0 +1,67 @@ +name: O365 SharePoint Suspicious Search Behavior +id: 6ca919db-52f3-4c95-a4e9-7b189e8a043d +version: 1 +date: '2025-01-08' +author: Steven Dick +status: production +type: Anomaly +description: The following analytic identifies when the O365 SharePoint users search for suspicious keywords or have an excessive number of queries within a limited timeframe. This behavior may indicate malicious actor enumeration of SharePoint based data within O365. +data_source: +- Office 365 Universal Audit Log +search: |- + `o365_management_activity` Workload=SharePoint Operation="SearchQueryPerformed" SearchQueryText=* EventData=*search* + | where NOT (match(SearchQueryText, "\*") OR match(SearchQueryText,"(\*)")) + | eval signature_id = CorrelationId, signature=Operation, src = ClientIP, user = UserId, object_name=EventData, command = SearchQueryText, -time = _time + | bin _time span=1hr + | stats values(object_name) as object_name values(command) as command, values(src) as src, dc(command) as count, min(-time) as firstTime, max(-time) as lastTime by user,signature,_time + | where count > 20 OR match(command, "(?i)password|credential|passwd|shadow|active directory|account|username|network|computer|access|MFA|bank|deposit|payroll|EFT|Electonic Funds|routing") + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `o365_sharepoint_suspicious_search_behavior_filter` +how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest Office 365 management activity events. The thresholds and match terms set within the analytic are initial guidelines and should be customized based on the organization's user behavior and risk profile. Security teams are encouraged to adjust these thresholds to optimize the balance between detecting genuine threats and minimizing false positives, ensuring the detection is tailored to their specific environment. +known_false_positives: Users searching excessively or possible false positives related to matching conditions. +references: +- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a +- https://attack.mitre.org/techniques/T1213/002/ +drilldown_searches: +- name: View the detection results for - "$user$" + search: '%original_detection_search% | search user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: Investigate search behavior by $user$ + search: '`o365_management_activity` Workload=SharePoint Operation="SearchQueryPerformed" SearchQueryText=* EventData=*search* AND UserId = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The SharePoint Online was searched suspiciously by $user$ + risk_objects: + - field: user + type: user + score: 25 + threat_objects: + - field: src + type: ip_address +tags: + analytic_story: + - Azure Active Directory Persistence + - Office 365 Account Takeover + - CISA AA22-320A + asset_type: O365 Tenant + mitre_attack_id: + - T1213.002 + - T1552 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: threat +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1213.002/o365_sus_sharepoint_search/o365_sus_sharepoint_search.log + source: o365 + sourcetype: o365:management:activity diff --git a/detections/cloud/o365_tenant_wide_admin_consent_granted.yml b/detections/cloud/o365_tenant_wide_admin_consent_granted.yml index 5375087924..9d9a2e8780 100644 --- a/detections/cloud/o365_tenant_wide_admin_consent_granted.yml +++ b/detections/cloud/o365_tenant_wide_admin_consent_granted.yml @@ -1,7 +1,7 @@ name: O365 Tenant Wide Admin Consent Granted id: 50eaabf8-5180-4e86-bfb2-011472c359fc -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - NOBELIUM Group asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/o365_threat_intelligence_suspicious_email_delivered.yml b/detections/cloud/o365_threat_intelligence_suspicious_email_delivered.yml index b2142169f6..80ffe96469 100644 --- a/detections/cloud/o365_threat_intelligence_suspicious_email_delivered.yml +++ b/detections/cloud/o365_threat_intelligence_suspicious_email_delivered.yml @@ -1,7 +1,7 @@ name: O365 Threat Intelligence Suspicious Email Delivered id: 605cc93a-70e4-4ee3-9a3d-1a62e8c9b6c2 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: Anomaly @@ -63,7 +63,6 @@ tags: - Suspicious Emails asset_type: O365 Tenant mitre_attack_id: - - T1566 - T1566.001 - T1566.002 product: diff --git a/detections/cloud/o365_threat_intelligence_suspicious_file_detected.yml b/detections/cloud/o365_threat_intelligence_suspicious_file_detected.yml index d7fcb9eb0a..f6313dcc2c 100644 --- a/detections/cloud/o365_threat_intelligence_suspicious_file_detected.yml +++ b/detections/cloud/o365_threat_intelligence_suspicious_file_detected.yml @@ -1,7 +1,7 @@ name: O365 Threat Intelligence Suspicious File Detected id: 00958c7b-35db-4e7a-ad13-31550a7a7c64 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -58,7 +58,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1204.002 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_zap_activity_detection.yml b/detections/cloud/o365_zap_activity_detection.yml index b16c86afb1..daab34fb89 100644 --- a/detections/cloud/o365_zap_activity_detection.yml +++ b/detections/cloud/o365_zap_activity_detection.yml @@ -1,7 +1,7 @@ name: O365 ZAP Activity Detection id: 4df275fd-a0e5-4246-8b92-d3201edaef7a -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: Anomaly @@ -58,7 +58,6 @@ tags: - Suspicious Emails asset_type: O365 Tenant mitre_attack_id: - - T1566 - T1566.001 - T1566.002 product: diff --git a/detections/cloud/risk_rule_for_dev_sec_ops_by_repository.yml b/detections/cloud/risk_rule_for_dev_sec_ops_by_repository.yml index f1555d3ff6..145748eea0 100644 --- a/detections/cloud/risk_rule_for_dev_sec_ops_by_repository.yml +++ b/detections/cloud/risk_rule_for_dev_sec_ops_by_repository.yml @@ -1,7 +1,7 @@ name: Risk Rule for Dev Sec Ops by Repository id: 161bc0ca-4651-4c13-9c27-27770660cf67 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel status: production type: Correlation @@ -47,7 +47,6 @@ tags: asset_type: Amazon Elastic Container Registry mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/account_discovery_with_net_app.yml b/detections/deprecated/account_discovery_with_net_app.yml index bf2568a3f0..074b4fba7a 100644 --- a/detections/deprecated/account_discovery_with_net_app.yml +++ b/detections/deprecated/account_discovery_with_net_app.yml @@ -1,7 +1,7 @@ name: Account Discovery With Net App id: 339805ce-ac30-11eb-b87d-acde48001122 -version: 8 -date: '2025-01-13' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, TheLawsOfChaos, Github Community status: deprecated type: TTP @@ -72,7 +72,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/attempt_to_stop_security_service.yml b/detections/deprecated/attempt_to_stop_security_service.yml index 09f69ad572..1964d9b110 100644 --- a/detections/deprecated/attempt_to_stop_security_service.yml +++ b/detections/deprecated/attempt_to_stop_security_service.yml @@ -1,7 +1,7 @@ name: Attempt To Stop Security Service id: c8e349c6-b97c-486e-8949-bd7bcd1f3910 -version: 9 -date: '2025-01-24' +version: 11 +date: '2025-02-10' author: Rico Valdez, Splunk status: deprecated type: TTP @@ -80,7 +80,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml index 38fdbf95b5..65c188a991 100644 --- a/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml @@ -1,7 +1,7 @@ name: Attempted Credential Dump From Registry via Reg exe id: e9fb4a59-c5fb-440a-9f24-191fbc6b2911 -version: 12 -date: '2025-01-15' +version: 14 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: deprecated type: TTP @@ -80,7 +80,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.002 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml index d59e586b5a..91a576d2f0 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml @@ -15,8 +15,8 @@ search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceI sourceIPAddress | search City=* | stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country | inputlookup append=t previously_seen_provisioning_activity_src | stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress, - City, Region, Country | outputlookup previously_seen_provisioning_activity_src | - stats min(firstTime) as firstTime max(lastTime) as lastTime by City | eval newCity=if(firstTime + City, Region, Country | outputlookup previously_seen_provisioning_activity_src + | stats min(firstTime) as firstTime max(lastTime) as lastTime by City | eval newCity=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) | where newCity=1 | table City] | spath output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time, user, src_ip, City, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_city_filter`' diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml index 05ecc67be0..986a31d1f0 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml @@ -14,13 +14,13 @@ search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceI | search Country=* [search `cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceIPAddress | search Country=* | stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country | inputlookup - append=t previously_seen_provisioning_activity_src | stats min(firstTime) as firstTime - max(lastTime) as lastTime by sourceIPAddress, City, Region, Country | outputlookup - previously_seen_provisioning_activity_src | stats min(firstTime) as firstTime max(lastTime) - as lastTime by Country | eval newCountry=if(firstTime >= relative_time(now(), "-70m@m"), - 1, 0) | where newCountry=1 | table Country] | spath output=user userIdentity.arn - | rename sourceIPAddress as src_ip | table _time, user, src_ip, Country, eventName, - errorCode | `aws_cloud_provisioning_from_previously_unseen_country_filter`' + append=t previously_seen_provisioning_activity_src | stats min(firstTime) as + firstTime max(lastTime) as lastTime by sourceIPAddress, City, Region, Country | + outputlookup previously_seen_provisioning_activity_src | stats min(firstTime) + as firstTime max(lastTime) as lastTime by Country | eval newCountry=if(firstTime + >= relative_time(now(), "-70m@m"), 1, 0) | where newCountry=1 | table Country] | + spath output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time, + user, src_ip, Country, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_country_filter`' how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. This search works best when you run the "Previously Seen AWS Provisioning diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml index 7adba589db..5efa68a449 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml @@ -15,8 +15,8 @@ search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceI sourceIPAddress | search Region=* | stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country | inputlookup append=t previously_seen_provisioning_activity_src | stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress, - City, Region, Country | outputlookup previously_seen_provisioning_activity_src | - stats min(firstTime) as firstTime max(lastTime) as lastTime by Region | eval newRegion=if(firstTime + City, Region, Country | outputlookup previously_seen_provisioning_activity_src + | stats min(firstTime) as firstTime max(lastTime) as lastTime by Region | eval newRegion=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) | where newRegion=1 | table Region] | spath output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time, user, src_ip, Region, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_region_filter`' diff --git a/detections/deprecated/change_default_file_association.yml b/detections/deprecated/change_default_file_association.yml index b524230015..e5e583848a 100644 --- a/detections/deprecated/change_default_file_association.yml +++ b/detections/deprecated/change_default_file_association.yml @@ -1,7 +1,7 @@ name: Change Default File Association id: 462d17d8-1f71-11ec-ad07-acde48001122 -version: 5 -date: '2025-01-24' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: deprecated type: TTP @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.001 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml b/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml index 1df440f488..74087020ed 100644 --- a/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml +++ b/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml @@ -1,7 +1,7 @@ name: Cmdline Tool Not Executed In CMD Shell id: 6c3f7dd8-153c-11ec-ac2d-acde48001122 -version: 7 -date: '2025-01-24' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: deprecated type: TTP @@ -86,7 +86,6 @@ tags: - Gozi Malware asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.007 product: - Splunk Enterprise diff --git a/detections/deprecated/correlation_by_repository_and_risk.yml b/detections/deprecated/correlation_by_repository_and_risk.yml index 2629b408ff..681f046bf4 100644 --- a/detections/deprecated/correlation_by_repository_and_risk.yml +++ b/detections/deprecated/correlation_by_repository_and_risk.yml @@ -1,7 +1,7 @@ name: Correlation by Repository and Risk id: 8da9fdd9-6a1b-4ae0-8a34-8c25e6be9687 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: deprecated type: Correlation @@ -20,7 +20,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/correlation_by_user_and_risk.yml b/detections/deprecated/correlation_by_user_and_risk.yml index 63d9c738ae..d121453be9 100644 --- a/detections/deprecated/correlation_by_user_and_risk.yml +++ b/detections/deprecated/correlation_by_user_and_risk.yml @@ -1,7 +1,7 @@ name: Correlation by User and Risk id: 610e12dc-b6fa-4541-825e-4a0b3b6f6773 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: deprecated type: Correlation @@ -20,7 +20,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/create_local_admin_accounts_using_net_exe.yml b/detections/deprecated/create_local_admin_accounts_using_net_exe.yml index cf89f5b1ac..05bd612ba3 100644 --- a/detections/deprecated/create_local_admin_accounts_using_net_exe.yml +++ b/detections/deprecated/create_local_admin_accounts_using_net_exe.yml @@ -1,7 +1,7 @@ name: Create local admin accounts using net exe id: b89919ed-fe5f-492c-b139-151bb162040e -version: 15 -date: '2025-01-24' +version: 17 +date: '2025-02-10' author: Bhavin Patel, Splunk status: deprecated type: TTP @@ -78,7 +78,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1136.001 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/deleting_of_net_users.yml b/detections/deprecated/deleting_of_net_users.yml index cb8dc58817..379264584f 100644 --- a/detections/deprecated/deleting_of_net_users.yml +++ b/detections/deprecated/deleting_of_net_users.yml @@ -1,18 +1,18 @@ name: Deleting Of Net Users id: 1c8c6f66-acce-11eb-aafb-acde48001122 -version: 7 +version: 8 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated type: TTP -description: The following analytic has been deprecated. The following analytic detects - the use of net.exe or net1.exe command-line to delete a user account on a system. - It leverages data from Endpoint Detection and Response (EDR) agents, focusing on - process and command-line execution logs. This activity is significant as it may - indicate an attempt to impair user accounts or cover tracks during lateral movement. - If confirmed malicious, this could lead to unauthorized access removal, disruption - of legitimate user activities, or concealment of adversarial actions, complicating - incident response and forensic investigations. +description: The following analytic has been deprecated. + The following analytic detects the use of net.exe or net1.exe command-line + to delete a user account on a system. It leverages data from Endpoint Detection + and Response (EDR) agents, focusing on process and command-line execution logs. + This activity is significant as it may indicate an attempt to impair user accounts + or cover tracks during lateral movement. If confirmed malicious, this could lead + to unauthorized access removal, disruption of legitimate user activities, or concealment + of adversarial actions, complicating incident response and forensic investigations. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml b/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml index 0c13a55b87..9b6c9aec2c 100644 --- a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml +++ b/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml @@ -1,7 +1,7 @@ name: Detect Activity Related to Pass the Hash Attacks id: f5939373-8054-40ad-8c64-cec478a22a4b -version: 9 -date: '2024-11-14' +version: 10 +date: '2025-02-10' author: Bhavin Patel, Patrick Bareiss, Splunk status: deprecated type: Hunting @@ -29,7 +29,6 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1550 - T1550.002 product: - Splunk Enterprise diff --git a/detections/deprecated/detect_critical_alerts_from_security_tools.yml b/detections/deprecated/detect_critical_alerts_from_security_tools.yml index 75848f931f..79ba56809d 100644 --- a/detections/deprecated/detect_critical_alerts_from_security_tools.yml +++ b/detections/deprecated/detect_critical_alerts_from_security_tools.yml @@ -8,40 +8,10 @@ type: TTP data_source: - Windows Defender Alerts - MS365 Defender Incident Alerts -description: The following analytic has been deprecated in favour of specific and - dedicated product analytics such as "Microsoft Defender ATP Alerts". The following - analytic is to detect high and critical alerts from endpoint security tools such - as Microsoft Defender, Carbon Black, and Crowdstrike. This query aggregates and - summarizes critical severity alerts from the Alerts data model, providing details - such as the alert signature, application, description, source, destination, and - timestamps, while applying custom filters and formatting for enhanced analysis in - a SIEM environment.This capability allows security teams to efficiently allocate - resources and maintain a strong security posture, while also supporting compliance - with regulatory requirements by providing a clear record of critical security events. - We tested these detections with logs from Microsoft Defender, however this detection - should work for any security alerts that are ingested into the alerts data model. - **Note** - We are dynamically creating the risk_score field based on the severity - of the alert in the SPL and that supersedes the risk score set in the detection. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime values(Alerts.description) as description values(Alerts.mitre_technique_id) - as annotations.mitre_attack.mitre_technique_id values(Alerts.severity) as severity - values(Alerts.type) as type values(Alerts.severity_id) as severity_id values(Alerts.signature) - as signature values(Alerts.signature_id) as signature_id values(Alerts.dest) as - dest from datamodel=Alerts where Alerts.severity IN ("high","critical") by Alerts.src - Alerts.user Alerts.id Alerts.vendor sourcetype | `drop_dm_object_name("Alerts")` - | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | eval - risk_score=case(severity="informational", 2, severity="low", 5, severity="medium", - 10, severity="high", 50, severity="critical" , 100) | `detect_critical_alerts_from_security_tools_filter`' -how_to_implement: In order to properly run this search, you to ingest alerts data - from other security products such as Crowdstrike, Microsoft Defender, or Carbon - Black using appropriate TAs for that technology. Once ingested, the fields should - be mapped to the Alerts data model. Make sure to apply transformation on the data - if necessary. The risk_score field is used to calculate the risk score for the alerts - and the mitre_technique_id field is used to map the alerts to the MITRE ATT&CK framework - is dynamically created by the detection when this is triggered. These fields need - not be set in the adaptive response actions. -known_false_positives: False positives may vary by endpoint protection tool; monitor - and filter out the alerts that are not relevant to your environment. +description: The following analytic has been deprecated in favour of specific and dedicated product analytics such as "Microsoft Defender ATP Alerts". The following analytic is to detect high and critical alerts from endpoint security tools such as Microsoft Defender, Carbon Black, and Crowdstrike. This query aggregates and summarizes critical severity alerts from the Alerts data model, providing details such as the alert signature, application, description, source, destination, and timestamps, while applying custom filters and formatting for enhanced analysis in a SIEM environment.This capability allows security teams to efficiently allocate resources and maintain a strong security posture, while also supporting compliance with regulatory requirements by providing a clear record of critical security events. We tested these detections with logs from Microsoft Defender, however this detection should work for any security alerts that are ingested into the alerts data model. **Note** - We are dynamically creating the risk_score field based on the severity of the alert in the SPL and that supersedes the risk score set in the detection. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Alerts.description) as description values(Alerts.mitre_technique_id) as annotations.mitre_attack.mitre_technique_id values(Alerts.severity) as severity values(Alerts.type) as type values(Alerts.severity_id) as severity_id values(Alerts.signature) as signature values(Alerts.signature_id) as signature_id values(Alerts.dest) as dest from datamodel=Alerts where Alerts.severity IN ("high","critical") by Alerts.src Alerts.user Alerts.id Alerts.vendor sourcetype | `drop_dm_object_name("Alerts")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | eval risk_score=case(severity="informational", 2, severity="low", 5, severity="medium", 10, severity="high", 50, severity="critical" , 100) | `detect_critical_alerts_from_security_tools_filter`' +how_to_implement: In order to properly run this search, you to ingest alerts data from other security products such as Crowdstrike, Microsoft Defender, or Carbon Black using appropriate TAs for that technology. Once ingested, the fields should be mapped to the Alerts data model. Make sure to apply transformation on the data if necessary. The risk_score field is used to calculate the risk score for the alerts and the mitre_technique_id field is used to map the alerts to the MITRE ATT&CK framework is dynamically created by the detection when this is triggered. These fields need not be set in the adaptive response actions. +known_false_positives: False positives may vary by endpoint protection tool; monitor and filter out the alerts that are not relevant to your environment. references: - https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/accessing-microsoft-defender-for-cloud-alerts-in-splunk-using/ba-p/938228 - https://docs.splunk.com/Documentation/CIM/5.3.2/User/Alerts diff --git a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml index 67c72e7e14..2d4975f3ec 100644 --- a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml +++ b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml @@ -31,9 +31,9 @@ how_to_implement: "You need to ingest data from your DNS logs in the Network_Res add the correct hostname to the \"Phantom Instance\" field in the Adaptive Response Actions when configuring this detection search, and set the corresponding Playbook to active.\n(Playbook link:`https://my.phantom.us/4.2/playbook/lets-encrypt-domain-investigate/`)" -known_false_positives: If a known good domain is not listed in the `legit_domains` - lookup, then the search could give you false postives. Please update that lookup - file to filter out DNS requests to legitimate domains. +known_false_positives: If a known good domain is not listed in the `legit_domains` lookup, + then the search could give you false postives. Please update that lookup file + to filter out DNS requests to legitimate domains. references: [] rba: message: DNS Request for EvilGinx2 Phishing Site diff --git a/detections/deprecated/detect_mimikatz_using_loaded_images.yml b/detections/deprecated/detect_mimikatz_using_loaded_images.yml index b002ff2bcc..75e66c0061 100644 --- a/detections/deprecated/detect_mimikatz_using_loaded_images.yml +++ b/detections/deprecated/detect_mimikatz_using_loaded_images.yml @@ -1,7 +1,7 @@ name: Detect Mimikatz Using Loaded Images id: 29e307ba-40af-4ab2-91b2-3c6b392bbba0 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: deprecated type: TTP @@ -49,7 +49,6 @@ tags: asset_type: Windows mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_new_api_calls_from_user_roles.yml b/detections/deprecated/detect_new_api_calls_from_user_roles.yml index cc41aecff1..5ed0943c52 100644 --- a/detections/deprecated/detect_new_api_calls_from_user_roles.yml +++ b/detections/deprecated/detect_new_api_calls_from_user_roles.yml @@ -12,9 +12,9 @@ search: '`cloudtrail` eventType=AwsApiCall errorCode=success userIdentity.type=A [search `cloudtrail` eventType=AwsApiCall errorCode=success userIdentity.type=AssumedRole | stats earliest(_time) as earliest latest(_time) as latest by userName eventName | inputlookup append=t previously_seen_api_calls_from_user_roles | stats min(earliest) - as earliest, max(latest) as latest by userName eventName | outputlookup previously_seen_api_calls_from_user_roles - | eval newApiCallfromUserRole=if(earliest>=relative_time(now(), "-70m@m"), 1, 0) - | where newApiCallfromUserRole=1 | `security_content_ctime(earliest)` | `security_content_ctime(latest)` + as earliest, max(latest) as latest by userName eventName | outputlookup previously_seen_api_calls_from_user_roles | + eval newApiCallfromUserRole=if(earliest>=relative_time(now(), "-70m@m"), 1, 0) | + where newApiCallfromUserRole=1 | `security_content_ctime(earliest)` | `security_content_ctime(latest)` | table eventName userName] |rename userName as user| stats values(eventName) earliest(_time) as earliest latest(_time) as latest by user | `security_content_ctime(earliest)` | `security_content_ctime(latest)` | `detect_new_api_calls_from_user_roles_filter`' diff --git a/detections/deprecated/detect_new_user_aws_console_login.yml b/detections/deprecated/detect_new_user_aws_console_login.yml index 68c62a8d9c..1713d3b52d 100644 --- a/detections/deprecated/detect_new_user_aws_console_login.yml +++ b/detections/deprecated/detect_new_user_aws_console_login.yml @@ -13,9 +13,9 @@ description: This search looks for AWS CloudTrail events wherein a console login data_source: [] search: '`cloudtrail` eventName=ConsoleLogin | rename userIdentity.arn as user | stats earliest(_time) as firstTime latest(_time) as lastTime by user | inputlookup append=t - previously_seen_users_console_logins | stats min(firstTime) as firstTime max(lastTime) - as lastTime by user | eval userStatus=if(firstTime >= relative_time(now(), "-70m@m"), - "First Time Logging into AWS Console","Previously Seen User") | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`| + previously_seen_users_console_logins | stats min(firstTime) as firstTime + max(lastTime) as lastTime by user | eval userStatus=if(firstTime >= relative_time(now(), + "-70m@m"), "First Time Logging into AWS Console","Previously Seen User") | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`| where userStatus ="First Time Logging into AWS Console" | `detect_new_user_aws_console_login_filter`' how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail diff --git a/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml b/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml index 05f6ff2bd6..d0851935d2 100644 --- a/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml +++ b/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml @@ -1,19 +1,20 @@ name: Detect processes used for System Network Configuration Discovery id: a51bfe1a-94f0-48cc-b1e4-16ae10145893 -version: 7 +version: 8 date: '2025-01-24' author: Bhavin Patel, Splunk status: deprecated type: TTP -description: The following analytic has been deprecated. The following analytic identifies - the rapid execution of processes used for system network configuration discovery - on an endpoint. It leverages data from Endpoint Detection and Response (EDR) agents, - focusing on process GUIDs, names, parent processes, and command-line executions. - This activity is significant as it may indicate an attacker attempting to map the - network, which is a common precursor to lateral movement or further exploitation. - If confirmed malicious, this behavior could allow an attacker to gain insights into - the network topology, identify critical systems, and plan subsequent attacks, potentially - leading to data exfiltration or system compromise. +description: The following analytic has been deprecated. + The following analytic identifies the rapid execution of processes used + for system network configuration discovery on an endpoint. It leverages data from + Endpoint Detection and Response (EDR) agents, focusing on process GUIDs, names, + parent processes, and command-line executions. This activity is significant as it + may indicate an attacker attempting to map the network, which is a common precursor + to lateral movement or further exploitation. If confirmed malicious, this behavior + could allow an attacker to gain insights into the network topology, identify critical + systems, and plan subsequent attacks, potentially leading to data exfiltration or + system compromise. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/detect_webshell_exploit_behavior.yml b/detections/deprecated/detect_webshell_exploit_behavior.yml index 5f61b3c0c8..a460946a1a 100644 --- a/detections/deprecated/detect_webshell_exploit_behavior.yml +++ b/detections/deprecated/detect_webshell_exploit_behavior.yml @@ -1,7 +1,7 @@ name: Detect Webshell Exploit Behavior id: 22597426-6dbd-49bd-bcdc-4ec19857192f -version: 7 -date: '2025-01-24' +version: 8 +date: '2025-02-10' author: Steven Dick status: deprecated type: TTP @@ -87,7 +87,6 @@ tags: - BlackByte Ransomware asset_type: Endpoint mitre_attack_id: - - T1505 - T1505.003 product: - Splunk Enterprise diff --git a/detections/deprecated/disabling_net_user_account.yml b/detections/deprecated/disabling_net_user_account.yml index 615c9dea0b..409e89854a 100644 --- a/detections/deprecated/disabling_net_user_account.yml +++ b/detections/deprecated/disabling_net_user_account.yml @@ -1,18 +1,18 @@ name: Disabling Net User Account id: c0325326-acd6-11eb-98c2-acde48001122 -version: 7 +version: 8 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated type: TTP -description: The following analytic has been deprecated. The following analytic detects - the use of the `net.exe` utility to disable a user account via the command line. - It leverages data from Endpoint Detection and Response (EDR) agents, focusing on - process execution logs and command-line arguments. This activity is significant - as it may indicate an adversary's attempt to disrupt user availability, potentially - as a precursor to further malicious actions. If confirmed malicious, this could - lead to denial of service for legitimate users, aiding the attacker in maintaining - control or covering their tracks. +description: The following analytic has been deprecated. + The following analytic detects the use of the `net.exe` utility to disable + a user account via the command line. It leverages data from Endpoint Detection and + Response (EDR) agents, focusing on process execution logs and command-line arguments. + This activity is significant as it may indicate an adversary's attempt to disrupt + user availability, potentially as a precursor to further malicious actions. If confirmed + malicious, this could lead to denial of service for legitimate users, aiding the + attacker in maintaining control or covering their tracks. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/domain_account_discovery_with_net_app.yml b/detections/deprecated/domain_account_discovery_with_net_app.yml index 92ad5bcfa8..a1518a4c1f 100644 --- a/detections/deprecated/domain_account_discovery_with_net_app.yml +++ b/detections/deprecated/domain_account_discovery_with_net_app.yml @@ -1,7 +1,7 @@ name: Domain Account Discovery With Net App id: 98f6a534-04c2-11ec-96b2-acde48001122 -version: 5 -date: '2025-01-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: deprecated type: TTP @@ -71,7 +71,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/domain_group_discovery_with_net.yml b/detections/deprecated/domain_group_discovery_with_net.yml index b01c32e127..928dec10e8 100644 --- a/detections/deprecated/domain_group_discovery_with_net.yml +++ b/detections/deprecated/domain_group_discovery_with_net.yml @@ -1,7 +1,7 @@ name: Domain Group Discovery With Net id: f2f14ac7-fa81-471a-80d5-7eb65c3c7349 -version: 6 -date: '2025-01-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: deprecated type: Hunting @@ -46,7 +46,6 @@ tags: - Cleo File Transfer Software asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/deprecated/elevated_group_discovery_with_net.yml b/detections/deprecated/elevated_group_discovery_with_net.yml index 45c777516b..a941649159 100644 --- a/detections/deprecated/elevated_group_discovery_with_net.yml +++ b/detections/deprecated/elevated_group_discovery_with_net.yml @@ -1,7 +1,7 @@ name: Elevated Group Discovery With Net id: a23a0e20-0b1b-4a07-82e5-ec5f70811e7a -version: 6 -date: '2025-01-24' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: deprecated type: TTP @@ -70,7 +70,6 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/deprecated/excel_spawning_powershell.yml b/detections/deprecated/excel_spawning_powershell.yml index 28ca3fa40a..764de86234 100644 --- a/detections/deprecated/excel_spawning_powershell.yml +++ b/detections/deprecated/excel_spawning_powershell.yml @@ -1,7 +1,7 @@ name: Excel Spawning PowerShell id: 42d40a22-9be3-11eb-8f08-acde48001122 -version: 7 -date: '2025-01-13' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -75,7 +75,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.002 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/excel_spawning_windows_script_host.yml b/detections/deprecated/excel_spawning_windows_script_host.yml index 70da2b9f10..40deb89c49 100644 --- a/detections/deprecated/excel_spawning_windows_script_host.yml +++ b/detections/deprecated/excel_spawning_windows_script_host.yml @@ -1,12 +1,12 @@ name: Excel Spawning Windows Script Host id: 57fe880a-9be3-11eb-9bf3-acde48001122 -version: 8 -date: '2025-01-13' +version: 10 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP -description: The following analytic has been deprecated in favour of a more generic approach. - The following analytic identifies instances where Microsoft Excel spawns +description: The following analytic has been deprecated in favour of a more generic + approach. The following analytic identifies instances where Microsoft Excel spawns Windows Script Host processes (`cscript.exe` or `wscript.exe`). This behavior is detected using Endpoint Detection and Response (EDR) telemetry, focusing on process creation events where the parent process is `excel.exe`. This activity is significant @@ -75,7 +75,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.002 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security @@ -84,6 +83,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/deprecated/excessive_service_stop_attempt.yml b/detections/deprecated/excessive_service_stop_attempt.yml index 9c51626bde..3e27dc456b 100644 --- a/detections/deprecated/excessive_service_stop_attempt.yml +++ b/detections/deprecated/excessive_service_stop_attempt.yml @@ -5,14 +5,15 @@ date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated type: Anomaly -description: The following analytic has been deprecated. The following analytic detects - multiple attempts to stop or delete services on a system using `net.exe`, `sc.exe`, - or `net1.exe`. It leverages Endpoint Detection and Response (EDR) telemetry, focusing - on process names and command-line executions within a one-minute window. This activity - is significant as it may indicate an adversary attempting to disable security or - critical services to evade detection and further their objectives. If confirmed - malicious, this could lead to the attacker gaining persistence, escalating privileges, - or disrupting essential services, thereby compromising the system's security posture. +description: The following analytic has been deprecated. + The following analytic detects multiple attempts to stop or delete services + on a system using `net.exe`, `sc.exe`, or `net1.exe`. It leverages Endpoint Detection + and Response (EDR) telemetry, focusing on process names and command-line executions + within a one-minute window. This activity is significant as it may indicate an adversary + attempting to disable security or critical services to evade detection and further + their objectives. If confirmed malicious, this could lead to the attacker gaining + persistence, escalating privileges, or disrupting essential services, thereby compromising + the system's security posture. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/excessive_usage_of_net_app.yml b/detections/deprecated/excessive_usage_of_net_app.yml index 050c4047c9..1b3556f57b 100644 --- a/detections/deprecated/excessive_usage_of_net_app.yml +++ b/detections/deprecated/excessive_usage_of_net_app.yml @@ -1,18 +1,19 @@ name: Excessive Usage Of Net App id: 45e52536-ae42-11eb-b5c6-acde48001122 -version: 6 +version: 7 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated type: Anomaly -description: The following analytic has been deprecated. The following analytic detects - excessive usage of `net.exe` or `net1.exe` within a one-minute interval. It leverages - data from Endpoint Detection and Response (EDR) agents, focusing on process names, - parent processes, and command-line executions. This behavior is significant as it - may indicate an adversary attempting to create, delete, or disable multiple user - accounts rapidly, a tactic observed in Monero mining incidents. If confirmed malicious, - this activity could lead to unauthorized user account manipulation, potentially - compromising system integrity and enabling further malicious actions. +description: The following analytic has been deprecated. + The following analytic detects excessive usage of `net.exe` or `net1.exe` + within a one-minute interval. It leverages data from Endpoint Detection and Response + (EDR) agents, focusing on process names, parent processes, and command-line executions. + This behavior is significant as it may indicate an adversary attempting to create, + delete, or disable multiple user accounts rapidly, a tactic observed in Monero mining + incidents. If confirmed malicious, this activity could lead to unauthorized user + account manipulation, potentially compromising system integrity and enabling further + malicious actions. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/extraction_of_registry_hives.yml b/detections/deprecated/extraction_of_registry_hives.yml index 7e1ddbc2bc..ceb5264fa6 100644 --- a/detections/deprecated/extraction_of_registry_hives.yml +++ b/detections/deprecated/extraction_of_registry_hives.yml @@ -1,7 +1,7 @@ name: Extraction of Registry Hives id: 8bbb7d58-b360-11eb-ba21-acde48001122 -version: 6 -date: '2025-01-24' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -77,7 +77,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.002 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/known_services_killed_by_ransomware.yml b/detections/deprecated/known_services_killed_by_ransomware.yml similarity index 93% rename from detections/endpoint/known_services_killed_by_ransomware.yml rename to detections/deprecated/known_services_killed_by_ransomware.yml index 38760a26ef..5ca93f96d4 100644 --- a/detections/endpoint/known_services_killed_by_ransomware.yml +++ b/detections/deprecated/known_services_killed_by_ransomware.yml @@ -1,11 +1,11 @@ name: Known Services Killed by Ransomware id: 3070f8e0-c528-11eb-b2a0-acde48001122 -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-07' author: Teoderick Contreras, Splunk -status: production +status: deprecated type: TTP -description: The following analytic detects the suspicious termination of known services +description: This analytic has been deprecated in favor of a new analytic - Windows Security And Backup Services Stop. The following analytic detects the suspicious termination of known services commonly targeted by ransomware before file encryption. It leverages Windows System Event Logs (EventCode 7036) to identify when critical services such as Volume Shadow Copy, backup, and antivirus services are stopped. This activity is significant because @@ -75,4 +75,4 @@ tests: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/known_services_killed_by_ransomware/windows-xml.log source: XmlWinEventLog:System - sourcetype: XmlWinEventLog + sourcetype: XmlWinEventLog \ No newline at end of file diff --git a/detections/deprecated/linux_auditd_find_private_keys.yml b/detections/deprecated/linux_auditd_find_private_keys.yml index 756073da56..d45b98a890 100644 --- a/detections/deprecated/linux_auditd_find_private_keys.yml +++ b/detections/deprecated/linux_auditd_find_private_keys.yml @@ -1,7 +1,7 @@ name: Linux Auditd Find Private Keys id: 80bb9988-190b-4ee0-a3c3-509545a8f678 -version: 5 -date: '2025-01-24' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: deprecated type: TTP @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.004 - - T1552 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/local_account_discovery_with_net.yml b/detections/deprecated/local_account_discovery_with_net.yml index 8af80acf03..69f3af6598 100644 --- a/detections/deprecated/local_account_discovery_with_net.yml +++ b/detections/deprecated/local_account_discovery_with_net.yml @@ -1,7 +1,7 @@ name: Local Account Discovery with Net id: 5d0d4830-0133-11ec-bae3-acde48001122 -version: 6 -date: '2025-01-24' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: deprecated type: Hunting @@ -41,7 +41,6 @@ tags: - Sandworm Tools asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.001 product: - Splunk Enterprise diff --git a/detections/deprecated/mshtml_module_load_in_office_product.yml b/detections/deprecated/mshtml_module_load_in_office_product.yml index 870c4aea9d..833a24a872 100644 --- a/detections/deprecated/mshtml_module_load_in_office_product.yml +++ b/detections/deprecated/mshtml_module_load_in_office_product.yml @@ -1,7 +1,7 @@ name: MSHTML Module Load in Office Product id: 5f1c168e-118b-11ec-84ff-acde48001122 -version: 7 -date: '2025-01-24' +version: 8 +date: '2025-02-10' author: Michael Haag, Mauricio Velazco, Splunk status: deprecated type: TTP @@ -64,7 +64,6 @@ tags: cve: - CVE-2021-40444 mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml b/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml index 68269b2e43..1ebadf8ebc 100644 --- a/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml +++ b/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml @@ -1,7 +1,7 @@ name: Multiple Okta Users With Invalid Credentials From The Same IP id: 19cba45f-cad3-4032-8911-0c09e0444552 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Michael Haag, Mauricio Velazco, Rico Valdez, Splunk status: deprecated type: TTP @@ -41,9 +41,8 @@ tags: - Suspicious Okta Activity asset_type: Okta Tenant mitre_attack_id: - - T1110.003 - - T1078 - T1078.001 + - T1110.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/net_localgroup_discovery.yml b/detections/deprecated/net_localgroup_discovery.yml index b3d15becdf..31b775f015 100644 --- a/detections/deprecated/net_localgroup_discovery.yml +++ b/detections/deprecated/net_localgroup_discovery.yml @@ -1,7 +1,7 @@ name: Net Localgroup Discovery id: 54f5201e-155b-11ec-a6e2-acde48001122 -version: 5 -date: '2025-01-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: Hunting @@ -52,7 +52,6 @@ tags: - Rhysida Ransomware asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.001 product: - Splunk Enterprise diff --git a/detections/deprecated/network_connection_discovery_with_net.yml b/detections/deprecated/network_connection_discovery_with_net.yml index e2caea92c7..0002699f31 100644 --- a/detections/deprecated/network_connection_discovery_with_net.yml +++ b/detections/deprecated/network_connection_discovery_with_net.yml @@ -5,15 +5,15 @@ date: '2025-01-24' author: Mauricio Velazco, Splunk status: deprecated type: Hunting -description: The following analytic has been deprecated. The following analytic identifies - the execution of `net.exe` or `net1.exe` with command-line arguments used to list - network connections on a compromised system. It leverages data from Endpoint Detection - and Response (EDR) agents, focusing on process names and command-line executions. - This activity is significant as it indicates potential network reconnaissance by - adversaries or Red Teams, aiming to gather situational awareness and Active Directory - information. If confirmed malicious, this behavior could allow attackers to map - the network, identify critical assets, and plan further attacks, potentially leading - to data exfiltration or lateral movement. +description: The following analytic has been deprecated. + The following analytic identifies the execution of `net.exe` or `net1.exe` + with command-line arguments used to list network connections on a compromised system. + It leverages data from Endpoint Detection and Response (EDR) agents, focusing on + process names and command-line executions. This activity is significant as it indicates + potential network reconnaissance by adversaries or Red Teams, aiming to gather situational + awareness and Active Directory information. If confirmed malicious, this behavior + could allow attackers to map the network, identify critical assets, and plan further + attacks, potentially leading to data exfiltration or lateral movement. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/o365_suspicious_admin_email_forwarding.yml b/detections/deprecated/o365_suspicious_admin_email_forwarding.yml index 13dddb8c18..b706b2d0a8 100644 --- a/detections/deprecated/o365_suspicious_admin_email_forwarding.yml +++ b/detections/deprecated/o365_suspicious_admin_email_forwarding.yml @@ -1,7 +1,7 @@ name: O365 Suspicious Admin Email Forwarding id: 7f398cfb-918d-41f4-8db8-2e2474e02c28 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: deprecated type: Anomaly @@ -33,7 +33,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1114.003 - - T1114 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/o365_suspicious_rights_delegation.yml b/detections/deprecated/o365_suspicious_rights_delegation.yml index e9e6543750..716fd6289c 100644 --- a/detections/deprecated/o365_suspicious_rights_delegation.yml +++ b/detections/deprecated/o365_suspicious_rights_delegation.yml @@ -1,7 +1,7 @@ name: O365 Suspicious Rights Delegation id: b25d2973-303e-47c8-bacd-52b61604c6a7 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Mauricio Velazco, Splunk status: deprecated type: TTP @@ -56,10 +56,8 @@ tags: - Office 365 Collection Techniques asset_type: O365 Tenant mitre_attack_id: - - T1114.002 - - T1114 - T1098.002 - - T1098 + - T1114.002 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/o365_suspicious_user_email_forwarding.yml b/detections/deprecated/o365_suspicious_user_email_forwarding.yml index 1a9c9c5c4c..4ea5ecc88d 100644 --- a/detections/deprecated/o365_suspicious_user_email_forwarding.yml +++ b/detections/deprecated/o365_suspicious_user_email_forwarding.yml @@ -1,7 +1,7 @@ name: O365 Suspicious User Email Forwarding id: f8dfe015-dbb3-4569-ba75-b13787e06aa4 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: deprecated type: Anomaly @@ -59,7 +59,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1114.003 - - T1114 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/office_application_drop_executable.yml b/detections/deprecated/office_application_drop_executable.yml index 792556a6d3..c87210ccf6 100644 --- a/detections/deprecated/office_application_drop_executable.yml +++ b/detections/deprecated/office_application_drop_executable.yml @@ -1,7 +1,7 @@ name: Office Application Drop Executable id: 73ce70c4-146d-11ec-9184-acde48001122 -version: 9 -date: '2025-01-24' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Michael Haag, Splunk, TheLawsOfChaos, Github status: deprecated type: TTP @@ -69,7 +69,6 @@ tags: - PlugX asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_application_spawn_regsvr32_process.yml b/detections/deprecated/office_application_spawn_regsvr32_process.yml index ceec84dba1..8aa07a2de3 100644 --- a/detections/deprecated/office_application_spawn_regsvr32_process.yml +++ b/detections/deprecated/office_application_spawn_regsvr32_process.yml @@ -1,7 +1,7 @@ name: Office Application Spawn Regsvr32 process id: 2d9fc90c-f11f-11eb-9300-acde48001122 -version: 8 -date: '2025-01-13' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: deprecated type: TTP @@ -70,7 +70,6 @@ tags: - Qakbot asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_application_spawn_rundll32_process.yml b/detections/deprecated/office_application_spawn_rundll32_process.yml index 6d10c2b8c8..e648095cc9 100644 --- a/detections/deprecated/office_application_spawn_rundll32_process.yml +++ b/detections/deprecated/office_application_spawn_rundll32_process.yml @@ -1,7 +1,7 @@ name: Office Application Spawn rundll32 process id: 958751e4-9c5f-11eb-b103-acde48001122 -version: 8 -date: '2025-01-13' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: deprecated type: TTP @@ -73,7 +73,6 @@ tags: - Trickbot asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_document_creating_schedule_task.yml b/detections/deprecated/office_document_creating_schedule_task.yml index 1275c00579..ef59131ecc 100644 --- a/detections/deprecated/office_document_creating_schedule_task.yml +++ b/detections/deprecated/office_document_creating_schedule_task.yml @@ -1,7 +1,7 @@ name: Office Document Creating Schedule Task id: cc8b7b74-9d0f-11eb-8342-acde48001122 -version: 10 -date: '2025-01-24' +version: 11 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: deprecated type: TTP @@ -59,7 +59,6 @@ tags: - Spearphishing Attachments asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_document_executing_macro_code.yml b/detections/deprecated/office_document_executing_macro_code.yml index 9bf6ad3357..8d74ea1aa2 100644 --- a/detections/deprecated/office_document_executing_macro_code.yml +++ b/detections/deprecated/office_document_executing_macro_code.yml @@ -1,7 +1,7 @@ name: Office Document Executing Macro Code id: b12c89bc-9d06-11eb-a592-acde48001122 -version: 9 -date: '2025-01-24' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: deprecated type: TTP @@ -69,7 +69,6 @@ tags: - NjRAT asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_document_spawned_child_process_to_download.yml b/detections/deprecated/office_document_spawned_child_process_to_download.yml index 73220f4027..2e78ed372c 100644 --- a/detections/deprecated/office_document_spawned_child_process_to_download.yml +++ b/detections/deprecated/office_document_spawned_child_process_to_download.yml @@ -1,7 +1,7 @@ name: Office Document Spawned Child Process To Download id: 6fed27d2-9ec7-11eb-8fe4-aa665a019aa3 -version: 10 -date: '2025-01-24' +version: 11 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: deprecated type: TTP @@ -69,7 +69,6 @@ tags: - NjRAT asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_product_spawn_cmd_process.yml b/detections/deprecated/office_product_spawn_cmd_process.yml index 4193c23ca8..4893d60d9f 100644 --- a/detections/deprecated/office_product_spawn_cmd_process.yml +++ b/detections/deprecated/office_product_spawn_cmd_process.yml @@ -1,7 +1,7 @@ name: Office Product Spawn CMD Process id: b8b19420-e892-11eb-9244-acde48001122 -version: 8 -date: '2025-01-13' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: deprecated type: TTP @@ -85,7 +85,6 @@ tags: - NjRAT asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_product_spawning_bitsadmin.yml b/detections/deprecated/office_product_spawning_bitsadmin.yml index 3bda779c35..28ee0cc811 100644 --- a/detections/deprecated/office_product_spawning_bitsadmin.yml +++ b/detections/deprecated/office_product_spawning_bitsadmin.yml @@ -1,7 +1,7 @@ name: Office Product Spawning BITSAdmin id: e8c591f4-a6d7-11eb-8cf7-acde48001122 -version: 9 -date: '2025-01-13' +version: 10 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -71,7 +71,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_product_spawning_certutil.yml b/detections/deprecated/office_product_spawning_certutil.yml index 00bc0797c9..698343c8ae 100644 --- a/detections/deprecated/office_product_spawning_certutil.yml +++ b/detections/deprecated/office_product_spawning_certutil.yml @@ -1,7 +1,7 @@ name: Office Product Spawning CertUtil id: 6925fe72-a6d5-11eb-9e17-acde48001122 -version: 9 -date: '2025-01-13' +version: 10 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -72,7 +72,6 @@ tags: - CVE-2023-36884 Office and Windows HTML RCE Vulnerability asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_product_spawning_mshta.yml b/detections/deprecated/office_product_spawning_mshta.yml index ef07f76ce2..9c8c8ae1ce 100644 --- a/detections/deprecated/office_product_spawning_mshta.yml +++ b/detections/deprecated/office_product_spawning_mshta.yml @@ -1,7 +1,7 @@ name: Office Product Spawning MSHTA id: 6078fa20-a6d2-11eb-b662-acde48001122 -version: 8 -date: '2025-01-13' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -71,7 +71,6 @@ tags: - CVE-2023-36884 Office and Windows HTML RCE Vulnerability asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml b/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml index a74965e373..41f3f9df66 100644 --- a/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml +++ b/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml @@ -1,7 +1,7 @@ name: Office Product Spawning Rundll32 with no DLL id: c661f6be-a38c-11eb-be57-acde48001122 -version: 10 -date: '2025-01-24' +version: 11 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -72,7 +72,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_product_spawning_windows_script_host.yml b/detections/deprecated/office_product_spawning_windows_script_host.yml index 659a4b48ed..b4da3bfa8e 100644 --- a/detections/deprecated/office_product_spawning_windows_script_host.yml +++ b/detections/deprecated/office_product_spawning_windows_script_host.yml @@ -1,7 +1,7 @@ name: Office Product Spawning Windows Script Host id: b3628a5b-8d02-42fa-a891-eebf2351cbe1 -version: 10 -date: '2025-01-13' +version: 12 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -75,7 +75,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_product_spawning_wmic.yml b/detections/deprecated/office_product_spawning_wmic.yml index a06d97a5d7..0e60c6e32f 100644 --- a/detections/deprecated/office_product_spawning_wmic.yml +++ b/detections/deprecated/office_product_spawning_wmic.yml @@ -1,7 +1,7 @@ name: Office Product Spawning Wmic id: ffc236d6-a6c9-11eb-95f1-acde48001122 -version: 10 -date: '2025-01-13' +version: 11 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -72,7 +72,6 @@ tags: - FIN7 asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_product_writing_cab_or_inf.yml b/detections/deprecated/office_product_writing_cab_or_inf.yml index 30adac14d5..9d29d2a888 100644 --- a/detections/deprecated/office_product_writing_cab_or_inf.yml +++ b/detections/deprecated/office_product_writing_cab_or_inf.yml @@ -1,7 +1,7 @@ name: Office Product Writing cab or inf id: f48cd1d4-125a-11ec-a447-acde48001122 -version: 10 -date: '2025-01-24' +version: 11 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -76,7 +76,6 @@ tags: cve: - CVE-2021-40444 mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_spawning_control.yml b/detections/deprecated/office_spawning_control.yml index 984e8bf0a8..f141b89519 100644 --- a/detections/deprecated/office_spawning_control.yml +++ b/detections/deprecated/office_spawning_control.yml @@ -1,7 +1,7 @@ name: Office Spawning Control id: 053e027c-10c7-11ec-8437-acde48001122 -version: 10 -date: '2025-01-24' +version: 12 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -77,7 +77,6 @@ tags: cve: - CVE-2021-40444 mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/okta_account_lockout_events.yml b/detections/deprecated/okta_account_lockout_events.yml index 07f8d09a9d..b2ec1f14ef 100644 --- a/detections/deprecated/okta_account_lockout_events.yml +++ b/detections/deprecated/okta_account_lockout_events.yml @@ -1,7 +1,7 @@ name: Okta Account Lockout Events id: 62b70968-a0a5-4724-8ac4-67871e6f544d -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Michael Haag, Rico Valdez, Splunk status: deprecated type: Anomaly @@ -43,7 +43,6 @@ tags: - Suspicious Okta Activity asset_type: Infrastructure mitre_attack_id: - - T1078 - T1078.001 product: - Splunk Enterprise diff --git a/detections/deprecated/okta_failed_sso_attempts.yml b/detections/deprecated/okta_failed_sso_attempts.yml index 6516d32c67..3c1d92c759 100644 --- a/detections/deprecated/okta_failed_sso_attempts.yml +++ b/detections/deprecated/okta_failed_sso_attempts.yml @@ -1,7 +1,7 @@ name: Okta Failed SSO Attempts id: 371a6545-2618-4032-ad84-93386b8698c5 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Michael Haag, Rico Valdez, Splunk status: deprecated type: Anomaly @@ -32,7 +32,6 @@ tags: - Suspicious Okta Activity asset_type: Infrastructure mitre_attack_id: - - T1078 - T1078.001 product: - Splunk Enterprise diff --git a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml b/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml index 1f87cc42bf..00af9d0aa5 100644 --- a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml +++ b/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml @@ -1,7 +1,7 @@ name: Okta ThreatInsight Login Failure with High Unknown users id: 632663b0-4562-4aad-abe9-9f621a049738 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Okta, Inc, Michael Haag, Splunk type: TTP status: deprecated @@ -34,7 +34,6 @@ tags: - Suspicious Okta Activity asset_type: Infrastructure mitre_attack_id: - - T1078 - T1078.001 - T1110.004 product: diff --git a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml b/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml index 478b4895a1..e68cf87729 100644 --- a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml +++ b/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml @@ -1,7 +1,7 @@ name: Okta ThreatInsight Suspected PasswordSpray Attack id: 25dbad05-6682-4dd5-9ce9-8adecf0d9ae2 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Okta, Inc, Michael Haag, Splunk type: TTP status: deprecated @@ -33,7 +33,6 @@ tags: - Suspicious Okta Activity asset_type: Infrastructure mitre_attack_id: - - T1078 - T1078.001 - T1110.003 product: diff --git a/detections/deprecated/osquery_pack___coldroot_detection.yml b/detections/deprecated/osquery_pack___coldroot_detection.yml index 3ba9866bed..369173b8fd 100644 --- a/detections/deprecated/osquery_pack___coldroot_detection.yml +++ b/detections/deprecated/osquery_pack___coldroot_detection.yml @@ -1,6 +1,6 @@ name: Osquery pack - ColdRoot detection id: a6fffe5e-05c3-4c04-badc-887607fbb8dc -version: 4 +version: 5 date: '2024-11-14' author: Rico Valdez, Splunk status: deprecated diff --git a/detections/deprecated/password_policy_discovery_with_net.yml b/detections/deprecated/password_policy_discovery_with_net.yml index 66ef237307..0656e661c8 100644 --- a/detections/deprecated/password_policy_discovery_with_net.yml +++ b/detections/deprecated/password_policy_discovery_with_net.yml @@ -5,15 +5,16 @@ date: '2025-01-24' author: Teoderick Contreras, Mauricio Velazco, Splunk status: deprecated type: Hunting -description: The following analytic has been deprecated. The following analytic identifies - the execution of `net.exe` or `net1.exe` with command line arguments aimed at obtaining - the domain password policy. It leverages data from Endpoint Detection and Response - (EDR) agents, focusing on process names and command-line executions. This activity - is significant as it indicates potential reconnaissance efforts by adversaries to - gather information about Active Directory password policies. If confirmed malicious, - this behavior could allow attackers to understand password complexity requirements, - aiding in brute-force or password-guessing attacks, ultimately compromising user - accounts and gaining unauthorized access to the network. +description: The following analytic has been deprecated. + The following analytic identifies the execution of `net.exe` or `net1.exe` + with command line arguments aimed at obtaining the domain password policy. It leverages + data from Endpoint Detection and Response (EDR) agents, focusing on process names + and command-line executions. This activity is significant as it indicates potential + reconnaissance efforts by adversaries to gather information about Active Directory + password policies. If confirmed malicious, this behavior could allow attackers to + understand password complexity requirements, aiding in brute-force or password-guessing + attacks, ultimately compromising user accounts and gaining unauthorized access to + the network. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/remote_desktop_network_bruteforce.yml b/detections/deprecated/remote_desktop_network_bruteforce.yml new file mode 100644 index 0000000000..400fe691cf --- /dev/null +++ b/detections/deprecated/remote_desktop_network_bruteforce.yml @@ -0,0 +1,58 @@ +name: Remote Desktop Network Bruteforce +id: a98727cc-286b-4ff2-b898-41df64695923 +version: 7 +date: '2025-01-10' +author: Jose Hernandez, Bhavin Patel, Splunk +status: deprecated +type: TTP +description: The following analytic has been deprecated in favor of "Windows Remote Desktop Network Bruteforce Attempt". The following analytic identifies potential Remote Desktop Protocol (RDP) brute force attacks by monitoring network traffic for RDP application activity. This query detects potential RDP brute force attacks by identifying source IPs that have made more than 10 successful connection attempts to the same RDP port on a host within a one-hour window. The results are presented in a table that includes the source and destination IPs, destination port, number of attempts, and the times of the first and last connection attempts, helping to prioritize IPs based on the intensity of activity. +data_source: +- Sysmon EventID 3 +search: >- + | tstats `security_content_summariesonly` count, min(_time) as firstTime, max(_time) as lastTime from datamodel=Network_Traffic where (All_Traffic.app=rdp OR All_Traffic.dest_port=3389) AND All_Traffic.action=allowed by All_Traffic.src, All_Traffic.dest, All_Traffic.dest_port All_Traffic.user All_Traffic.vendor_product + | `drop_dm_object_name("All_Traffic")` + | eval duration=lastTime-firstTime + | where count > 10 AND duration < 3600 + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `remote_desktop_network_bruteforce_filter` +how_to_implement: You must ensure that your network traffic data is populating the Network_Traffic data model. Adjust the count and duration thresholds as necessary to tune the sensitivity of your detection. +known_false_positives: RDP gateways may have unusually high amounts of traffic from all other hosts' RDP applications in the network.Any legitimate RDP traffic using wrong/expired credentials will be also detected as a false positive. +references: +- https://www.zscaler.com/blogs/security-research/ransomware-delivered-using-rdp-brute-force-attack +- https://www.reliaquest.com/blog/rdp-brute-force-attacks/ +drilldown_searches: +- name: View the detection results for - "$dest$" + search: '%original_detection_search% | search dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: RDP brute force attack on $dest$ + risk_objects: + - field: dest + type: system + score: 25 + threat_objects: [] +tags: + analytic_story: + - SamSam Ransomware + - Ryuk Ransomware + - Compromised User Account + asset_type: Endpoint + mitre_attack_id: + - T1110.001 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: network +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.001/rdp_brute_sysmon/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/deprecated/remote_system_discovery_with_net.yml b/detections/deprecated/remote_system_discovery_with_net.yml index 6e730569fc..2377264b52 100644 --- a/detections/deprecated/remote_system_discovery_with_net.yml +++ b/detections/deprecated/remote_system_discovery_with_net.yml @@ -5,35 +5,13 @@ date: '2025-01-13' author: Mauricio Velazco, Splunk status: deprecated type: Hunting -description: The following analytic has been deprecated in favour of two dedicated - analytics "4dc3951f-b3f8-4f46-b412-76a483f72277" and "a23a0e20-0b1b-4a07-82e5-ec5f70811e7a" - .The following analytic identifies the execution of `net.exe` or `net1.exe` with - command-line arguments used to discover remote systems, such as `domain computers - /domain`. This detection leverages data from Endpoint Detection and Response (EDR) - agents, focusing on process names and command-line arguments. This activity is significant - as it indicates potential reconnaissance efforts by adversaries or Red Teams to - map out networked systems and Active Directory structures. If confirmed malicious, - this behavior could lead to further network exploitation, privilege escalation, - or lateral movement within the environment. +description: The following analytic has been deprecated in favour of two dedicated analytics "4dc3951f-b3f8-4f46-b412-76a483f72277" and "a23a0e20-0b1b-4a07-82e5-ec5f70811e7a" .The following analytic identifies the execution of `net.exe` or `net1.exe` with command-line arguments used to discover remote systems, such as `domain computers /domain`. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments. This activity is significant as it indicates potential reconnaissance efforts by adversaries or Red Teams to map out networked systems and Active Directory structures. If confirmed malicious, this behavior could lead to further network exploitation, privilege escalation, or lateral movement within the environment. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where `process_net` AND (Processes.process="*domain - computers*" AND Processes.process=*/do*) OR (Processes.process="*view*" AND Processes.process=*/do*) - by Processes.dest Processes.user Processes.parent_process Processes.process_name - Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `remote_system_discovery_with_net_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection - and Response (EDR) agents. These agents are designed to provide security-related - telemetry from the endpoints where the agent is installed. To implement this search, - you must ingest logs that contain the process GUID, process name, and parent process. - Additionally, you must ingest complete command-line executions. These logs must - be processed using the appropriate Splunk Technology Add-ons that are specific to - the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` - data model. Use the Splunk Common Information Model (CIM) to normalize the field - names and speed up the data modeling process. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` AND (Processes.process="*domain computers*" AND Processes.process=*/do*) OR (Processes.process="*view*" AND Processes.process=*/do*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `remote_system_discovery_with_net_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. known_false_positives: Administrators or power users may use this command for troubleshooting. references: - https://attack.mitre.org/techniques/T1018/ @@ -53,7 +31,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/suspicious_driver_loaded_path.yml b/detections/deprecated/suspicious_driver_loaded_path.yml similarity index 93% rename from detections/endpoint/suspicious_driver_loaded_path.yml rename to detections/deprecated/suspicious_driver_loaded_path.yml index 91196704e5..16d121b7b3 100644 --- a/detections/endpoint/suspicious_driver_loaded_path.yml +++ b/detections/deprecated/suspicious_driver_loaded_path.yml @@ -1,11 +1,11 @@ name: Suspicious Driver Loaded Path id: f880acd4-a8f1-11eb-a53b-acde48001122 -version: 4 -date: '2024-11-13' +version: 6 +date: '2025-02-06' author: Teoderick Contreras, Splunk -status: production +status: deprecated type: TTP -description: The following analytic detects the loading of drivers from suspicious +description: This search has been deprecated in favour of - Windows Suspicious Driver Loaded Path. The following analytic detects the loading of drivers from suspicious paths, which is a technique often used by malicious software such as coin miners (e.g., xmrig). It leverages Sysmon EventCode 6 to identify drivers loaded from non-standard directories. This activity is significant because legitimate drivers typically reside @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1543.003 - - T1543 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_process_file_path.yml b/detections/deprecated/suspicious_process_file_path.yml similarity index 95% rename from detections/endpoint/suspicious_process_file_path.yml rename to detections/deprecated/suspicious_process_file_path.yml index 1d636ec76c..d7cd62534f 100644 --- a/detections/endpoint/suspicious_process_file_path.yml +++ b/detections/deprecated/suspicious_process_file_path.yml @@ -1,11 +1,11 @@ name: Suspicious Process File Path id: 9be25988-ad82-11eb-a14f-acde48001122 -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk -status: production +status: deprecated type: TTP -description: The following analytic identifies processes running from file paths not +description: This search has been deprecated in favour of - Windows Suspicious Process File Path. The following analytic identifies processes running from file paths not typically associated with legitimate software. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on specific process paths within the Endpoint data model. This activity is significant because adversaries often use unconventional @@ -117,4 +117,4 @@ tests: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog + sourcetype: XmlWinEventLog \ No newline at end of file diff --git a/detections/deprecated/suspicious_rundll32_rename.yml b/detections/deprecated/suspicious_rundll32_rename.yml index 48fdc6b2d5..eee4228129 100644 --- a/detections/deprecated/suspicious_rundll32_rename.yml +++ b/detections/deprecated/suspicious_rundll32_rename.yml @@ -1,7 +1,7 @@ name: Suspicious Rundll32 Rename id: 7360137f-abad-473e-8189-acbdaa34d114 -version: 7 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: Hunting @@ -40,10 +40,8 @@ tags: - Masquerading - Rename System Utilities asset_type: Endpoint mitre_attack_id: - - T1218 - - T1036 - - T1218.011 - T1036.003 + - T1218.011 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/windows_command_shell_fetch_env_variables.yml b/detections/deprecated/windows_command_shell_fetch_env_variables.yml index 8fcaf15950..90618ba3e5 100644 --- a/detections/deprecated/windows_command_shell_fetch_env_variables.yml +++ b/detections/deprecated/windows_command_shell_fetch_env_variables.yml @@ -5,14 +5,15 @@ date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated type: TTP -description: The following analytic has been deprecated. The following analytic identifies - a suspicious process command line fetching environment variables with a non-shell - parent process. It leverages data from Endpoint Detection and Response (EDR) agents, - focusing on command-line executions and parent process names. This activity is significant - as it is commonly associated with malware like Qakbot, which uses this technique - to gather system information. If confirmed malicious, this behavior could indicate - that the parent process has been compromised, potentially allowing attackers to - execute arbitrary commands, escalate privileges, or persist within the environment. +description: The following analytic has been deprecated. + The following analytic identifies a suspicious process command line fetching + environment variables with a non-shell parent process. It leverages data from Endpoint + Detection and Response (EDR) agents, focusing on command-line executions and parent + process names. This activity is significant as it is commonly associated with malware + like Qakbot, which uses this technique to gather system information. If confirmed + malicious, this behavior could indicate that the parent process has been compromised, + potentially allowing attackers to execute arbitrary commands, escalate privileges, + or persist within the environment. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml b/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml index 38d777ae9a..6149fc746d 100644 --- a/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml +++ b/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml @@ -1,7 +1,7 @@ name: Windows DLL Search Order Hijacking Hunt id: 79c7d0fc-60c7-41be-a616-ccda752efe89 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: Hunting @@ -49,7 +49,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.001 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/windows_lateral_tool_transfer_remcom.yml b/detections/deprecated/windows_lateral_tool_transfer_remcom.yml index 0611c1c8f6..47789c6b30 100644 --- a/detections/deprecated/windows_lateral_tool_transfer_remcom.yml +++ b/detections/deprecated/windows_lateral_tool_transfer_remcom.yml @@ -1,6 +1,6 @@ name: Windows Lateral Tool Transfer RemCom id: e373a840-5bdc-47ef-b2fd-9cc7aaf387f0 -version: 5 +version: 6 date: '2024-12-10' author: Michael Haag, Splunk type: TTP diff --git a/detections/deprecated/windows_modify_registry_reg_restore.yml b/detections/deprecated/windows_modify_registry_reg_restore.yml index e1fcad055a..f63d1b0214 100644 --- a/detections/deprecated/windows_modify_registry_reg_restore.yml +++ b/detections/deprecated/windows_modify_registry_reg_restore.yml @@ -5,15 +5,15 @@ date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated type: Hunting -description: The following analytic has been deprecated. The following analytic detects - the execution of reg.exe with the "restore" parameter, indicating an attempt to - restore registry backup data on a host. This detection leverages data from Endpoint - Detection and Response (EDR) agents, focusing on process execution logs and command-line - arguments. This activity is significant as it may indicate post-exploitation actions, - such as those performed by tools like winpeas, which use "reg save" and "reg restore" - to manipulate registry settings. If confirmed malicious, this could allow an attacker - to revert registry changes, potentially bypassing security controls and maintaining - persistence. +description: The following analytic has been deprecated. + The following analytic detects the execution of reg.exe with the "restore" + parameter, indicating an attempt to restore registry backup data on a host. This + detection leverages data from Endpoint Detection and Response (EDR) agents, focusing + on process execution logs and command-line arguments. This activity is significant + as it may indicate post-exploitation actions, such as those performed by tools like + winpeas, which use "reg save" and "reg restore" to manipulate registry settings. + If confirmed malicious, this could allow an attacker to revert registry changes, + potentially bypassing security controls and maintaining persistence. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/windows_msiexec_with_network_connections.yml b/detections/deprecated/windows_msiexec_with_network_connections.yml index 39ac9d4465..5c17518468 100644 --- a/detections/deprecated/windows_msiexec_with_network_connections.yml +++ b/detections/deprecated/windows_msiexec_with_network_connections.yml @@ -1,18 +1,19 @@ name: Windows MSIExec With Network Connections id: 827409a1-5393-4d8d-8da4-bbb297c262a7 -version: 6 +version: 7 date: '2025-01-24' author: Michael Haag, Splunk status: deprecated type: TTP -description: The following analytic has been deprecated. The following analytic detects - MSIExec making network connections over ports 443 or 80. This behavior is identified - by correlating process creation events from Endpoint Detection and Response (EDR) - agents with network traffic logs. Typically, MSIExec does not perform network communication - to the internet, making this activity unusual and potentially indicative of malicious - behavior. If confirmed malicious, an attacker could be using MSIExec to download - or communicate with external servers, potentially leading to data exfiltration, - command and control (C2) communication, or further malware deployment. +description: The following analytic has been deprecated. + The following analytic detects MSIExec making network connections over + ports 443 or 80. This behavior is identified by correlating process creation events + from Endpoint Detection and Response (EDR) agents with network traffic logs. Typically, + MSIExec does not perform network communication to the internet, making this activity + unusual and potentially indicative of malicious behavior. If confirmed malicious, + an attacker could be using MSIExec to download or communicate with external servers, + potentially leading to data exfiltration, command and control (C2) communication, + or further malware deployment. data_source: - Sysmon EventID 1 AND Sysmon EventID 3 search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes diff --git a/detections/deprecated/windows_network_share_interaction_with_net.yml b/detections/deprecated/windows_network_share_interaction_with_net.yml index 29047d8992..fea71519c1 100644 --- a/detections/deprecated/windows_network_share_interaction_with_net.yml +++ b/detections/deprecated/windows_network_share_interaction_with_net.yml @@ -7,13 +7,13 @@ status: deprecated type: TTP data_source: - Sysmon EventID 1 -description: The following analytic has been deprecated. This analytic detects network - share discovery and collection activities performed on Windows systems using the - Net command. Attackers often use network share discovery to identify accessible - shared resources within a network, which can be a precursor to privilege escalation - or data exfiltration. By monitoring Windows Event Logs for the usage of the Net - command to list and interact with network shares, this detection helps identify - potential reconnaissance and collection activities. +description: The following analytic has been deprecated. + This analytic detects network share discovery and collection activities + performed on Windows systems using the Net command. Attackers often use network + share discovery to identify accessible shared resources within a network, which + can be a precursor to privilege escalation or data exfiltration. By monitoring Windows + Event Logs for the usage of the Net command to list and interact with network shares, + this detection helps identify potential reconnaissance and collection activities. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.user_category) as user_category values(Processes.user_bunit) as user_bunit FROM datamodel=Endpoint.Processes WHERE `process_net` BY Processes.user diff --git a/detections/deprecated/windows_office_product_spawning_msdt.yml b/detections/deprecated/windows_office_product_spawning_msdt.yml index 88be1f1298..9415352231 100644 --- a/detections/deprecated/windows_office_product_spawning_msdt.yml +++ b/detections/deprecated/windows_office_product_spawning_msdt.yml @@ -1,7 +1,7 @@ name: Windows Office Product Spawning MSDT id: 127eba64-c981-40bf-8589-1830638864a7 -version: 9 -date: '2025-01-24' +version: 11 +date: '2025-02-10' author: Michael Haag, Teoderick Contreras, Splunk status: deprecated type: TTP @@ -80,7 +80,6 @@ tags: cve: - CVE-2022-30190 mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/windows_query_registry_reg_save.yml b/detections/deprecated/windows_query_registry_reg_save.yml index f44d4b8617..291c0cf7a0 100644 --- a/detections/deprecated/windows_query_registry_reg_save.yml +++ b/detections/deprecated/windows_query_registry_reg_save.yml @@ -5,14 +5,14 @@ date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated type: Hunting -description: The following analytic has been deprecated. The following analytic detects - the execution of the reg.exe process with the "save" parameter. This detection leverages - data from Endpoint Detection and Response (EDR) agents, focusing on process execution - logs and command-line arguments. This activity is significant because threat actors - often use the "reg save" command to dump credentials or test registry modification - capabilities on compromised hosts. If confirmed malicious, this behavior could allow - attackers to escalate privileges, persist in the environment, or access sensitive - information stored in the registry. +description: The following analytic has been deprecated. + The following analytic detects the execution of the reg.exe process with + the "save" parameter. This detection leverages data from Endpoint Detection and + Response (EDR) agents, focusing on process execution logs and command-line arguments. + This activity is significant because threat actors often use the "reg save" command + to dump credentials or test registry modification capabilities on compromised hosts. + If confirmed malicious, this behavior could allow attackers to escalate privileges, + persist in the environment, or access sensitive information stored in the registry. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/windows_valid_account_with_never_expires_password.yml b/detections/deprecated/windows_valid_account_with_never_expires_password.yml index 6bd2c46133..01b416d1d5 100644 --- a/detections/deprecated/windows_valid_account_with_never_expires_password.yml +++ b/detections/deprecated/windows_valid_account_with_never_expires_password.yml @@ -5,14 +5,15 @@ date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated type: TTP -description: The following analytic has been deprecated. The following analytic detects - the use of net.exe to update user account policies to set passwords as non-expiring. - It leverages data from Endpoint Detection and Response (EDR) agents, focusing on - command-line executions involving "/maxpwage:unlimited". This activity is significant - as it can indicate an attempt to maintain persistence, escalate privileges, evade - defenses, or facilitate lateral movement. If confirmed malicious, this behavior - could allow an attacker to maintain long-term access to compromised accounts, potentially - leading to further exploitation and unauthorized access to sensitive information. +description: The following analytic has been deprecated. + The following analytic detects the use of net.exe to update user account + policies to set passwords as non-expiring. It leverages data from Endpoint Detection + and Response (EDR) agents, focusing on command-line executions involving "/maxpwage:unlimited". + This activity is significant as it can indicate an attempt to maintain persistence, + escalate privileges, evade defenses, or facilitate lateral movement. If confirmed + malicious, this behavior could allow an attacker to maintain long-term access to + compromised accounts, potentially leading to further exploitation and unauthorized + access to sensitive information. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/winword_spawning_cmd.yml b/detections/deprecated/winword_spawning_cmd.yml index f16575033c..2d65e01f22 100644 --- a/detections/deprecated/winword_spawning_cmd.yml +++ b/detections/deprecated/winword_spawning_cmd.yml @@ -1,7 +1,7 @@ name: Winword Spawning Cmd id: 6fcbaedc-a37b-11eb-956b-acde48001122 -version: 7 -date: '2025-01-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -73,7 +73,6 @@ tags: - DarkCrystal RAT asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/winword_spawning_powershell.yml b/detections/deprecated/winword_spawning_powershell.yml index 50d598f95b..4164d64cf7 100644 --- a/detections/deprecated/winword_spawning_powershell.yml +++ b/detections/deprecated/winword_spawning_powershell.yml @@ -1,7 +1,7 @@ name: Winword Spawning PowerShell id: b2c950b8-9be2-11eb-8658-acde48001122 -version: 7 -date: '2025-01-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -76,7 +76,6 @@ tags: - DarkCrystal RAT asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/winword_spawning_windows_script_host.yml b/detections/deprecated/winword_spawning_windows_script_host.yml index b1d17ca5a5..47feee0635 100644 --- a/detections/deprecated/winword_spawning_windows_script_host.yml +++ b/detections/deprecated/winword_spawning_windows_script_host.yml @@ -1,7 +1,7 @@ name: Winword Spawning Windows Script Host id: 637e1b5c-9be1-11eb-9c32-acde48001122 -version: 6 -date: '2025-01-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -70,7 +70,6 @@ tags: - CVE-2023-21716 Word RTF Heap Corruption asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/endpoint/7zip_commandline_to_smb_share_path.yml b/detections/endpoint/7zip_commandline_to_smb_share_path.yml index 01c78be576..052abeb87b 100644 --- a/detections/endpoint/7zip_commandline_to_smb_share_path.yml +++ b/detections/endpoint/7zip_commandline_to_smb_share_path.yml @@ -1,7 +1,7 @@ name: 7zip CommandLine To SMB Share Path id: 01d29b48-ff6f-11eb-b81e-acde48001123 -version: 5 -date: '2025-01-21' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -43,7 +43,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1560.001 - - T1560 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/access_lsass_memory_for_dump_creation.yml b/detections/endpoint/access_lsass_memory_for_dump_creation.yml index ad6103c9b0..0f261b491b 100644 --- a/detections/endpoint/access_lsass_memory_for_dump_creation.yml +++ b/detections/endpoint/access_lsass_memory_for_dump_creation.yml @@ -1,7 +1,7 @@ name: Access LSASS Memory for Dump Creation id: fb4c31b0-13e8-4155-8aa5-24de4b8d6717 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Windows mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/active_setup_registry_autostart.yml b/detections/endpoint/active_setup_registry_autostart.yml index 6f4e0d1d4d..6ca39da2a4 100644 --- a/detections/endpoint/active_setup_registry_autostart.yml +++ b/detections/endpoint/active_setup_registry_autostart.yml @@ -1,7 +1,7 @@ name: Active Setup Registry Autostart id: f64579c0-203f-11ec-abcc-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Steven Dick, Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.014 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/add_defaultuser_and_password_in_registry.yml b/detections/endpoint/add_defaultuser_and_password_in_registry.yml index cd0c7eb48c..968de4b132 100644 --- a/detections/endpoint/add_defaultuser_and_password_in_registry.yml +++ b/detections/endpoint/add_defaultuser_and_password_in_registry.yml @@ -1,7 +1,7 @@ name: Add DefaultUser And Password In Registry id: d4a3eb62-0f1e-11ec-a971-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: Anomaly @@ -59,7 +59,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.002 - - T1552 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/add_or_set_windows_defender_exclusion.yml b/detections/endpoint/add_or_set_windows_defender_exclusion.yml index cf78828ce7..ca4975ede6 100644 --- a/detections/endpoint/add_or_set_windows_defender_exclusion.yml +++ b/detections/endpoint/add_or_set_windows_defender_exclusion.yml @@ -1,7 +1,7 @@ name: Add or Set Windows Defender Exclusion id: 773b66fe-4dd9-11ec-8289-acde48001122 -version: '6' -date: '2024-12-17' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -77,7 +77,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/adsisearcher_account_discovery.yml b/detections/endpoint/adsisearcher_account_discovery.yml index 65286be5b8..67241b0279 100644 --- a/detections/endpoint/adsisearcher_account_discovery.yml +++ b/detections/endpoint/adsisearcher_account_discovery.yml @@ -1,7 +1,7 @@ name: AdsiSearcher Account Discovery id: de7fcadc-04f3-11ec-a241-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml index 0a86ed9fd9..2e11a3aa86 100644 --- a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml +++ b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml @@ -1,7 +1,7 @@ name: Allow File And Printing Sharing In Firewall id: ce27646e-d411-11eb-8a00-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -70,7 +70,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.007 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml index 6b7f561f20..8aa114f36a 100644 --- a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml +++ b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml @@ -1,7 +1,7 @@ name: Allow Inbound Traffic By Firewall Rule Registry id: 0a46537c-be02-11eb-92ca-acde48001122 -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.001 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml b/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml index 677ec6f051..bf2fda0d4b 100644 --- a/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml +++ b/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml @@ -1,7 +1,7 @@ name: Allow Inbound Traffic In Firewall Rule id: a5d85486-b89c-11eb-8267-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.001 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/allow_network_discovery_in_firewall.yml b/detections/endpoint/allow_network_discovery_in_firewall.yml index 1334af8f48..1163a4d168 100644 --- a/detections/endpoint/allow_network_discovery_in_firewall.yml +++ b/detections/endpoint/allow_network_discovery_in_firewall.yml @@ -1,7 +1,7 @@ name: Allow Network Discovery In Firewall id: ccd6a38c-d40b-11eb-85a5-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.007 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/anomalous_usage_of_7zip.yml b/detections/endpoint/anomalous_usage_of_7zip.yml index 952bab98c5..32a9f2d25c 100644 --- a/detections/endpoint/anomalous_usage_of_7zip.yml +++ b/detections/endpoint/anomalous_usage_of_7zip.yml @@ -1,7 +1,7 @@ name: Anomalous usage of 7zip id: 9364ee8e-a39a-11eb-8f1d-acde48001122 -version: 6 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Teoderick Contreras, Splunk status: production type: Anomaly @@ -77,7 +77,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1560.001 - - T1560 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/any_powershell_downloadfile.yml b/detections/endpoint/any_powershell_downloadfile.yml index 74049ff9cb..65a6733058 100644 --- a/detections/endpoint/any_powershell_downloadfile.yml +++ b/detections/endpoint/any_powershell_downloadfile.yml @@ -1,7 +1,7 @@ name: Any Powershell DownloadFile id: 1a93b7ea-7af7-11eb-adb5-acde48001122 -version: 9 -date: '2025-01-27' +version: 11 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -87,7 +87,6 @@ tags: cve: - CVE-2021-44228 mitre_attack_id: - - T1059 - T1059.001 - T1105 product: @@ -98,6 +97,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/any_powershell_downloadstring.yml b/detections/endpoint/any_powershell_downloadstring.yml index 3a5fdced6f..7f516361ff 100644 --- a/detections/endpoint/any_powershell_downloadstring.yml +++ b/detections/endpoint/any_powershell_downloadstring.yml @@ -1,7 +1,7 @@ name: Any Powershell DownloadString id: 4d015ef2-7adf-11eb-95da-acde48001122 -version: 7 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -83,7 +83,6 @@ tags: - Phemedrone Stealer asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 - T1105 product: diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index 13d06f14d7..a983aeb31d 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -1,7 +1,7 @@ name: Attacker Tools On Endpoint id: a51bfe1a-94f0-48cc-b4e4-16a110145893 -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -73,9 +73,8 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1036.005 - - T1036 - T1003 + - T1036.005 - T1595 product: - Splunk Enterprise diff --git a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml index e23a285c6c..360d6c472d 100644 --- a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml +++ b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml @@ -1,7 +1,7 @@ name: Attempt To Add Certificate To Untrusted Store id: 6bc5243e-ef36-45dc-9b12-f4a6be131159 -version: 11 -date: '2024-11-13' +version: 13 +date: '2025-02-10' author: Patrick Bareiss, Rico Valdez, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1553.004 - - T1553 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/auto_admin_logon_registry_entry.yml b/detections/endpoint/auto_admin_logon_registry_entry.yml index ab26897ba0..8161fcdca6 100644 --- a/detections/endpoint/auto_admin_logon_registry_entry.yml +++ b/detections/endpoint/auto_admin_logon_registry_entry.yml @@ -1,7 +1,7 @@ name: Auto Admin Logon Registry Entry id: 1379d2b8-0f18-11ec-8ca3-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.002 - - T1552 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/batch_file_write_to_system32.yml b/detections/endpoint/batch_file_write_to_system32.yml index b7fa5f29ff..0d3a9702cd 100644 --- a/detections/endpoint/batch_file_write_to_system32.yml +++ b/detections/endpoint/batch_file_write_to_system32.yml @@ -1,7 +1,7 @@ name: Batch File Write to System32 id: 503d17cb-9eab-4cf8-a20e-01d5c6987ae3 -version: 8 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Steven Dick, Michael Haag, Rico Valdez, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1204 - T1204.002 product: - Splunk Enterprise diff --git a/detections/endpoint/bcdedit_failure_recovery_modification.yml b/detections/endpoint/bcdedit_failure_recovery_modification.yml index 29bdb7ba33..1425eee424 100644 --- a/detections/endpoint/bcdedit_failure_recovery_modification.yml +++ b/detections/endpoint/bcdedit_failure_recovery_modification.yml @@ -1,6 +1,6 @@ name: BCDEdit Failure Recovery Modification id: 809b31d2-5462-11eb-ae93-0242ac130002 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/bits_job_persistence.yml b/detections/endpoint/bits_job_persistence.yml index b115098430..eee12eeb44 100644 --- a/detections/endpoint/bits_job_persistence.yml +++ b/detections/endpoint/bits_job_persistence.yml @@ -1,6 +1,6 @@ name: BITS Job Persistence id: e97a5ffe-90bf-11eb-928a-acde48001122 -version: 6 +version: 7 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/bitsadmin_download_file.yml b/detections/endpoint/bitsadmin_download_file.yml index da8e3522bb..bdab9e207a 100644 --- a/detections/endpoint/bitsadmin_download_file.yml +++ b/detections/endpoint/bitsadmin_download_file.yml @@ -1,6 +1,6 @@ name: BITSAdmin Download File id: 80630ff4-8e4c-11eb-aab5-acde48001122 -version: 7 +version: 8 date: '2024-11-13' author: Michael Haag, Sittikorn S status: production diff --git a/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml b/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml index 7e3407c516..b6d19b0b39 100644 --- a/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml +++ b/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml @@ -1,6 +1,6 @@ name: CertUtil Download With URLCache and Split Arguments id: 415b4306-8bfb-11eb-85c4-acde48001122 -version: 9 +version: 10 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml b/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml index 7c6a453b69..97a0c24ba9 100644 --- a/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml +++ b/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml @@ -1,6 +1,6 @@ name: CertUtil Download With VerifyCtl and Split Arguments id: 801ad9e4-8bfb-11eb-8b31-acde48001122 -version: 9 +version: 10 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/certutil_exe_certificate_extraction.yml b/detections/endpoint/certutil_exe_certificate_extraction.yml index 34b29335c5..6dafec9ff9 100644 --- a/detections/endpoint/certutil_exe_certificate_extraction.yml +++ b/detections/endpoint/certutil_exe_certificate_extraction.yml @@ -1,6 +1,6 @@ name: Certutil exe certificate extraction id: 337a46be-600f-11eb-ae93-0242ac130002 -version: 7 +version: 8 date: '2024-12-10' author: Rod Soto, Splunk status: production diff --git a/detections/endpoint/certutil_with_decode_argument.yml b/detections/endpoint/certutil_with_decode_argument.yml index 0fc4d9b902..f00b0f4387 100644 --- a/detections/endpoint/certutil_with_decode_argument.yml +++ b/detections/endpoint/certutil_with_decode_argument.yml @@ -1,6 +1,6 @@ name: CertUtil With Decode Argument id: bfe94226-8c10-11eb-a4b3-acde48001122 -version: 6 +version: 7 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/check_elevated_cmd_using_whoami.yml b/detections/endpoint/check_elevated_cmd_using_whoami.yml index abb19e8ac8..b5f5648875 100644 --- a/detections/endpoint/check_elevated_cmd_using_whoami.yml +++ b/detections/endpoint/check_elevated_cmd_using_whoami.yml @@ -1,6 +1,6 @@ name: Check Elevated CMD using whoami id: a9079b18-1633-11ec-859c-acde48001122 -version: 4 +version: 5 date: '2024-11-13' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml b/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml index ee6d5594e2..82a73a420c 100644 --- a/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml +++ b/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml @@ -1,7 +1,7 @@ name: Clear Unallocated Sector Using Cipher App id: cd80a6ac-c9d9-11eb-8839-acde48001122 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -72,7 +72,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1070.004 - - T1070 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/clop_common_exec_parameter.yml b/detections/endpoint/clop_common_exec_parameter.yml index 0be756484b..3618dec57d 100644 --- a/detections/endpoint/clop_common_exec_parameter.yml +++ b/detections/endpoint/clop_common_exec_parameter.yml @@ -1,6 +1,6 @@ name: Clop Common Exec Parameter id: 5a8a2a72-8322-11eb-9ee9-acde48001122 -version: 7 +version: 8 date: '2024-12-10' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/cmd_carry_out_string_command_parameter.yml b/detections/endpoint/cmd_carry_out_string_command_parameter.yml index ead8c6acad..f2545358d1 100644 --- a/detections/endpoint/cmd_carry_out_string_command_parameter.yml +++ b/detections/endpoint/cmd_carry_out_string_command_parameter.yml @@ -1,7 +1,7 @@ name: CMD Carry Out String Command Parameter id: 54a6ed00-3256-11ec-b031-acde48001122 -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Teoderick Contreras, Bhavin Patel, Splunk status: production type: Hunting @@ -64,7 +64,6 @@ tags: - CVE-2021-44228 mitre_attack_id: - T1059.003 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/cmd_echo_pipe___escalation.yml b/detections/endpoint/cmd_echo_pipe___escalation.yml index 618a7f1670..c1b77e4c5b 100644 --- a/detections/endpoint/cmd_echo_pipe___escalation.yml +++ b/detections/endpoint/cmd_echo_pipe___escalation.yml @@ -1,7 +1,7 @@ name: CMD Echo Pipe - Escalation id: eb277ba0-b96b-11eb-b00e-acde48001122 -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -75,10 +75,8 @@ tags: - BlackByte Ransomware asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.003 - T1543.003 - - T1543 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml b/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml index d71bc60a38..deb0daab75 100644 --- a/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml +++ b/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml @@ -1,7 +1,7 @@ name: CMLUA Or CMSTPLUA UAC Bypass id: f87b5062-b405-11eb-a889-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - ValleyRAT asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.003 product: - Splunk Enterprise diff --git a/detections/endpoint/common_ransomware_extensions.yml b/detections/endpoint/common_ransomware_extensions.yml index 281a998ed1..b7dbef7eb3 100644 --- a/detections/endpoint/common_ransomware_extensions.yml +++ b/detections/endpoint/common_ransomware_extensions.yml @@ -1,6 +1,6 @@ name: Common Ransomware Extensions id: a9e5c5db-db11-43ca-86a8-c852d1b2c0ec -version: 10 +version: 11 date: '2025-01-07' author: David Dorsey, Michael Haag, Splunk, Steven Dick status: production diff --git a/detections/endpoint/conti_common_exec_parameter.yml b/detections/endpoint/conti_common_exec_parameter.yml index fe3227dd29..68ddb073f8 100644 --- a/detections/endpoint/conti_common_exec_parameter.yml +++ b/detections/endpoint/conti_common_exec_parameter.yml @@ -1,6 +1,6 @@ name: Conti Common Exec parameter id: 624919bc-c382-11eb-adcc-acde48001122 -version: 6 +version: 7 date: '2024-12-10' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/control_loading_from_world_writable_directory.yml b/detections/endpoint/control_loading_from_world_writable_directory.yml index 0b02258a47..34c0fe2491 100644 --- a/detections/endpoint/control_loading_from_world_writable_directory.yml +++ b/detections/endpoint/control_loading_from_world_writable_directory.yml @@ -1,7 +1,7 @@ name: Control Loading from World Writable Directory id: 10423ac4-10c9-11ec-8dc4-acde48001122 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -80,7 +80,6 @@ tags: cve: - CVE-2021-40444 mitre_attack_id: - - T1218 - T1218.002 product: - Splunk Enterprise diff --git a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml index c90a12c6e9..43cc11f1f7 100644 --- a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml +++ b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml @@ -1,7 +1,7 @@ name: Create or delete windows shares using net exe id: 743a322c-9a68-4a0f-9c17-85d9cce2a27c -version: 10 -date: '2024-12-12' +version: 12 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -76,7 +76,6 @@ tags: - DarkGate Malware asset_type: Endpoint mitre_attack_id: - - T1070 - T1070.005 product: - Splunk Enterprise diff --git a/detections/endpoint/create_remote_thread_into_lsass.yml b/detections/endpoint/create_remote_thread_into_lsass.yml index daf76493ed..fbc0310759 100644 --- a/detections/endpoint/create_remote_thread_into_lsass.yml +++ b/detections/endpoint/create_remote_thread_into_lsass.yml @@ -1,7 +1,7 @@ name: Create Remote Thread into LSASS id: 67d4dbef-9564-4699-8da8-03a151529edc -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: asset_type: Windows mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml b/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml index ee0bb861f3..dcd2a4391c 100644 --- a/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml +++ b/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml @@ -1,7 +1,7 @@ name: Creation of lsass Dump with Taskmgr id: b2fbe95a-9c62-4c12-8a29-24b97e84c0cd -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: asset_type: Windows mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/creation_of_shadow_copy.yml b/detections/endpoint/creation_of_shadow_copy.yml index 49b3059565..ce5b148d77 100644 --- a/detections/endpoint/creation_of_shadow_copy.yml +++ b/detections/endpoint/creation_of_shadow_copy.yml @@ -1,7 +1,7 @@ name: Creation of Shadow Copy id: eb120f5f-b879-4a63-97c1-93352b5df844 -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -74,7 +74,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.003 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml index 9571ea9236..78b7c0d9dd 100644 --- a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml +++ b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml @@ -1,7 +1,7 @@ name: Creation of Shadow Copy with wmic and powershell id: 2ed8b538-d284-449a-be1d-82ad1dbd186b -version: 8 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.003 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml index 69aa5fe62b..a443947f7e 100644 --- a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml +++ b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml @@ -1,7 +1,7 @@ name: Credential Dumping via Copy Command from Shadow Copy id: d8c406fe-23d2-45f3-a983-1abe7b83ff3b -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -70,7 +70,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.003 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml index ed7082bfee..ac524c6b29 100644 --- a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml +++ b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml @@ -1,7 +1,7 @@ name: Credential Dumping via Symlink to Shadow Copy id: c5eac648-fae0-4263-91a6-773df1f4c903 -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.003 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/csc_net_on_the_fly_compilation.yml b/detections/endpoint/csc_net_on_the_fly_compilation.yml index 523efe64be..39211a947c 100644 --- a/detections/endpoint/csc_net_on_the_fly_compilation.yml +++ b/detections/endpoint/csc_net_on_the_fly_compilation.yml @@ -1,7 +1,7 @@ name: CSC Net On The Fly Compilation id: ea73128a-43ab-11ec-9753-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -45,7 +45,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1027.004 - - T1027 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/deleting_shadow_copies.yml b/detections/endpoint/deleting_shadow_copies.yml index 43b2d363b6..89b5ebed9b 100644 --- a/detections/endpoint/deleting_shadow_copies.yml +++ b/detections/endpoint/deleting_shadow_copies.yml @@ -1,6 +1,6 @@ name: Deleting Shadow Copies id: b89919ed-ee5f-492c-b139-95dbb162039e -version: 9 +version: 10 date: '2024-12-10' author: David Dorsey, Splunk status: production diff --git a/detections/endpoint/detect_azurehound_command_line_arguments.yml b/detections/endpoint/detect_azurehound_command_line_arguments.yml index a20929459c..df661b9c10 100644 --- a/detections/endpoint/detect_azurehound_command_line_arguments.yml +++ b/detections/endpoint/detect_azurehound_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Detect AzureHound Command-Line Arguments id: 26f02e96-c300-11eb-b611-acde48001122 -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -72,13 +72,11 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1087.002 - T1069.001 - - T1482 - - T1087.001 - - T1087 - T1069.002 - - T1069 + - T1087.001 + - T1087.002 + - T1482 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_azurehound_file_modifications.yml b/detections/endpoint/detect_azurehound_file_modifications.yml index 71aee3b142..af89e009cd 100644 --- a/detections/endpoint/detect_azurehound_file_modifications.yml +++ b/detections/endpoint/detect_azurehound_file_modifications.yml @@ -1,7 +1,7 @@ name: Detect AzureHound File Modifications id: 1c34549e-c31b-11eb-996b-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -62,13 +62,11 @@ tags: - Windows Discovery Techniques asset_type: Endpoint mitre_attack_id: - - T1087.002 - T1069.001 - - T1482 - - T1087.001 - - T1087 - T1069.002 - - T1069 + - T1087.001 + - T1087.002 + - T1482 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_certify_with_powershell_script_block_logging.yml b/detections/endpoint/detect_certify_with_powershell_script_block_logging.yml index 38e25e1fcc..5b22224e3d 100644 --- a/detections/endpoint/detect_certify_with_powershell_script_block_logging.yml +++ b/detections/endpoint/detect_certify_with_powershell_script_block_logging.yml @@ -1,7 +1,7 @@ name: Detect Certify With PowerShell Script Block Logging id: f533ca6c-9440-4686-80cb-7f294c07812a -version: 4 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -62,9 +62,8 @@ tags: - Malicious PowerShell asset_type: Endpoint mitre_attack_id: - - T1649 - - T1059 - T1059.001 + - T1649 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_certipy_file_modifications.yml b/detections/endpoint/detect_certipy_file_modifications.yml index 932c36dce7..48a6a3129b 100644 --- a/detections/endpoint/detect_certipy_file_modifications.yml +++ b/detections/endpoint/detect_certipy_file_modifications.yml @@ -1,6 +1,6 @@ name: Detect Certipy File Modifications id: 7e3df743-b1d8-4631-8fa8-bd5819688876 -version: 4 +version: 5 date: '2024-11-13' author: Steven Dick status: production diff --git a/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml b/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml index 9f13d8ec5e..5ba7b43a6d 100644 --- a/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml +++ b/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml @@ -1,7 +1,7 @@ name: Detect Copy of ShadowCopy with Script Block Logging id: 9251299c-ea5b-11eb-a8de-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - CVE-2021-36934 mitre_attack_id: - T1003.002 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_credential_dumping_through_lsass_access.yml b/detections/endpoint/detect_credential_dumping_through_lsass_access.yml index cbca225e2f..d407bbd637 100644 --- a/detections/endpoint/detect_credential_dumping_through_lsass_access.yml +++ b/detections/endpoint/detect_credential_dumping_through_lsass_access.yml @@ -1,7 +1,7 @@ name: Detect Credential Dumping through LSASS access id: 2c365e57-4414-4540-8dc0-73ab10729996 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Windows mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml b/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml index 7e5e09b90a..4c5e71523a 100644 --- a/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml +++ b/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml @@ -1,7 +1,7 @@ name: Detect Empire with PowerShell Script Block Logging id: bc1dc6b8-c954-11eb-bade-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml b/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml index c159f44c23..e81a797125 100644 --- a/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml +++ b/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml @@ -1,7 +1,7 @@ name: Detect Excessive Account Lockouts From Endpoint id: c026e3dd-7e18-4abb-8f41-929e836efe74 -version: 11 -date: '2024-11-13' +version: 12 +date: '2025-02-10' author: David Dorsey, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: - Active Directory Password Spraying asset_type: Windows mitre_attack_id: - - T1078 - T1078.002 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_excessive_user_account_lockouts.yml b/detections/endpoint/detect_excessive_user_account_lockouts.yml index e80d4200a3..6eab6eb5d8 100644 --- a/detections/endpoint/detect_excessive_user_account_lockouts.yml +++ b/detections/endpoint/detect_excessive_user_account_lockouts.yml @@ -1,7 +1,7 @@ name: Detect Excessive User Account Lockouts id: 95a7f9a5-6096-437e-a19e-86f42ac609bd -version: 8 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: David Dorsey, Splunk status: production type: Anomaly @@ -51,7 +51,6 @@ tags: - Active Directory Password Spraying asset_type: Windows mitre_attack_id: - - T1078 - T1078.003 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_exchange_web_shell.yml b/detections/endpoint/detect_exchange_web_shell.yml index 6301bf3efc..11b24212d0 100644 --- a/detections/endpoint/detect_exchange_web_shell.yml +++ b/detections/endpoint/detect_exchange_web_shell.yml @@ -1,7 +1,7 @@ name: Detect Exchange Web Shell id: 8c14eeee-2af1-4a4b-bda8-228da0f4862a -version: 9 -date: '2024-12-12' +version: 10 +date: '2025-02-10' author: Michael Haag, Shannon Davis, David Dorsey, Splunk status: production type: TTP @@ -16,18 +16,16 @@ description: The following analytic identifies the creation of suspicious .aspx data_source: - Sysmon EventID 1 AND Sysmon EventID 11 search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - where Processes.process_name=System by _time span=1h Processes.process_guid Processes.process_name Processes.process - Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| join process_guid, _time - [| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\HttpProxy\\owa\\auth\\*", - "*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*") Filesystem.file_name - IN( "*.aspx", "*.ashx") by _time span=1h Filesystem.process_guid Filesystem.user Filesystem.dest Filesystem.file_create_time - Filesystem.file_name Filesystem.file_path - | `drop_dm_object_name(Filesystem)` ] - | dedup file_create_time - | table _time dest user file_create_time file_name file_path process_name process process_guid | `detect_exchange_web_shell_filter`' + where Processes.process_name=System by _time span=1h Processes.process_guid Processes.process_name + Processes.process Processes.dest Processes.user | `drop_dm_object_name(Processes)` + | join process_guid, _time [| tstats `security_content_summariesonly` count min(_time) + as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path + IN ("*\\HttpProxy\\owa\\auth\\*", "*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*") + Filesystem.file_name IN( "*.aspx", "*.ashx") by _time span=1h Filesystem.process_guid + Filesystem.user Filesystem.dest Filesystem.file_create_time Filesystem.file_name + Filesystem.file_path | `drop_dm_object_name(Filesystem)` ] | dedup file_create_time + | table _time dest user file_create_time file_name file_path process_name process + process_guid | `detect_exchange_web_shell_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` @@ -78,10 +76,9 @@ tags: - BlackByte Ransomware asset_type: Endpoint mitre_attack_id: - - T1505 - - T1505.003 - - T1190 - T1133 + - T1190 + - T1505.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_html_help_renamed.yml b/detections/endpoint/detect_html_help_renamed.yml index 5ad0885f0f..a772c50bad 100644 --- a/detections/endpoint/detect_html_help_renamed.yml +++ b/detections/endpoint/detect_html_help_renamed.yml @@ -1,7 +1,7 @@ name: Detect HTML Help Renamed id: 62fed254-513b-460e-953d-79771493a9f3 -version: 8 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -44,7 +44,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.001 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_html_help_spawn_child_process.yml b/detections/endpoint/detect_html_help_spawn_child_process.yml index 05aed6328e..e4cf5469a5 100644 --- a/detections/endpoint/detect_html_help_spawn_child_process.yml +++ b/detections/endpoint/detect_html_help_spawn_child_process.yml @@ -1,7 +1,7 @@ name: Detect HTML Help Spawn Child Process id: 723716de-ee55-4cd4-9759-c44e7e55ba4b -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -78,7 +78,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.001 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_html_help_url_in_command_line.yml b/detections/endpoint/detect_html_help_url_in_command_line.yml index d72c7f64a1..4e07b994f9 100644 --- a/detections/endpoint/detect_html_help_url_in_command_line.yml +++ b/detections/endpoint/detect_html_help_url_in_command_line.yml @@ -1,7 +1,7 @@ name: Detect HTML Help URL in Command Line id: 8c5835b9-39d9-438b-817c-95f14c69a31e -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -77,7 +77,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.001 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml b/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml index 335817cd7b..3ab1a666ab 100644 --- a/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml +++ b/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml @@ -1,7 +1,7 @@ name: Detect HTML Help Using InfoTech Storage Handlers id: 0b2eefa5-5508-450d-b970-3dd2fb761aec -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -75,7 +75,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.001 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml b/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml index 0960910cc8..d3616fae42 100644 --- a/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml +++ b/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml @@ -1,6 +1,6 @@ name: Detect Mimikatz With PowerShell Script Block Logging id: 8148c29c-c952-11eb-9255-acde48001122 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/detect_mshta_inline_hta_execution.yml b/detections/endpoint/detect_mshta_inline_hta_execution.yml index 09c4f17867..cc64c91a1d 100644 --- a/detections/endpoint/detect_mshta_inline_hta_execution.yml +++ b/detections/endpoint/detect_mshta_inline_hta_execution.yml @@ -1,7 +1,7 @@ name: Detect mshta inline hta execution id: a0873b32-5b68-11eb-ae93-0242ac130002 -version: 12 -date: '2024-12-10' +version: 14 +date: '2025-02-10' author: Bhavin Patel, Michael Haag, Splunk status: production type: TTP @@ -77,7 +77,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.005 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_mshta_renamed.yml b/detections/endpoint/detect_mshta_renamed.yml index 229050f266..8edd8c5256 100644 --- a/detections/endpoint/detect_mshta_renamed.yml +++ b/detections/endpoint/detect_mshta_renamed.yml @@ -1,7 +1,7 @@ name: Detect mshta renamed id: 8f45fcf0-5b68-11eb-ae93-0242ac130002 -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -42,7 +42,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.005 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_mshta_url_in_command_line.yml b/detections/endpoint/detect_mshta_url_in_command_line.yml index 7a9bc24261..c33a2bd047 100644 --- a/detections/endpoint/detect_mshta_url_in_command_line.yml +++ b/detections/endpoint/detect_mshta_url_in_command_line.yml @@ -1,7 +1,7 @@ name: Detect MSHTA Url in Command Line id: 9b3af1e6-5b68-11eb-ae93-0242ac130002 -version: 8 -date: '2024-12-10' +version: 10 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -77,7 +77,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.005 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_new_local_admin_account.yml b/detections/endpoint/detect_new_local_admin_account.yml index f70320bd1c..e17eed841e 100644 --- a/detections/endpoint/detect_new_local_admin_account.yml +++ b/detections/endpoint/detect_new_local_admin_account.yml @@ -1,7 +1,7 @@ name: Detect New Local Admin account id: b25f6f62-0712-43c1-b203-083231ffd97d -version: 6 -date: '2024-12-12' +version: 7 +date: '2025-02-10' author: David Dorsey, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: asset_type: Windows mitre_attack_id: - T1136.001 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml b/detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml index 4e6934e5fc..95d80c9749 100644 --- a/detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml +++ b/detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml @@ -1,7 +1,7 @@ name: Detect Outlook exe writing a zip file id: a51bfe1a-94f0-4822-b1e4-16ae10145893 -version: 9 -date: '2024-12-10' +version: 10 +date: '2025-02-10' author: Bhavin Patel, Splunk status: experimental type: TTP @@ -55,7 +55,6 @@ tags: - Meduza Stealer asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_password_spray_attack_behavior_from_source.yml b/detections/endpoint/detect_password_spray_attack_behavior_from_source.yml index a3a18311fa..474fcdd7d7 100644 --- a/detections/endpoint/detect_password_spray_attack_behavior_from_source.yml +++ b/detections/endpoint/detect_password_spray_attack_behavior_from_source.yml @@ -1,7 +1,7 @@ name: Detect Password Spray Attack Behavior From Source id: b6391b15-e913-4c2c-8949-9eecc06efacc -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -68,7 +68,6 @@ tags: asset_type: Account mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_password_spray_attack_behavior_on_user.yml b/detections/endpoint/detect_password_spray_attack_behavior_on_user.yml index bd82127859..c584c6dae0 100644 --- a/detections/endpoint/detect_password_spray_attack_behavior_on_user.yml +++ b/detections/endpoint/detect_password_spray_attack_behavior_on_user.yml @@ -1,7 +1,7 @@ name: Detect Password Spray Attack Behavior On User id: a7539705-7183-4a12-9b6a-b6eef645a6d7 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Account mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml index f6f07579ae..7996dfb15e 100644 --- a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml +++ b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml @@ -1,7 +1,7 @@ name: Detect Path Interception By Creation Of program exe id: cbef820c-e1ff-407f-887f-0a9240a2d477 -version: 9 -date: '2024-11-13' +version: 11 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -72,7 +72,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.009 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml index 08ebbb0515..1b9df60d0d 100644 --- a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml +++ b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml @@ -1,7 +1,7 @@ name: Detect Prohibited Applications Spawning cmd exe id: dcfd6b40-42f9-469d-a433-2e53f7486664 -version: 10 -date: '2024-11-13' +version: 11 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: Hunting @@ -44,7 +44,6 @@ tags: - NOBELIUM Group asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.003 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_psexec_with_accepteula_flag.yml b/detections/endpoint/detect_psexec_with_accepteula_flag.yml index 6004101254..f1974ad052 100644 --- a/detections/endpoint/detect_psexec_with_accepteula_flag.yml +++ b/detections/endpoint/detect_psexec_with_accepteula_flag.yml @@ -1,7 +1,7 @@ name: Detect PsExec With accepteula Flag id: 27c3a83d-cada-47c6-9042-67baf19d2574 -version: 8 -date: '2024-11-13' +version: 10 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -83,7 +83,6 @@ tags: - Rhysida Ransomware asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.002 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_rclone_command_line_usage.yml b/detections/endpoint/detect_rclone_command_line_usage.yml index 31e5bc6329..a36e49cace 100644 --- a/detections/endpoint/detect_rclone_command_line_usage.yml +++ b/detections/endpoint/detect_rclone_command_line_usage.yml @@ -1,6 +1,6 @@ name: Detect RClone Command-Line Usage id: 32e0baea-b3f1-11eb-a2ce-acde48001122 -version: 6 +version: 7 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/detect_regasm_spawning_a_process.yml b/detections/endpoint/detect_regasm_spawning_a_process.yml index edd0e0652f..adc6c5a181 100644 --- a/detections/endpoint/detect_regasm_spawning_a_process.yml +++ b/detections/endpoint/detect_regasm_spawning_a_process.yml @@ -1,7 +1,7 @@ name: Detect Regasm Spawning a Process id: 72170ec5-f7d2-42f5-aefb-2b8be6aad15f -version: 8 -date: '2024-12-10' +version: 10 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -81,7 +81,6 @@ tags: - Snake Keylogger asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.009 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_regasm_with_network_connection.yml b/detections/endpoint/detect_regasm_with_network_connection.yml index 9b010fad35..803e1d2cc8 100644 --- a/detections/endpoint/detect_regasm_with_network_connection.yml +++ b/detections/endpoint/detect_regasm_with_network_connection.yml @@ -1,7 +1,7 @@ name: Detect Regasm with Network Connection id: 07921114-6db4-4e2e-ae58-3ea8a52ae93f -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - Handala Wiper asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.009 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml b/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml index 3431b74b40..a04e5c72a0 100644 --- a/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml +++ b/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Detect Regasm with no Command Line Arguments id: c3bc1430-04e7-4178-835f-047d8e6e97df -version: 7 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -75,7 +75,6 @@ tags: - Handala Wiper asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.009 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_regsvcs_spawning_a_process.yml b/detections/endpoint/detect_regsvcs_spawning_a_process.yml index 369fa49db9..72541a45bc 100644 --- a/detections/endpoint/detect_regsvcs_spawning_a_process.yml +++ b/detections/endpoint/detect_regsvcs_spawning_a_process.yml @@ -1,7 +1,7 @@ name: Detect Regsvcs Spawning a Process id: bc477b57-5c21-4ab6-9c33-668772e7f114 -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -76,7 +76,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.009 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_regsvcs_with_network_connection.yml b/detections/endpoint/detect_regsvcs_with_network_connection.yml index 43d8cd8f6f..160e0aad1e 100644 --- a/detections/endpoint/detect_regsvcs_with_network_connection.yml +++ b/detections/endpoint/detect_regsvcs_with_network_connection.yml @@ -1,7 +1,7 @@ name: Detect Regsvcs with Network Connection id: e3e7a1c0-f2b9-445c-8493-f30a63522d1a -version: 8 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.009 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml b/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml index c8dfa3767d..79f0ca5b7e 100644 --- a/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml +++ b/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Detect Regsvcs with No Command Line Arguments id: 6b74d578-a02e-4e94-a0d1-39440d0bf254 -version: 7 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.009 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_regsvr32_application_control_bypass.yml b/detections/endpoint/detect_regsvr32_application_control_bypass.yml index e2130893c1..a3df354b36 100644 --- a/detections/endpoint/detect_regsvr32_application_control_bypass.yml +++ b/detections/endpoint/detect_regsvr32_application_control_bypass.yml @@ -1,7 +1,7 @@ name: Detect Regsvr32 Application Control Bypass id: 070e9b80-6252-11eb-ae93-0242ac130002 -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -79,7 +79,6 @@ tags: - BlackByte Ransomware asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.010 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_remote_access_software_usage_file.yml b/detections/endpoint/detect_remote_access_software_usage_file.yml index a9d1005364..25292e24c2 100644 --- a/detections/endpoint/detect_remote_access_software_usage_file.yml +++ b/detections/endpoint/detect_remote_access_software_usage_file.yml @@ -1,6 +1,6 @@ name: Detect Remote Access Software Usage File id: 3bf5541a-6a45-4fdc-b01d-59b899fff961 -version: 5 +version: 6 date: '2024-11-13' author: Steven Dick status: production @@ -54,6 +54,10 @@ drilldown_searches: by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ +- name: Investigate files on $dest$ + search: '| from datamodel:Endpoint.Filesystem | search dest=$dest$ file_name=$file_name$' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ rba: message: A file for known a remote access software [$file_name$] was created on $dest$ by $user$. @@ -67,6 +71,8 @@ rba: threat_objects: - field: file_name type: file_name + - field: signature + type: signature tags: analytic_story: - Insider Threat @@ -74,6 +80,7 @@ tags: - Ransomware - Gozi Malware - CISA AA24-241A + - Remote Monitoring and Management Software asset_type: Endpoint mitre_attack_id: - T1219 diff --git a/detections/endpoint/detect_remote_access_software_usage_fileinfo.yml b/detections/endpoint/detect_remote_access_software_usage_fileinfo.yml index 8286572d72..b1a9ef4f84 100644 --- a/detections/endpoint/detect_remote_access_software_usage_fileinfo.yml +++ b/detections/endpoint/detect_remote_access_software_usage_fileinfo.yml @@ -1,6 +1,6 @@ name: Detect Remote Access Software Usage FileInfo id: ccad96d7-a48c-4f13-8b9c-9f6a31cba454 -version: 5 +version: 6 date: '2024-11-13' author: Steven Dick status: production @@ -47,6 +47,10 @@ drilldown_searches: | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ +- name: Investigate processes on $dest$ + search: '| from datamodel:Endpoint.Processes| search dest=$dest$ process_name=$process_name$' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ rba: message: A file attributes for known a remote access software [$process_name$] was detected on $dest$ @@ -54,15 +58,21 @@ rba: - field: dest type: system score: 25 + - field: user + type: user + score: 25 threat_objects: - field: process_name type: process_name + - field: signature + type: signature tags: analytic_story: - Insider Threat - Command And Control - Ransomware - Gozi Malware + - Remote Monitoring and Management Software asset_type: Endpoint mitre_attack_id: - T1219 diff --git a/detections/endpoint/detect_remote_access_software_usage_process.yml b/detections/endpoint/detect_remote_access_software_usage_process.yml index 8a5dfd6d64..e0417a4071 100644 --- a/detections/endpoint/detect_remote_access_software_usage_process.yml +++ b/detections/endpoint/detect_remote_access_software_usage_process.yml @@ -1,6 +1,6 @@ name: Detect Remote Access Software Usage Process id: ffd5e001-2e34-48f4-97a2-26dc4bb08178 -version: 5 +version: 6 date: '2024-11-13' author: Steven Dick status: production @@ -59,6 +59,10 @@ drilldown_searches: by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ +- name: Investigate processes on $dest$ + search: '| from datamodel:Endpoint.Processes| search dest=$dest$ process_name=$process_name$' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ rba: message: A process for a known remote access software $process_name$ was identified on $dest$. @@ -72,6 +76,8 @@ rba: threat_objects: - field: process_name type: process_name + - field: signature + type: signature tags: analytic_story: - Insider Threat @@ -79,6 +85,7 @@ tags: - Ransomware - Gozi Malware - CISA AA24-241A + - Remote Monitoring and Management Software asset_type: Endpoint mitre_attack_id: - T1219 diff --git a/detections/endpoint/detect_remote_access_software_usage_registry.yml b/detections/endpoint/detect_remote_access_software_usage_registry.yml index 93e927f108..a757b157c9 100644 --- a/detections/endpoint/detect_remote_access_software_usage_registry.yml +++ b/detections/endpoint/detect_remote_access_software_usage_registry.yml @@ -1,6 +1,6 @@ name: Detect Remote Access Software Usage Registry id: 33804986-25dd-43cf-bb6b-dc14956c7cbc -version: 2 +version: 3 date: '2025-01-10' author: Steven Dick status: production @@ -60,6 +60,7 @@ tags: - Ransomware - Gozi Malware - CISA AA24-241A + - Remote Monitoring and Management Software asset_type: Endpoint mitre_attack_id: - T1219 diff --git a/detections/endpoint/detect_renamed_7_zip.yml b/detections/endpoint/detect_renamed_7_zip.yml index e2a994e020..62309db2ab 100644 --- a/detections/endpoint/detect_renamed_7_zip.yml +++ b/detections/endpoint/detect_renamed_7_zip.yml @@ -1,7 +1,7 @@ name: Detect Renamed 7-Zip id: 4057291a-b8cf-11eb-95fe-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -43,7 +43,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1560.001 - - T1560 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_renamed_psexec.yml b/detections/endpoint/detect_renamed_psexec.yml index 3b2380accc..27479f9d15 100644 --- a/detections/endpoint/detect_renamed_psexec.yml +++ b/detections/endpoint/detect_renamed_psexec.yml @@ -1,7 +1,7 @@ name: Detect Renamed PSExec id: 683e6196-b8e8-11eb-9a79-acde48001122 -version: 10 -date: '2025-01-27' +version: 11 +date: '2025-02-10' author: Michael Haag, Splunk, Alex Oberkircher, Github Community status: production type: Hunting @@ -53,7 +53,6 @@ tags: - Rhysida Ransomware asset_type: Endpoint mitre_attack_id: - - T1569 - T1569.002 product: - Splunk Enterprise @@ -63,6 +62,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/detect_renamed_winrar.yml b/detections/endpoint/detect_renamed_winrar.yml index 43af74579c..5c146b775f 100644 --- a/detections/endpoint/detect_renamed_winrar.yml +++ b/detections/endpoint/detect_renamed_winrar.yml @@ -1,7 +1,7 @@ name: Detect Renamed WinRAR id: 1b7bfb2c-b8e6-11eb-99ac-acde48001122 -version: 8 -date: '2025-01-27' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -45,7 +45,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1560.001 - - T1560 product: - Splunk Enterprise - Splunk Enterprise Security @@ -54,6 +53,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/detect_rtlo_in_file_name.yml b/detections/endpoint/detect_rtlo_in_file_name.yml index 0754140915..5e65a0dda2 100644 --- a/detections/endpoint/detect_rtlo_in_file_name.yml +++ b/detections/endpoint/detect_rtlo_in_file_name.yml @@ -1,7 +1,7 @@ name: Detect RTLO In File Name id: 468b7e11-d362-43b8-b6ec-7a2d3b246678 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1036.002 - - T1036 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_rtlo_in_process.yml b/detections/endpoint/detect_rtlo_in_process.yml index f9af08e747..c9ee16ee83 100644 --- a/detections/endpoint/detect_rtlo_in_process.yml +++ b/detections/endpoint/detect_rtlo_in_process.yml @@ -1,7 +1,7 @@ name: Detect RTLO In Process id: 22ac27b4-7189-4a4f-9375-b9017c9620d7 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -72,7 +72,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1036.002 - - T1036 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml b/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml index 8774c0b8e9..710a02181c 100644 --- a/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml +++ b/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml @@ -1,7 +1,7 @@ name: Detect Rundll32 Application Control Bypass - advpack id: 4aefadfe-9abd-4bf8-b3fd-867e9ef95bf8 -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -77,7 +77,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml b/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml index 5870f0e87b..2ee5451c0e 100644 --- a/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml +++ b/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml @@ -1,7 +1,7 @@ name: Detect Rundll32 Application Control Bypass - setupapi id: 61e7b44a-6088-4f26-b788-9a96ba13b37a -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -77,7 +77,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml b/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml index cab866b351..86662d958f 100644 --- a/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml +++ b/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml @@ -1,7 +1,7 @@ name: Detect Rundll32 Application Control Bypass - syssetup id: 71b9bf37-cde1-45fb-b899-1b0aa6fa1183 -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -77,7 +77,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_rundll32_inline_hta_execution.yml b/detections/endpoint/detect_rundll32_inline_hta_execution.yml index 310dee62f4..3a1a84e20a 100644 --- a/detections/endpoint/detect_rundll32_inline_hta_execution.yml +++ b/detections/endpoint/detect_rundll32_inline_hta_execution.yml @@ -1,7 +1,7 @@ name: Detect Rundll32 Inline HTA Execution id: 91c79f14-5b41-11eb-ae93-0242ac130002 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -66,7 +66,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.005 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_sharphound_command_line_arguments.yml b/detections/endpoint/detect_sharphound_command_line_arguments.yml index 25d0f48916..f1763e793c 100644 --- a/detections/endpoint/detect_sharphound_command_line_arguments.yml +++ b/detections/endpoint/detect_sharphound_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Detect SharpHound Command-Line Arguments id: a0bdd2f6-c2ff-11eb-b918-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -67,13 +67,11 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1087.002 - T1069.001 - - T1482 - - T1087.001 - - T1087 - T1069.002 - - T1069 + - T1087.001 + - T1087.002 + - T1482 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_sharphound_file_modifications.yml b/detections/endpoint/detect_sharphound_file_modifications.yml index 6d6d2d57ee..9054f588ce 100644 --- a/detections/endpoint/detect_sharphound_file_modifications.yml +++ b/detections/endpoint/detect_sharphound_file_modifications.yml @@ -1,7 +1,7 @@ name: Detect SharpHound File Modifications id: 42b4b438-beed-11eb-ba1d-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -64,13 +64,11 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1087.002 - T1069.001 - - T1482 - - T1087.001 - - T1087 - T1069.002 - - T1069 + - T1087.001 + - T1087.002 + - T1482 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_sharphound_usage.yml b/detections/endpoint/detect_sharphound_usage.yml index 8f75b08dfe..ce759de968 100644 --- a/detections/endpoint/detect_sharphound_usage.yml +++ b/detections/endpoint/detect_sharphound_usage.yml @@ -1,7 +1,7 @@ name: Detect SharpHound Usage id: dd04b29a-beed-11eb-87bc-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -67,13 +67,11 @@ tags: - Ransomware asset_type: Endpoint mitre_attack_id: - - T1087.002 - T1069.001 - - T1482 - - T1087.001 - - T1087 - T1069.002 - - T1069 + - T1087.001 + - T1087.002 + - T1482 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_suspicious_processnames_using_pretrained_model_in_dsdl.yml b/detections/endpoint/detect_suspicious_processnames_using_pretrained_model_in_dsdl.yml index 6fa1b4cdd0..93af7b9881 100644 --- a/detections/endpoint/detect_suspicious_processnames_using_pretrained_model_in_dsdl.yml +++ b/detections/endpoint/detect_suspicious_processnames_using_pretrained_model_in_dsdl.yml @@ -1,6 +1,6 @@ name: Detect suspicious processnames using pretrained model in DSDL id: a15f8977-ad7d-4669-92ef-b59b97219bf5 -version: 4 +version: 5 date: '2024-11-13' author: Abhinav Mishra, Kumar Sharad and Namratha Sreekanta, Splunk type: Anomaly diff --git a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml index eb1159dade..307509b731 100644 --- a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml +++ b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml @@ -1,7 +1,7 @@ name: Detect Use of cmd exe to Launch Script Interpreters id: b89919ed-fe5f-492c-b139-95dbb162039e -version: 8 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Bhavin Patel, Mauricio Velazco, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: - Azorult asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.003 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_wmi_event_subscription_persistence.yml b/detections/endpoint/detect_wmi_event_subscription_persistence.yml index 4ed7920815..5aff76c6d1 100644 --- a/detections/endpoint/detect_wmi_event_subscription_persistence.yml +++ b/detections/endpoint/detect_wmi_event_subscription_persistence.yml @@ -1,7 +1,7 @@ name: Detect WMI Event Subscription Persistence id: 01d9a0c2-cece-11eb-ab46-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.003 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_amsi_through_registry.yml b/detections/endpoint/disable_amsi_through_registry.yml index 4f526be68b..a0ee63d1be 100644 --- a/detections/endpoint/disable_amsi_through_registry.yml +++ b/detections/endpoint/disable_amsi_through_registry.yml @@ -1,7 +1,7 @@ name: Disable AMSI Through Registry id: 9c27ec42-d338-11eb-9044-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_defender_antivirus_registry.yml b/detections/endpoint/disable_defender_antivirus_registry.yml index b73157c4ce..fdd91cef44 100644 --- a/detections/endpoint/disable_defender_antivirus_registry.yml +++ b/detections/endpoint/disable_defender_antivirus_registry.yml @@ -1,7 +1,7 @@ name: Disable Defender AntiVirus Registry id: aa4f695a-3024-11ec-9987-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_defender_blockatfirstseen_feature.yml b/detections/endpoint/disable_defender_blockatfirstseen_feature.yml index d092f50138..f1289e60a2 100644 --- a/detections/endpoint/disable_defender_blockatfirstseen_feature.yml +++ b/detections/endpoint/disable_defender_blockatfirstseen_feature.yml @@ -1,7 +1,7 @@ name: Disable Defender BlockAtFirstSeen Feature id: 2dd719ac-3021-11ec-97b4-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_defender_enhanced_notification.yml b/detections/endpoint/disable_defender_enhanced_notification.yml index 55022f84b4..6475fe086a 100644 --- a/detections/endpoint/disable_defender_enhanced_notification.yml +++ b/detections/endpoint/disable_defender_enhanced_notification.yml @@ -1,7 +1,7 @@ name: Disable Defender Enhanced Notification id: dc65678c-301f-11ec-8e30-acde48001122 -version: 7 -date: '2025-01-21' +version: 8 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -75,7 +75,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_defender_mpengine_registry.yml b/detections/endpoint/disable_defender_mpengine_registry.yml index e7472c30b0..ce5b547c15 100644 --- a/detections/endpoint/disable_defender_mpengine_registry.yml +++ b/detections/endpoint/disable_defender_mpengine_registry.yml @@ -1,7 +1,7 @@ name: Disable Defender MpEngine Registry id: cc391750-3024-11ec-955a-acde48001122 -version: 9 -date: '2024-12-16' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_defender_spynet_reporting.yml b/detections/endpoint/disable_defender_spynet_reporting.yml index 4c5bffe004..f670dce6cc 100644 --- a/detections/endpoint/disable_defender_spynet_reporting.yml +++ b/detections/endpoint/disable_defender_spynet_reporting.yml @@ -1,7 +1,7 @@ name: Disable Defender Spynet Reporting id: 898debf4-3021-11ec-ba7c-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_defender_submit_samples_consent_feature.yml b/detections/endpoint/disable_defender_submit_samples_consent_feature.yml index e7286d3d79..3ee864c99c 100644 --- a/detections/endpoint/disable_defender_submit_samples_consent_feature.yml +++ b/detections/endpoint/disable_defender_submit_samples_consent_feature.yml @@ -1,7 +1,7 @@ name: Disable Defender Submit Samples Consent Feature id: 73922ff8-3022-11ec-bf5e-acde48001122 -version: 8 -date: '2024-12-16' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_etw_through_registry.yml b/detections/endpoint/disable_etw_through_registry.yml index cae93c999b..6aeb854d3b 100644 --- a/detections/endpoint/disable_etw_through_registry.yml +++ b/detections/endpoint/disable_etw_through_registry.yml @@ -1,7 +1,7 @@ name: Disable ETW Through Registry id: f0eacfa4-d33f-11eb-8f9d-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -59,7 +59,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_logs_using_wevtutil.yml b/detections/endpoint/disable_logs_using_wevtutil.yml index 33e17afd7d..434b6452ec 100644 --- a/detections/endpoint/disable_logs_using_wevtutil.yml +++ b/detections/endpoint/disable_logs_using_wevtutil.yml @@ -1,7 +1,7 @@ name: Disable Logs Using WevtUtil id: 236e7c8e-c9d9-11eb-a824-acde48001122 -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: - Rhysida Ransomware asset_type: Endpoint mitre_attack_id: - - T1070 - T1070.001 product: - Splunk Enterprise diff --git a/detections/endpoint/disable_registry_tool.yml b/detections/endpoint/disable_registry_tool.yml index b75eca4b3c..ce3b191378 100644 --- a/detections/endpoint/disable_registry_tool.yml +++ b/detections/endpoint/disable_registry_tool.yml @@ -1,7 +1,7 @@ name: Disable Registry Tool id: cd2cf33c-9201-11eb-a10a-acde48001122 -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -58,9 +58,8 @@ tags: - NjRAT asset_type: Endpoint mitre_attack_id: - - T1562.001 - - T1562 - T1112 + - T1562.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_schedule_task.yml b/detections/endpoint/disable_schedule_task.yml index 4474a3fc1d..43abf6fe4d 100644 --- a/detections/endpoint/disable_schedule_task.yml +++ b/detections/endpoint/disable_schedule_task.yml @@ -1,7 +1,7 @@ name: Disable Schedule Task id: db596056-3019-11ec-a9ff-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_show_hidden_files.yml b/detections/endpoint/disable_show_hidden_files.yml index 8cf133efe2..f2851fcdf0 100644 --- a/detections/endpoint/disable_show_hidden_files.yml +++ b/detections/endpoint/disable_show_hidden_files.yml @@ -1,7 +1,7 @@ name: Disable Show Hidden Files id: 6f3ccfa2-91fe-11eb-8f9b-acde48001122 -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: Anomaly @@ -58,11 +58,9 @@ tags: - Azorult asset_type: Endpoint mitre_attack_id: - - T1564.001 - - T1562.001 - - T1564 - - T1562 - T1112 + - T1562.001 + - T1564.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_uac_remote_restriction.yml b/detections/endpoint/disable_uac_remote_restriction.yml index 9ca80568c7..5f4ae2f4db 100644 --- a/detections/endpoint/disable_uac_remote_restriction.yml +++ b/detections/endpoint/disable_uac_remote_restriction.yml @@ -1,7 +1,7 @@ name: Disable UAC Remote Restriction id: 9928b732-210e-11ec-b65e-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_windows_app_hotkeys.yml b/detections/endpoint/disable_windows_app_hotkeys.yml index 0edb9bc907..61d89307c0 100644 --- a/detections/endpoint/disable_windows_app_hotkeys.yml +++ b/detections/endpoint/disable_windows_app_hotkeys.yml @@ -1,7 +1,7 @@ name: Disable Windows App Hotkeys id: 1490f224-ad8b-11eb-8c4f-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -57,9 +57,8 @@ tags: - Windows Registry Abuse asset_type: Endpoint mitre_attack_id: - - T1562.001 - - T1562 - T1112 + - T1562.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_windows_behavior_monitoring.yml b/detections/endpoint/disable_windows_behavior_monitoring.yml index 07d891b9b9..ff1af8433e 100644 --- a/detections/endpoint/disable_windows_behavior_monitoring.yml +++ b/detections/endpoint/disable_windows_behavior_monitoring.yml @@ -1,7 +1,7 @@ name: Disable Windows Behavior Monitoring id: 79439cae-9200-11eb-a4d3-acde48001122 -version: 10 -date: '2024-12-08' +version: 11 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_windows_smartscreen_protection.yml b/detections/endpoint/disable_windows_smartscreen_protection.yml index 88d052f10e..d804b2c8d0 100644 --- a/detections/endpoint/disable_windows_smartscreen_protection.yml +++ b/detections/endpoint/disable_windows_smartscreen_protection.yml @@ -1,7 +1,7 @@ name: Disable Windows SmartScreen Protection id: 664f0fd0-91ff-11eb-a56f-acde48001122 -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_get_aduser.yml b/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_get_aduser.yml index 1606e574da..2aeb701771 100644 --- a/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_get_aduser.yml +++ b/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_get_aduser.yml @@ -1,7 +1,7 @@ name: Disabled Kerberos Pre-Authentication Discovery With Get-ADUser id: 114c6bfe-9406-11ec-bcce-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1558 - T1558.004 product: - Splunk Enterprise diff --git a/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_powerview.yml b/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_powerview.yml index e5ac20f37f..b5464753fe 100644 --- a/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_powerview.yml +++ b/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_powerview.yml @@ -1,7 +1,7 @@ name: Disabled Kerberos Pre-Authentication Discovery With PowerView id: b0b34e2c-90de-11ec-baeb-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -53,7 +53,6 @@ tags: - Active Directory Kerberos Attacks asset_type: Endpoint mitre_attack_id: - - T1558 - T1558.004 product: - Splunk Enterprise diff --git a/detections/endpoint/disabling_cmd_application.yml b/detections/endpoint/disabling_cmd_application.yml index d35acced16..2a96b3b449 100644 --- a/detections/endpoint/disabling_cmd_application.yml +++ b/detections/endpoint/disabling_cmd_application.yml @@ -1,7 +1,7 @@ name: Disabling CMD Application id: ff86077c-9212-11eb-a1e6-acde48001122 -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -60,9 +60,8 @@ tags: - NjRAT asset_type: Endpoint mitre_attack_id: - - T1562.001 - - T1562 - T1112 + - T1562.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disabling_controlpanel.yml b/detections/endpoint/disabling_controlpanel.yml index c6428e5197..7225cef46f 100644 --- a/detections/endpoint/disabling_controlpanel.yml +++ b/detections/endpoint/disabling_controlpanel.yml @@ -1,7 +1,7 @@ name: Disabling ControlPanel id: 6ae0148e-9215-11eb-a94a-acde48001122 -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -60,9 +60,8 @@ tags: - Windows Registry Abuse asset_type: Endpoint mitre_attack_id: - - T1562.001 - - T1562 - T1112 + - T1562.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disabling_defender_services.yml b/detections/endpoint/disabling_defender_services.yml index d9432952f5..c8fc943b34 100644 --- a/detections/endpoint/disabling_defender_services.yml +++ b/detections/endpoint/disabling_defender_services.yml @@ -1,7 +1,7 @@ name: Disabling Defender Services id: 911eacdc-317f-11ec-ad30-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disabling_firewall_with_netsh.yml b/detections/endpoint/disabling_firewall_with_netsh.yml index d2cf8713d8..c5d95d266a 100644 --- a/detections/endpoint/disabling_firewall_with_netsh.yml +++ b/detections/endpoint/disabling_firewall_with_netsh.yml @@ -1,7 +1,7 @@ name: Disabling Firewall with Netsh id: 6860a62c-9203-11eb-9e05-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disabling_folderoptions_windows_feature.yml b/detections/endpoint/disabling_folderoptions_windows_feature.yml index 1025506d70..572e1550d2 100644 --- a/detections/endpoint/disabling_folderoptions_windows_feature.yml +++ b/detections/endpoint/disabling_folderoptions_windows_feature.yml @@ -1,7 +1,7 @@ name: Disabling FolderOptions Windows Feature id: 83776de4-921a-11eb-868a-acde48001122 -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disabling_norun_windows_app.yml b/detections/endpoint/disabling_norun_windows_app.yml index 793a6f7540..28ad2e6afa 100644 --- a/detections/endpoint/disabling_norun_windows_app.yml +++ b/detections/endpoint/disabling_norun_windows_app.yml @@ -1,7 +1,7 @@ name: Disabling NoRun Windows App id: de81bc46-9213-11eb-adc9-acde48001122 -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -60,9 +60,8 @@ tags: - Windows Registry Abuse asset_type: Endpoint mitre_attack_id: - - T1562.001 - - T1562 - T1112 + - T1562.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disabling_remote_user_account_control.yml b/detections/endpoint/disabling_remote_user_account_control.yml index cac14cea20..e1729e4fee 100644 --- a/detections/endpoint/disabling_remote_user_account_control.yml +++ b/detections/endpoint/disabling_remote_user_account_control.yml @@ -1,7 +1,7 @@ name: Disabling Remote User Account Control id: bbc644bc-37df-4e1a-9c88-ec9a53e2038c -version: 8 -date: '2024-12-16' +version: 9 +date: '2025-02-10' author: David Dorsey, Patrick Bareiss, Splunk status: production type: TTP @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disabling_task_manager.yml b/detections/endpoint/disabling_task_manager.yml index 218bab32c0..0cd9db8bc1 100644 --- a/detections/endpoint/disabling_task_manager.yml +++ b/detections/endpoint/disabling_task_manager.yml @@ -1,7 +1,7 @@ name: Disabling Task Manager id: dac279bc-9202-11eb-b7fb-acde48001122 -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/dns_exfiltration_using_nslookup_app.yml b/detections/endpoint/dns_exfiltration_using_nslookup_app.yml index a244b2a733..9e42a31685 100644 --- a/detections/endpoint/dns_exfiltration_using_nslookup_app.yml +++ b/detections/endpoint/dns_exfiltration_using_nslookup_app.yml @@ -1,6 +1,6 @@ name: DNS Exfiltration Using Nslookup App id: 2452e632-9e0d-11eb-bacd-acde48001122 -version: 7 +version: 8 date: '2024-12-10' author: Teoderick Contreras, Splunk, Wouter Jansen status: production diff --git a/detections/endpoint/domain_account_discovery_with_dsquery.yml b/detections/endpoint/domain_account_discovery_with_dsquery.yml index cde94f4d78..73c4f00bf2 100644 --- a/detections/endpoint/domain_account_discovery_with_dsquery.yml +++ b/detections/endpoint/domain_account_discovery_with_dsquery.yml @@ -1,7 +1,7 @@ name: Domain Account Discovery with Dsquery id: b1a8ce04-04c2-11ec-bea7-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: Hunting @@ -42,7 +42,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/domain_account_discovery_with_wmic.yml b/detections/endpoint/domain_account_discovery_with_wmic.yml index d374d2851a..5997c315cc 100644 --- a/detections/endpoint/domain_account_discovery_with_wmic.yml +++ b/detections/endpoint/domain_account_discovery_with_wmic.yml @@ -1,7 +1,7 @@ name: Domain Account Discovery with Wmic id: 383572e0-04c5-11ec-bdcc-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/domain_group_discovery_with_adsisearcher.yml b/detections/endpoint/domain_group_discovery_with_adsisearcher.yml index e1abeaa0b5..7e402f9632 100644 --- a/detections/endpoint/domain_group_discovery_with_adsisearcher.yml +++ b/detections/endpoint/domain_group_discovery_with_adsisearcher.yml @@ -1,7 +1,7 @@ name: Domain Group Discovery with Adsisearcher id: 089c862f-5f83-49b5-b1c8-7e4ff66560c7 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -53,7 +53,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/domain_group_discovery_with_dsquery.yml b/detections/endpoint/domain_group_discovery_with_dsquery.yml index 1ab2a63c77..3c80940d89 100644 --- a/detections/endpoint/domain_group_discovery_with_dsquery.yml +++ b/detections/endpoint/domain_group_discovery_with_dsquery.yml @@ -1,7 +1,7 @@ name: Domain Group Discovery With Dsquery id: f0c9d62f-a232-4edd-b17e-bc409fb133d4 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -40,7 +40,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/domain_group_discovery_with_wmic.yml b/detections/endpoint/domain_group_discovery_with_wmic.yml index 77e3b1886c..0ea13c9e66 100644 --- a/detections/endpoint/domain_group_discovery_with_wmic.yml +++ b/detections/endpoint/domain_group_discovery_with_wmic.yml @@ -1,7 +1,7 @@ name: Domain Group Discovery With Wmic id: a87736a6-95cd-4728-8689-3c64d5026b3e -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -40,7 +40,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/drop_icedid_license_dat.yml b/detections/endpoint/drop_icedid_license_dat.yml index 12460ee148..c5232b8655 100644 --- a/detections/endpoint/drop_icedid_license_dat.yml +++ b/detections/endpoint/drop_icedid_license_dat.yml @@ -1,7 +1,7 @@ name: Drop IcedID License dat id: b7a045fc-f14a-11eb-8e79-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -31,7 +31,6 @@ tags: - IcedID asset_type: Endpoint mitre_attack_id: - - T1204 - T1204.002 product: - Splunk Enterprise diff --git a/detections/endpoint/dsquery_domain_discovery.yml b/detections/endpoint/dsquery_domain_discovery.yml index 3ee0399230..72e21dfb8e 100644 --- a/detections/endpoint/dsquery_domain_discovery.yml +++ b/detections/endpoint/dsquery_domain_discovery.yml @@ -1,6 +1,6 @@ name: DSQuery Domain Discovery id: cc316032-924a-11eb-91a2-acde48001122 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml index ea6d606030..7199fc7352 100644 --- a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml +++ b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml @@ -1,7 +1,7 @@ name: Dump LSASS via comsvcs DLL id: 8943b567-f14d-4ee8-a0bb-2121d4ce3184 -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -84,7 +84,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/dump_lsass_via_procdump.yml b/detections/endpoint/dump_lsass_via_procdump.yml index 56b38267ec..18d9cc1aa4 100644 --- a/detections/endpoint/dump_lsass_via_procdump.yml +++ b/detections/endpoint/dump_lsass_via_procdump.yml @@ -1,7 +1,7 @@ name: Dump LSASS via procdump id: 3742ebfe-64c2-11eb-ae93-0242ac130002 -version: 8 -date: '2024-12-10' +version: 10 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -76,7 +76,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/elevated_group_discovery_with_powerview.yml b/detections/endpoint/elevated_group_discovery_with_powerview.yml index 1493676285..6b8427834e 100644 --- a/detections/endpoint/elevated_group_discovery_with_powerview.yml +++ b/detections/endpoint/elevated_group_discovery_with_powerview.yml @@ -1,7 +1,7 @@ name: Elevated Group Discovery with PowerView id: 10d62950-0de5-4199-a710-cff9ea79b413 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -35,7 +35,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/elevated_group_discovery_with_wmic.yml b/detections/endpoint/elevated_group_discovery_with_wmic.yml index 3c74c3e9ca..d06e82db3f 100644 --- a/detections/endpoint/elevated_group_discovery_with_wmic.yml +++ b/detections/endpoint/elevated_group_discovery_with_wmic.yml @@ -1,7 +1,7 @@ name: Elevated Group Discovery With Wmic id: 3f6bbf22-093e-4cb4-9641-83f47b8444b6 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -66,7 +66,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/esentutl_sam_copy.yml b/detections/endpoint/esentutl_sam_copy.yml index cf7ea2b703..b4f247be75 100644 --- a/detections/endpoint/esentutl_sam_copy.yml +++ b/detections/endpoint/esentutl_sam_copy.yml @@ -1,7 +1,7 @@ name: Esentutl SAM Copy id: d372f928-ce4f-11eb-a762-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -43,7 +43,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.002 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/etw_registry_disabled.yml b/detections/endpoint/etw_registry_disabled.yml index e001bbdc5b..c2be3b0a81 100644 --- a/detections/endpoint/etw_registry_disabled.yml +++ b/detections/endpoint/etw_registry_disabled.yml @@ -1,7 +1,7 @@ name: ETW Registry Disabled id: 8ed523ac-276b-11ec-ac39-acde48001122 -version: 9 -date: '2024-12-16' +version: 11 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -64,9 +64,8 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1562.006 - T1127 - - T1562 + - T1562.006 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/eventvwr_uac_bypass.yml b/detections/endpoint/eventvwr_uac_bypass.yml index d86cc12b72..87c438a3b5 100644 --- a/detections/endpoint/eventvwr_uac_bypass.yml +++ b/detections/endpoint/eventvwr_uac_bypass.yml @@ -1,7 +1,7 @@ name: Eventvwr UAC Bypass id: 9cf8fe08-7ad8-11eb-9819-acde48001122 -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Steven Dick, Michael Haag, Splunk status: production type: TTP @@ -78,7 +78,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml index 87384b30be..8e55318d13 100644 --- a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml +++ b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml @@ -1,7 +1,7 @@ name: Excessive number of service control start as disabled id: 77592bec-d5cc-11eb-9e60-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Hart, Splunk status: production type: Anomaly @@ -70,7 +70,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/excessive_usage_of_sc_service_utility.yml b/detections/endpoint/excessive_usage_of_sc_service_utility.yml index bf447f6818..a7cbd28e9d 100644 --- a/detections/endpoint/excessive_usage_of_sc_service_utility.yml +++ b/detections/endpoint/excessive_usage_of_sc_service_utility.yml @@ -1,7 +1,7 @@ name: Excessive Usage Of SC Service Utility id: cb6b339e-d4c6-11eb-a026-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -59,7 +59,6 @@ tags: - Crypto Stealer asset_type: Endpoint mitre_attack_id: - - T1569 - T1569.002 product: - Splunk Enterprise diff --git a/detections/endpoint/excessive_usage_of_taskkill.yml b/detections/endpoint/excessive_usage_of_taskkill.yml index 14669e1cab..58c6c1d2c6 100644 --- a/detections/endpoint/excessive_usage_of_taskkill.yml +++ b/detections/endpoint/excessive_usage_of_taskkill.yml @@ -1,7 +1,7 @@ name: Excessive Usage Of Taskkill id: fe5bca48-accb-11eb-a67c-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -72,7 +72,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/exchange_powershell_module_usage.yml b/detections/endpoint/exchange_powershell_module_usage.yml index 0f67e57eea..a4a976b447 100644 --- a/detections/endpoint/exchange_powershell_module_usage.yml +++ b/detections/endpoint/exchange_powershell_module_usage.yml @@ -1,7 +1,7 @@ name: Exchange PowerShell Module Usage id: 2d10095e-05ae-11ec-8fdf-acde48001122 -version: 8 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -66,7 +66,6 @@ tags: - CISA AA22-264A asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise diff --git a/detections/endpoint/executable_file_written_in_administrative_smb_share.yml b/detections/endpoint/executable_file_written_in_administrative_smb_share.yml index b86556c3ad..17986ee585 100644 --- a/detections/endpoint/executable_file_written_in_administrative_smb_share.yml +++ b/detections/endpoint/executable_file_written_in_administrative_smb_share.yml @@ -1,7 +1,7 @@ name: Executable File Written in Administrative SMB Share id: f63c34fe-a435-11eb-935a-acde48001122 -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -68,7 +68,6 @@ tags: - Trickbot asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.002 product: - Splunk Enterprise diff --git a/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml b/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml index d389a1626f..7099216131 100644 --- a/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml +++ b/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml @@ -1,7 +1,7 @@ name: Execute Javascript With Jscript COM CLSID id: dc64d064-d346-11eb-8588-acde48001122 -version: 4 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -68,7 +68,6 @@ tags: - Ransomware asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.005 product: - Splunk Enterprise diff --git a/detections/endpoint/execution_of_file_with_multiple_extensions.yml b/detections/endpoint/execution_of_file_with_multiple_extensions.yml index 306a367e2b..c7c46d2a00 100644 --- a/detections/endpoint/execution_of_file_with_multiple_extensions.yml +++ b/detections/endpoint/execution_of_file_with_multiple_extensions.yml @@ -1,7 +1,7 @@ name: Execution of File with Multiple Extensions id: b06a555e-dce0-417d-a2eb-28a5d8d66ef7 -version: 7 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Rico Valdez, Teoderick Contreras, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: - DarkGate Malware asset_type: Endpoint mitre_attack_id: - - T1036 - T1036.003 product: - Splunk Enterprise diff --git a/detections/endpoint/file_with_samsam_extension.yml b/detections/endpoint/file_with_samsam_extension.yml index 0d86b46dcd..f09d658da1 100644 --- a/detections/endpoint/file_with_samsam_extension.yml +++ b/detections/endpoint/file_with_samsam_extension.yml @@ -1,6 +1,6 @@ name: File with Samsam Extension id: 02c6cfc2-ae66-4735-bfc7-6291da834cbf -version: 5 +version: 6 date: '2024-11-13' author: Rico Valdez, Splunk status: production diff --git a/detections/endpoint/firewall_allowed_program_enable.yml b/detections/endpoint/firewall_allowed_program_enable.yml index 39966aac74..11f599d75e 100644 --- a/detections/endpoint/firewall_allowed_program_enable.yml +++ b/detections/endpoint/firewall_allowed_program_enable.yml @@ -1,7 +1,7 @@ name: Firewall Allowed Program Enable id: 9a8f63a8-43ac-11ec-904c-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -70,7 +70,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.004 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/first_time_seen_running_windows_service.yml b/detections/endpoint/first_time_seen_running_windows_service.yml index 8576de1a20..70ca621bf7 100644 --- a/detections/endpoint/first_time_seen_running_windows_service.yml +++ b/detections/endpoint/first_time_seen_running_windows_service.yml @@ -1,7 +1,7 @@ name: First Time Seen Running Windows Service id: 823136f2-d755-4b6d-ae04-372b486a5808 -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -46,7 +46,6 @@ tags: - NOBELIUM Group asset_type: Endpoint mitre_attack_id: - - T1569 - T1569.002 product: - Splunk Enterprise diff --git a/detections/endpoint/fodhelper_uac_bypass.yml b/detections/endpoint/fodhelper_uac_bypass.yml index b1be122909..643bf866c4 100644 --- a/detections/endpoint/fodhelper_uac_bypass.yml +++ b/detections/endpoint/fodhelper_uac_bypass.yml @@ -1,7 +1,7 @@ name: FodHelper UAC Bypass id: 909f8fd8-7ac8-11eb-a1f3-acde48001122 -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -75,7 +75,6 @@ tags: mitre_attack_id: - T1112 - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/get_aduser_with_powershell.yml b/detections/endpoint/get_aduser_with_powershell.yml index 1c21e48521..19c5c4c847 100644 --- a/detections/endpoint/get_aduser_with_powershell.yml +++ b/detections/endpoint/get_aduser_with_powershell.yml @@ -1,7 +1,7 @@ name: Get ADUser with PowerShell id: 0b6ee3f4-04e3-11ec-a87d-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: Hunting @@ -45,7 +45,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/get_aduser_with_powershell_script_block.yml b/detections/endpoint/get_aduser_with_powershell_script_block.yml index ecdc645ace..4ea837065c 100644 --- a/detections/endpoint/get_aduser_with_powershell_script_block.yml +++ b/detections/endpoint/get_aduser_with_powershell_script_block.yml @@ -1,7 +1,7 @@ name: Get ADUser with PowerShell Script Block id: 21432e40-04f4-11ec-b7e6-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: Hunting @@ -34,7 +34,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/get_domainuser_with_powershell.yml b/detections/endpoint/get_domainuser_with_powershell.yml index f6f9362eb3..b7844e4976 100644 --- a/detections/endpoint/get_domainuser_with_powershell.yml +++ b/detections/endpoint/get_domainuser_with_powershell.yml @@ -1,7 +1,7 @@ name: Get DomainUser with PowerShell id: 9a5a41d6-04e7-11ec-923c-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -70,7 +70,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/get_domainuser_with_powershell_script_block.yml b/detections/endpoint/get_domainuser_with_powershell_script_block.yml index 8b3e401a5a..9fb765be7e 100644 --- a/detections/endpoint/get_domainuser_with_powershell_script_block.yml +++ b/detections/endpoint/get_domainuser_with_powershell_script_block.yml @@ -1,7 +1,7 @@ name: Get DomainUser with PowerShell Script Block id: 61994268-04f4-11ec-865c-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/get_wmiobject_group_discovery.yml b/detections/endpoint/get_wmiobject_group_discovery.yml index ca6601298b..eb0c67807c 100644 --- a/detections/endpoint/get_wmiobject_group_discovery.yml +++ b/detections/endpoint/get_wmiobject_group_discovery.yml @@ -1,7 +1,7 @@ name: Get WMIObject Group Discovery id: 5434f670-155d-11ec-8cca-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -41,7 +41,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.001 product: - Splunk Enterprise diff --git a/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml b/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml index 04fa251a96..b6b6ec3604 100644 --- a/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml +++ b/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml @@ -1,7 +1,7 @@ name: Get WMIObject Group Discovery with Script Block Logging id: 69df7f7c-155d-11ec-a055-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -34,7 +34,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.001 product: - Splunk Enterprise diff --git a/detections/endpoint/getadgroup_with_powershell.yml b/detections/endpoint/getadgroup_with_powershell.yml index d381b71e36..8f87c04925 100644 --- a/detections/endpoint/getadgroup_with_powershell.yml +++ b/detections/endpoint/getadgroup_with_powershell.yml @@ -1,7 +1,7 @@ name: GetAdGroup with PowerShell id: 872e3063-0fc4-4e68-b2f3-f2b99184a708 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -41,7 +41,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/getadgroup_with_powershell_script_block.yml b/detections/endpoint/getadgroup_with_powershell_script_block.yml index 0e2b7f09ef..5f765ba70b 100644 --- a/detections/endpoint/getadgroup_with_powershell_script_block.yml +++ b/detections/endpoint/getadgroup_with_powershell_script_block.yml @@ -1,7 +1,7 @@ name: GetAdGroup with PowerShell Script Block id: e4c73d68-794b-468d-b4d0-dac1772bbae7 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -31,7 +31,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/getdomaingroup_with_powershell.yml b/detections/endpoint/getdomaingroup_with_powershell.yml index 85f7f11b3e..8c01054c4b 100644 --- a/detections/endpoint/getdomaingroup_with_powershell.yml +++ b/detections/endpoint/getdomaingroup_with_powershell.yml @@ -1,7 +1,7 @@ name: GetDomainGroup with PowerShell id: 93c94be3-bead-4a60-860f-77ca3fe59903 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/getdomaingroup_with_powershell_script_block.yml b/detections/endpoint/getdomaingroup_with_powershell_script_block.yml index 913dbacb5e..bad857a4c9 100644 --- a/detections/endpoint/getdomaingroup_with_powershell_script_block.yml +++ b/detections/endpoint/getdomaingroup_with_powershell_script_block.yml @@ -1,7 +1,7 @@ name: GetDomainGroup with PowerShell Script Block id: 09725404-a44f-4ed3-9efa-8ed5d69e4c53 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -52,7 +52,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/getlocaluser_with_powershell.yml b/detections/endpoint/getlocaluser_with_powershell.yml index 690b834301..7819e2520b 100644 --- a/detections/endpoint/getlocaluser_with_powershell.yml +++ b/detections/endpoint/getlocaluser_with_powershell.yml @@ -1,7 +1,7 @@ name: GetLocalUser with PowerShell id: 85fae8fa-0427-11ec-8b78-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -41,7 +41,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.001 product: - Splunk Enterprise diff --git a/detections/endpoint/getlocaluser_with_powershell_script_block.yml b/detections/endpoint/getlocaluser_with_powershell_script_block.yml index 754d2cadae..5e8423446f 100644 --- a/detections/endpoint/getlocaluser_with_powershell_script_block.yml +++ b/detections/endpoint/getlocaluser_with_powershell_script_block.yml @@ -1,7 +1,7 @@ name: GetLocalUser with PowerShell Script Block id: 2e891cbe-0426-11ec-9c9c-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -33,9 +33,8 @@ tags: - Malicious PowerShell asset_type: Endpoint mitre_attack_id: - - T1087 - - T1087.001 - T1059.001 + - T1087.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/getwmiobject_ds_group_with_powershell.yml b/detections/endpoint/getwmiobject_ds_group_with_powershell.yml index 11b144c48c..f0dc6262b2 100644 --- a/detections/endpoint/getwmiobject_ds_group_with_powershell.yml +++ b/detections/endpoint/getwmiobject_ds_group_with_powershell.yml @@ -1,7 +1,7 @@ name: GetWmiObject Ds Group with PowerShell id: df275a44-4527-443b-b884-7600e066e3eb -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml b/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml index 5dcd4326a6..36a64083ac 100644 --- a/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml +++ b/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml @@ -1,7 +1,7 @@ name: GetWmiObject Ds Group with PowerShell Script Block id: 67740bd3-1506-469c-b91d-effc322cc6e5 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -53,7 +53,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml index 5cd432dcaa..eeb6e39b17 100644 --- a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml +++ b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml @@ -1,7 +1,7 @@ name: GetWmiObject DS User with PowerShell id: 22d3b118-04df-11ec-8fa3-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml index ac5f12c52e..ab9fdb89c4 100644 --- a/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml +++ b/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml @@ -1,7 +1,7 @@ name: GetWmiObject DS User with PowerShell Script Block id: fabd364e-04f3-11ec-b34b-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/getwmiobject_user_account_with_powershell.yml b/detections/endpoint/getwmiobject_user_account_with_powershell.yml index 0c6134ae47..8733ba54ea 100644 --- a/detections/endpoint/getwmiobject_user_account_with_powershell.yml +++ b/detections/endpoint/getwmiobject_user_account_with_powershell.yml @@ -1,7 +1,7 @@ name: GetWmiObject User Account with PowerShell id: b44f6ac6-0429-11ec-87e9-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -42,7 +42,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.001 product: - Splunk Enterprise diff --git a/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml b/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml index 1a5ed182ed..8677fb28ab 100644 --- a/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml +++ b/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml @@ -1,7 +1,7 @@ name: GetWmiObject User Account with PowerShell Script Block id: 640b0eda-0429-11ec-accd-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -32,9 +32,8 @@ tags: - Malicious PowerShell asset_type: Endpoint mitre_attack_id: - - T1087 - - T1087.001 - T1059.001 + - T1087.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml b/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml index c60512b788..46ab4b2a2e 100644 --- a/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml +++ b/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml @@ -1,6 +1,6 @@ name: GPUpdate with no Command Line Arguments with Network id: 2c853856-a140-11eb-a5b5-acde48001122 -version: 7 +version: 8 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/headless_browser_mockbin_or_mocky_request.yml b/detections/endpoint/headless_browser_mockbin_or_mocky_request.yml index a5a0e59b2d..6d6557e0ab 100644 --- a/detections/endpoint/headless_browser_mockbin_or_mocky_request.yml +++ b/detections/endpoint/headless_browser_mockbin_or_mocky_request.yml @@ -1,6 +1,6 @@ name: Headless Browser Mockbin or Mocky Request id: 94fc85a1-e55b-4265-95e1-4b66730e05c0 -version: 4 +version: 5 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/hide_user_account_from_sign_in_screen.yml b/detections/endpoint/hide_user_account_from_sign_in_screen.yml index 8d27a673ad..1a4035b651 100644 --- a/detections/endpoint/hide_user_account_from_sign_in_screen.yml +++ b/detections/endpoint/hide_user_account_from_sign_in_screen.yml @@ -1,7 +1,7 @@ name: Hide User Account From Sign-In Screen id: 834ba832-ad89-11eb-937d-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml index c95af49a98..9e314746a6 100644 --- a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml +++ b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml @@ -1,7 +1,7 @@ name: Hiding Files And Directories With Attrib exe id: 6e5a3ae4-90a3-462d-9aa6-0119f638c0f1 -version: 9 -date: '2024-12-10' +version: 10 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -67,7 +67,6 @@ tags: - Crypto Stealer asset_type: Endpoint mitre_attack_id: - - T1222 - T1222.001 product: - Splunk Enterprise diff --git a/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml b/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml index d0965e6ffb..2a4a093612 100644 --- a/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml +++ b/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml @@ -1,7 +1,7 @@ name: IcedID Exfiltrated Archived File Creation id: 0db4da70-f14b-11eb-8043-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -34,7 +34,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1560.001 - - T1560 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml index 67d36cf818..7325419b34 100644 --- a/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml +++ b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml @@ -1,7 +1,7 @@ name: Impacket Lateral Movement Commandline Parameters id: 8ce07472-496f-11ec-ab3b-3e22fbd008af -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -82,7 +82,6 @@ tags: - CISA AA22-277A asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.002 - T1021.003 - T1047 diff --git a/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml index b48dcbbc37..5bc432054e 100644 --- a/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml +++ b/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml @@ -1,7 +1,7 @@ name: Impacket Lateral Movement smbexec CommandLine Parameters id: bb3c1bac-6bdf-4aa0-8dc9-068b8b712a76 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -83,7 +83,6 @@ tags: asset_type: Endpoint atomic_guid: [] mitre_attack_id: - - T1021 - T1021.002 - T1021.003 - T1047 diff --git a/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml index 7965e0f409..9e48d7ea19 100644 --- a/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml +++ b/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml @@ -1,7 +1,7 @@ name: Impacket Lateral Movement WMIExec Commandline Parameters id: d6e464e4-5c6a-474e-82d2-aed616a3a492 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -83,7 +83,6 @@ tags: asset_type: Endpoint atomic_guid: [] mitre_attack_id: - - T1021 - T1021.002 - T1021.003 - T1047 diff --git a/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml b/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml index a096091412..4e56391427 100644 --- a/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml +++ b/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml @@ -1,7 +1,7 @@ name: Interactive Session on Remote Endpoint with PowerShell id: a4e8f3a4-48b2-11ec-bcfc-3e22fbd008af -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -55,7 +55,6 @@ tags: - Active Directory Lateral Movement asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.006 product: - Splunk Enterprise diff --git a/detections/endpoint/jscript_execution_using_cscript_app.yml b/detections/endpoint/jscript_execution_using_cscript_app.yml index a88bd5debd..94f26c5e5f 100644 --- a/detections/endpoint/jscript_execution_using_cscript_app.yml +++ b/detections/endpoint/jscript_execution_using_cscript_app.yml @@ -1,7 +1,7 @@ name: Jscript Execution Using Cscript App id: 002f1e24-146e-11ec-a470-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -67,7 +67,6 @@ tags: - Remcos asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.007 product: - Splunk Enterprise diff --git a/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml b/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml index 948d171659..57f2076b4c 100644 --- a/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml +++ b/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml @@ -1,7 +1,7 @@ name: Kerberoasting spn request with RC4 encryption id: 5cc67381-44fa-4111-8a37-7a230943f027 -version: 9 -date: '2024-12-10' +version: 10 +date: '2025-02-10' author: Jose Hernandez, Patrick Bareiss, Mauricio Velazco, Dean Luxton, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - Hermetic Wiper asset_type: Endpoint mitre_attack_id: - - T1558 - T1558.003 product: - Splunk Enterprise diff --git a/detections/endpoint/kerberos_pre_authentication_flag_disabled_in_useraccountcontrol.yml b/detections/endpoint/kerberos_pre_authentication_flag_disabled_in_useraccountcontrol.yml index f5d8ed8cf8..748fef94bf 100644 --- a/detections/endpoint/kerberos_pre_authentication_flag_disabled_in_useraccountcontrol.yml +++ b/detections/endpoint/kerberos_pre_authentication_flag_disabled_in_useraccountcontrol.yml @@ -1,7 +1,7 @@ name: Kerberos Pre-Authentication Flag Disabled in UserAccountControl id: 0cb847ee-9423-11ec-b2df-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -16,7 +16,8 @@ description: The following analytic detects when the Kerberos Pre-Authentication data_source: - Windows Event Log Security 4738 search: > - `wineventlog_security` EventCode=4738 MSADChangedAttributes="*\'Don\'t Require Preauth\' - Enabled*" |rename Account_Name as user | table EventCode, user, dest, Security_ID, + `wineventlog_security` EventCode=4738 MSADChangedAttributes="*\'Don\'t Require Preauth\' + - Enabled*" |rename Account_Name as user | table EventCode, user, dest, Security_ID, MSADChangedAttributes | `kerberos_pre_authentication_flag_disabled_in_useraccountcontrol_filter` how_to_implement: To successfully implement this search, you need to be ingesting Domain Controller events. The Advanced Security Audit policy setting `User Account @@ -53,7 +54,6 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1558 - T1558.004 product: - Splunk Enterprise diff --git a/detections/endpoint/kerberos_pre_authentication_flag_disabled_with_powershell.yml b/detections/endpoint/kerberos_pre_authentication_flag_disabled_with_powershell.yml index bc3d94ee68..67814fc234 100644 --- a/detections/endpoint/kerberos_pre_authentication_flag_disabled_with_powershell.yml +++ b/detections/endpoint/kerberos_pre_authentication_flag_disabled_with_powershell.yml @@ -1,7 +1,7 @@ name: Kerberos Pre-Authentication Flag Disabled with PowerShell id: 59b51620-94c9-11ec-b3d5-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -55,7 +55,6 @@ tags: - Active Directory Kerberos Attacks asset_type: Endpoint mitre_attack_id: - - T1558 - T1558.004 product: - Splunk Enterprise diff --git a/detections/endpoint/kerberos_service_ticket_request_using_rc4_encryption.yml b/detections/endpoint/kerberos_service_ticket_request_using_rc4_encryption.yml index d667d529f4..768d5fe2e6 100644 --- a/detections/endpoint/kerberos_service_ticket_request_using_rc4_encryption.yml +++ b/detections/endpoint/kerberos_service_ticket_request_using_rc4_encryption.yml @@ -1,7 +1,7 @@ name: Kerberos Service Ticket Request Using RC4 Encryption id: 7d90f334-a482-11ec-908c-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: - Active Directory Privilege Escalation asset_type: Endpoint mitre_attack_id: - - T1558 - T1558.001 product: - Splunk Enterprise diff --git a/detections/endpoint/kerberos_user_enumeration.yml b/detections/endpoint/kerberos_user_enumeration.yml index 570a014a73..e5b80a4cea 100644 --- a/detections/endpoint/kerberos_user_enumeration.yml +++ b/detections/endpoint/kerberos_user_enumeration.yml @@ -1,7 +1,7 @@ name: Kerberos User Enumeration id: d82d4af4-a0bd-11ec-9445-3e22fbd008af -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Anomaly @@ -55,7 +55,6 @@ tags: - Active Directory Kerberos Attacks asset_type: Endpoint mitre_attack_id: - - T1589 - T1589.002 product: - Splunk Enterprise diff --git a/detections/endpoint/linux_account_manipulation_of_ssh_config_and_keys.yml b/detections/endpoint/linux_account_manipulation_of_ssh_config_and_keys.yml index 70069801ef..8728599618 100644 --- a/detections/endpoint/linux_account_manipulation_of_ssh_config_and_keys.yml +++ b/detections/endpoint/linux_account_manipulation_of_ssh_config_and_keys.yml @@ -1,7 +1,7 @@ name: Linux Account Manipulation Of SSH Config and Keys id: 73a56508-1cf5-4df7-b8d9-5737fbdc27d2 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -55,9 +55,8 @@ tags: - AcidRain asset_type: Endpoint mitre_attack_id: - - T1485 - T1070.004 - - T1070 + - T1485 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_add_files_in_known_crontab_directories.yml b/detections/endpoint/linux_add_files_in_known_crontab_directories.yml index 5ac49389a5..7c5f666cd9 100644 --- a/detections/endpoint/linux_add_files_in_known_crontab_directories.yml +++ b/detections/endpoint/linux_add_files_in_known_crontab_directories.yml @@ -1,7 +1,7 @@ name: Linux Add Files In Known Crontab Directories id: 023f3452-5f27-11ec-bf00-acde48001122 -version: 5 -date: '2024-12-19' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -59,7 +59,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.003 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_add_user_account.yml b/detections/endpoint/linux_add_user_account.yml index 3685c49b94..3c798ae4cb 100644 --- a/detections/endpoint/linux_add_user_account.yml +++ b/detections/endpoint/linux_add_user_account.yml @@ -1,7 +1,7 @@ name: Linux Add User Account id: 51fbcaf2-6259-11ec-b0f3-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -40,7 +40,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1136.001 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_adding_crontab_using_list_parameter.yml b/detections/endpoint/linux_adding_crontab_using_list_parameter.yml index 8bdc8a8822..7f05ba1ab8 100644 --- a/detections/endpoint/linux_adding_crontab_using_list_parameter.yml +++ b/detections/endpoint/linux_adding_crontab_using_list_parameter.yml @@ -1,7 +1,7 @@ name: Linux Adding Crontab Using List Parameter id: 52f6d751-1fd4-4c74-a4c9-777ecfeb5c58 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -47,7 +47,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.003 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_apt_get_privilege_escalation.yml b/detections/endpoint/linux_apt_get_privilege_escalation.yml index 7924c146e3..0dd8a1971a 100644 --- a/detections/endpoint/linux_apt_get_privilege_escalation.yml +++ b/detections/endpoint/linux_apt_get_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux apt-get Privilege Escalation id: d870ce3b-e796-402f-b2af-cab4da1223f2 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_apt_privilege_escalation.yml b/detections/endpoint/linux_apt_privilege_escalation.yml index 7f6804cbfb..b663f74c24 100644 --- a/detections/endpoint/linux_apt_privilege_escalation.yml +++ b/detections/endpoint/linux_apt_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux APT Privilege Escalation id: 4d5a05fa-77d9-4fd0-af9c-05704f9f9a88 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_at_allow_config_file_creation.yml b/detections/endpoint/linux_at_allow_config_file_creation.yml index 732c20f5b7..ae556ae740 100644 --- a/detections/endpoint/linux_at_allow_config_file_creation.yml +++ b/detections/endpoint/linux_at_allow_config_file_creation.yml @@ -1,7 +1,7 @@ name: Linux At Allow Config File Creation id: 977b3082-5f3d-11ec-b954-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.003 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_at_application_execution.yml b/detections/endpoint/linux_at_application_execution.yml index 3cd126c6ca..6666181369 100644 --- a/detections/endpoint/linux_at_application_execution.yml +++ b/detections/endpoint/linux_at_application_execution.yml @@ -1,7 +1,7 @@ name: Linux At Application Execution id: bf0a378e-5f3c-11ec-a6de-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.002 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_add_user_account.yml b/detections/endpoint/linux_auditd_add_user_account.yml index 900f4b6a4e..c29d67571e 100644 --- a/detections/endpoint/linux_auditd_add_user_account.yml +++ b/detections/endpoint/linux_auditd_add_user_account.yml @@ -1,7 +1,7 @@ name: Linux Auditd Add User Account id: aae66dc0-74b4-4807-b480-b35f8027abb4 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1136.001 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_add_user_account_type.yml b/detections/endpoint/linux_auditd_add_user_account_type.yml index 929dd08741..7bf00799da 100644 --- a/detections/endpoint/linux_auditd_add_user_account_type.yml +++ b/detections/endpoint/linux_auditd_add_user_account_type.yml @@ -1,7 +1,7 @@ name: Linux Auditd Add User Account Type id: f8c325ea-506e-4105-8ccf-da1492e90115 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -59,7 +59,6 @@ tags: - Compromised Linux Host asset_type: Endpoint mitre_attack_id: - - T1136 - T1136.001 product: - Splunk Enterprise diff --git a/detections/endpoint/linux_auditd_at_application_execution.yml b/detections/endpoint/linux_auditd_at_application_execution.yml index da29fe7c02..e9c76689ff 100644 --- a/detections/endpoint/linux_auditd_at_application_execution.yml +++ b/detections/endpoint/linux_auditd_at_application_execution.yml @@ -1,7 +1,7 @@ name: Linux Auditd At Application Execution id: 9f306e0a-1c36-469e-8892-968ca12470dd -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.002 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_change_file_owner_to_root.yml b/detections/endpoint/linux_auditd_change_file_owner_to_root.yml index a45a65d0f8..b4733004c9 100644 --- a/detections/endpoint/linux_auditd_change_file_owner_to_root.yml +++ b/detections/endpoint/linux_auditd_change_file_owner_to_root.yml @@ -1,16 +1,35 @@ name: Linux Auditd Change File Owner To Root id: 7b87c556-0ca4-47e0-b84c-6cd62a0a3e90 -version: 4 -date: '2025-01-20' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP -description: The following analytic detects the use of the 'chown' command to change a file owner to 'root' on a Linux system. It leverages Linux Auditd telemetry, specifically monitoring command-line executions and process details. This activity is significant as it may indicate an attempt to escalate privileges by adversaries, malware, or red teamers. If confirmed malicious, this action could allow an attacker to gain root-level access, leading to full control over the compromised host and potential persistence within the environment. +description: The following analytic detects the use of the 'chown' command to change + a file owner to 'root' on a Linux system. It leverages Linux Auditd telemetry, specifically + monitoring command-line executions and process details. This activity is significant + as it may indicate an attempt to escalate privileges by adversaries, malware, or + red teamers. If confirmed malicious, this action could allow an attacker to gain + root-level access, leading to full control over the compromised host and potential + persistence within the environment. data_source: - Linux Auditd Proctitle -search: '`linux_auditd` `linux_auditd_normalized_proctitle_process`| rename host as dest | where LIKE (process_exec, "%chown %root%") | stats count min(_time) as firstTime max(_time) as lastTime by process_exec proctitle normalized_proctitle_delimiter dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_change_file_owner_to_root_filter`' -how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed -known_false_positives: Administrator or network operator can execute this command. Please update the filter macros to remove false positives. +search: '`linux_auditd` `linux_auditd_normalized_proctitle_process`| rename host as + dest | where LIKE (process_exec, "%chown %root%") | stats count min(_time) as firstTime + max(_time) as lastTime by process_exec proctitle normalized_proctitle_delimiter + dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| + `linux_auditd_change_file_owner_to_root_filter`' +how_to_implement: To implement this detection, the process begins by ingesting auditd + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + which is essential for correctly parsing and categorizing the data. The next step + involves normalizing the field names to match the field names set by the Splunk + Common Information Model (CIM) to ensure consistency across different data sources + and enhance the efficiency of data modeling. This approach enables effective monitoring + and detection of linux endpoints where auditd is deployed +known_false_positives: Administrator or network operator can execute this command. + Please update the filter macros to remove false positives. references: - https://unix.stackexchange.com/questions/101073/how-to-change-permissions-from-root-user-to-all-users - https://askubuntu.com/questions/617850/changing-from-user-to-superuser @@ -20,7 +39,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -40,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1222.002 - - T1222 product: - Splunk Enterprise - Splunk Enterprise Security @@ -49,6 +72,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.002/linux_auditd_chown_root/linux_auditd_chown_root.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.002/linux_auditd_chown_root/linux_auditd_chown_root.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_disable_or_modify_system_firewall.yml b/detections/endpoint/linux_auditd_disable_or_modify_system_firewall.yml index 5dfd17febc..a825c4c9fe 100644 --- a/detections/endpoint/linux_auditd_disable_or_modify_system_firewall.yml +++ b/detections/endpoint/linux_auditd_disable_or_modify_system_firewall.yml @@ -1,7 +1,7 @@ name: Linux Auditd Disable Or Modify System Firewall id: 07052556-d4b5-4bae-89aa-cbdc1bb11250 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.004 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_doas_conf_file_creation.yml b/detections/endpoint/linux_auditd_doas_conf_file_creation.yml index 6eea3f2bdf..ce27362871 100644 --- a/detections/endpoint/linux_auditd_doas_conf_file_creation.yml +++ b/detections/endpoint/linux_auditd_doas_conf_file_creation.yml @@ -1,7 +1,7 @@ name: Linux Auditd Doas Conf File Creation id: 61059783-574b-40d2-ac2f-69b898afd6b4 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_doas_tool_execution.yml b/detections/endpoint/linux_auditd_doas_tool_execution.yml index 14483461ca..d955c86264 100644 --- a/detections/endpoint/linux_auditd_doas_tool_execution.yml +++ b/detections/endpoint/linux_auditd_doas_tool_execution.yml @@ -1,7 +1,7 @@ name: Linux Auditd Doas Tool Execution id: 91b8ca78-f205-4826-a3ef-cd8d6b24e97b -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_edit_cron_table_parameter.yml b/detections/endpoint/linux_auditd_edit_cron_table_parameter.yml index abcf36a2c5..e3a2452cda 100644 --- a/detections/endpoint/linux_auditd_edit_cron_table_parameter.yml +++ b/detections/endpoint/linux_auditd_edit_cron_table_parameter.yml @@ -1,7 +1,7 @@ name: Linux Auditd Edit Cron Table Parameter id: f4bb7321-7e64-4d1e-b1aa-21f8b019a91f -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.003 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_file_permission_modification_via_chmod.yml b/detections/endpoint/linux_auditd_file_permission_modification_via_chmod.yml index f33b95fed5..7ce6b582fc 100644 --- a/detections/endpoint/linux_auditd_file_permission_modification_via_chmod.yml +++ b/detections/endpoint/linux_auditd_file_permission_modification_via_chmod.yml @@ -1,8 +1,8 @@ name: Linux Auditd File Permission Modification Via Chmod id: 5f1d2ea7-eec0-4790-8b24-6875312ad492 -version: 6 -date: '2025-01-27' -author: "Teoderick Contreras, Splunk, Ivar Nyg\xE5rd" +version: 7 +date: '2025-02-10' +author: Teoderick Contreras, Splunk, Ivar Nygård status: production type: Anomaly description: The following analytic detects suspicious file permission modifications @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1222.002 - - T1222 product: - Splunk Enterprise - Splunk Enterprise Security @@ -77,6 +76,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.002/linux_auditd_chmod_exec_attrib/linux_auditd_chmod_exec_attrib.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.002/linux_auditd_chmod_exec_attrib/linux_auditd_chmod_exec_attrib.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_file_permissions_modification_via_chattr.yml b/detections/endpoint/linux_auditd_file_permissions_modification_via_chattr.yml index 84bb8beef4..de8a0c8bc8 100644 --- a/detections/endpoint/linux_auditd_file_permissions_modification_via_chattr.yml +++ b/detections/endpoint/linux_auditd_file_permissions_modification_via_chattr.yml @@ -1,16 +1,30 @@ name: Linux Auditd File Permissions Modification Via Chattr id: f2d1110d-b01c-4a58-9975-90a9edeb083a -version: 3 -date: '2025-01-16' +version: 4 +date: '2025-02-03' author: Teoderick Contreras, Splunk status: production -type: TTP +type: Anomaly description: The following analytic detects suspicious file permissions modifications using the chattr command, which may indicate an attacker attempting to manipulate file attributes to evade detection or prevent alteration. The chattr command can be used to make files immutable or restrict deletion, which can be leveraged to protect malicious files or disrupt system operations. By monitoring for unusual or unauthorized chattr usage, this analytic helps identify potential tampering with critical files, enabling security teams to quickly respond to and mitigate threats associated with unauthorized file attribute changes. data_source: - Linux Auditd Execve -search: '`linux_auditd` `linux_auditd_normalized_proctitle_process` | rename host as dest | rename comm as process_name | rename exe as process | where LIKE(process_exec, "%chattr %") AND LIKE(process_exec, "% -i%") | stats count min(_time) as firstTime max(_time) as lastTime by process_exec proctitle normalized_proctitle_delimiter dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_file_permissions_modification_via_chattr_filter`' -how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed -known_false_positives: Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. +search: '`linux_auditd` `linux_auditd_normalized_proctitle_process` | rename host + as dest | rename comm as process_name | rename exe as process | where LIKE(process_exec, + "%chattr %") AND LIKE(process_exec, "% -i%") | stats count min(_time) as firstTime + max(_time) as lastTime by process_exec proctitle normalized_proctitle_delimiter + dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| + `linux_auditd_file_permissions_modification_via_chattr_filter`' +how_to_implement: To implement this detection, the process begins by ingesting auditd + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + which is essential for correctly parsing and categorizing the data. The next step + involves normalizing the field names to match the field names set by the Splunk + Common Information Model (CIM) to ensure consistency across different data sources + and enhance the efficiency of data modeling. This approach enables effective monitoring + and detection of linux endpoints where auditd is deployed +known_false_positives: Administrator or network operator can use this application + for automation purposes. Please update the filter macros to remove false positives. references: - https://www.splunk.com/en_us/blog/security/deep-dive-on-persistence-privilege-escalation-technique-and-detection-in-linux-platform.html drilldown_searches: @@ -19,7 +33,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -28,7 +47,7 @@ rba: risk_objects: - field: dest type: system - score: 49 + score: 30 threat_objects: [] tags: analytic_story: @@ -39,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1222.002 - - T1222 product: - Splunk Enterprise - Splunk Enterprise Security @@ -48,6 +66,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.002/linux_auditd_chattr_i/linux_auditd_chattr_i.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.002/linux_auditd_chattr_i/linux_auditd_chattr_i.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_find_credentials_from_password_managers.yml b/detections/endpoint/linux_auditd_find_credentials_from_password_managers.yml index f42a173862..91a4468484 100644 --- a/detections/endpoint/linux_auditd_find_credentials_from_password_managers.yml +++ b/detections/endpoint/linux_auditd_find_credentials_from_password_managers.yml @@ -1,14 +1,21 @@ name: Linux Auditd Find Credentials From Password Managers id: 784241aa-85a5-4782-a503-d071bd3446f9 -version: 3 -date: '2025-01-16' +version: 4 +date: '2025-02-03' author: Teoderick Contreras, Splunk status: production type: TTP -description: The following analytic detects suspicious attempts to find credentials stored in password managers, which may indicate an attacker's effort to retrieve sensitive login information. Password managers are often targeted by adversaries seeking to access stored passwords for further compromise or lateral movement within a network. By monitoring for unusual or unauthorized access to password manager files or processes, this analytic helps identify potential credential theft attempts, enabling security teams to respond quickly to protect critical accounts and prevent further unauthorized access. +description: The following analytic detects suspicious attempts to find credentials + stored in password managers, which may indicate an attacker's effort to retrieve + sensitive login information. Password managers are often targeted by adversaries + seeking to access stored passwords for further compromise or lateral movement within + a network. By monitoring for unusual or unauthorized access to password manager + files or processes, this analytic helps identify potential credential theft attempts, + enabling security teams to respond quickly to protect critical accounts and prevent + further unauthorized access. data_source: - Linux Auditd Execve -search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%.kdbx%") OR LIKE (process_exec, "%KeePass%") OR LIKE (process_exec, "%KeePass\.enforced%") OR LIKE (process_exec, "%.lpdb%")OR LIKE (process_exec, "%.opvault%")OR LIKE (process_exec, "%.agilekeychain%")OR LIKE (process_exec, "%.dashlane%")OR LIKE (process_exec, "%.rfx%")OR LIKE (process_exec, "%passbolt%")OR LIKE (process_exec, "%.spdb%")OR LIKE (process_exec, "%StickyPassword%")OR LIKE (process_exec, "%.walletx%")OR LIKE (process_exec, "%enpass%")OR LIKE (process_exec, "%vault%")OR LIKE (process_exec, "%.kdb%")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_find_credentials_from_password_managers_filter`' +search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%.kdbx%") OR LIKE (process_exec, "%KeePass%") OR LIKE (process_exec, "%.enforced%") OR LIKE (process_exec, "%.lpdb%")OR LIKE (process_exec, "%.opvault%")OR LIKE (process_exec, "%.agilekeychain%")OR LIKE (process_exec, "%.dashlane%")OR LIKE (process_exec, "%.rfx%")OR LIKE (process_exec, "%passbolt%")OR LIKE (process_exec, "%.spdb%")OR LIKE (process_exec, "%StickyPassword%")OR LIKE (process_exec, "%.walletx%")OR LIKE (process_exec, "%enpass%")OR LIKE (process_exec, "%vault%")OR LIKE (process_exec, "%.kdb%")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_find_credentials_from_password_managers_filter`' how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed known_false_positives: Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. references: @@ -20,7 +27,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -40,7 +52,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1555.005 - - T1555 product: - Splunk Enterprise - Splunk Enterprise Security @@ -49,6 +60,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555.005/linux_auditd_find_password_db/linux_auditd_find_password_db.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555.005/linux_auditd_find_password_db/linux_auditd_find_password_db.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_find_credentials_from_password_stores.yml b/detections/endpoint/linux_auditd_find_credentials_from_password_stores.yml index 6332592a94..9ae67754ae 100644 --- a/detections/endpoint/linux_auditd_find_credentials_from_password_stores.yml +++ b/detections/endpoint/linux_auditd_find_credentials_from_password_stores.yml @@ -1,16 +1,38 @@ name: Linux Auditd Find Credentials From Password Stores id: 4de73044-9a1d-4a51-a1c2-85267d8dcab3 -version: 3 -date: '2025-01-16' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP -description: The following analytic detects suspicious attempts to find credentials stored in password stores, indicating a potential attacker's effort to access sensitive login information. Password stores are critical repositories that contain valuable credentials, and unauthorized access to them can lead to significant security breaches. By monitoring for unusual or unauthorized activities related to password store access, this analytic helps identify potential credential theft attempts, allowing security teams to respond promptly and prevent unauthorized access to critical systems and data. +description: The following analytic detects suspicious attempts to find credentials + stored in password stores, indicating a potential attacker's effort to access sensitive + login information. Password stores are critical repositories that contain valuable + credentials, and unauthorized access to them can lead to significant security breaches. + By monitoring for unusual or unauthorized activities related to password store access, + this analytic helps identify potential credential theft attempts, allowing security + teams to respond promptly and prevent unauthorized access to critical systems and + data. data_source: - Linux Auditd Execve -search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%password%") OR LIKE (process_exec, "%pass %") OR LIKE (process_exec, "%credential%")OR LIKE (process_exec, "%creds%")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_find_credentials_from_password_stores_filter`' -how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed -known_false_positives: Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. +search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as + dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, + "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%password%") + OR LIKE (process_exec, "%pass %") OR LIKE (process_exec, "%credential%")OR LIKE + (process_exec, "%creds%")) | stats count min(_time) as firstTime max(_time) as lastTime + by argc process_exec dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| + `linux_auditd_find_credentials_from_password_stores_filter`' +how_to_implement: To implement this detection, the process begins by ingesting auditd + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + which is essential for correctly parsing and categorizing the data. The next step + involves normalizing the field names to match the field names set by the Splunk + Common Information Model (CIM) to ensure consistency across different data sources + and enhance the efficiency of data modeling. This approach enables effective monitoring + and detection of linux endpoints where auditd is deployed +known_false_positives: Administrator or network operator can use this application + for automation purposes. Please update the filter macros to remove false positives. references: - https://www.splunk.com/en_us/blog/security/deep-dive-on-persistence-privilege-escalation-technique-and-detection-in-linux-platform.html - https://github.com/peass-ng/PEASS-ng/tree/master/linPEAS @@ -20,7 +42,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -40,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1555.005 - - T1555 product: - Splunk Enterprise - Splunk Enterprise Security @@ -49,6 +75,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555.005/linux_auditd_find_credentials/linux_auditd_find_credentials.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555.005/linux_auditd_find_credentials/linux_auditd_find_credentials.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_find_ssh_private_keys.yml b/detections/endpoint/linux_auditd_find_ssh_private_keys.yml index 8788828cc2..96e7d7d952 100644 --- a/detections/endpoint/linux_auditd_find_ssh_private_keys.yml +++ b/detections/endpoint/linux_auditd_find_ssh_private_keys.yml @@ -1,16 +1,38 @@ name: Linux Auditd Find Ssh Private Keys id: e2d2bd10-dcd1-4b2f-8a76-0198eab32ba5 -version: 3 -date: '2025-01-16' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly -description: The following analytic detects suspicious attempts to find SSH private keys, which may indicate an attacker's effort to compromise secure access to systems. SSH private keys are essential for secure authentication, and unauthorized access to these keys can enable attackers to gain unauthorized access to servers and other critical infrastructure. By monitoring for unusual or unauthorized searches for SSH private keys, this analytic helps identify potential threats to network security, allowing security teams to quickly respond and safeguard against unauthorized access and potential breaches. +description: The following analytic detects suspicious attempts to find SSH private + keys, which may indicate an attacker's effort to compromise secure access to systems. + SSH private keys are essential for secure authentication, and unauthorized access + to these keys can enable attackers to gain unauthorized access to servers and other + critical infrastructure. By monitoring for unusual or unauthorized searches for + SSH private keys, this analytic helps identify potential threats to network security, + allowing security teams to quickly respond and safeguard against unauthorized access + and potential breaches. data_source: - Linux Auditd Execve -search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%id_rsa%") OR LIKE (process_exec, "%id_dsa%")OR LIKE (process_exec, "%.key%") OR LIKE (process_exec, "%ssh_key%")OR LIKE (process_exec, "%authorized_keys%")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_find_ssh_private_keys_filter`' -how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed -known_false_positives: Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. +search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as + dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, + "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%id_rsa%") + OR LIKE (process_exec, "%id_dsa%")OR LIKE (process_exec, "%.key%") OR LIKE (process_exec, + "%ssh_key%")OR LIKE (process_exec, "%authorized_keys%")) | stats count min(_time) + as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`| `linux_auditd_find_ssh_private_keys_filter`' +how_to_implement: To implement this detection, the process begins by ingesting auditd + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + which is essential for correctly parsing and categorizing the data. The next step + involves normalizing the field names to match the field names set by the Splunk + Common Information Model (CIM) to ensure consistency across different data sources + and enhance the efficiency of data modeling. This approach enables effective monitoring + and detection of linux endpoints where auditd is deployed +known_false_positives: Administrator or network operator can use this application + for automation purposes. Please update the filter macros to remove false positives. references: - https://www.splunk.com/en_us/blog/security/deep-dive-on-persistence-privilege-escalation-technique-and-detection-in-linux-platform.html - https://github.com/peass-ng/PEASS-ng/tree/master/linPEAS @@ -20,7 +42,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -40,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.004 - - T1552 product: - Splunk Enterprise - Splunk Enterprise Security @@ -49,6 +75,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.004/linux_auditd_find_ssh_files/linux_auditd_find_ssh_files.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.004/linux_auditd_find_ssh_files/linux_auditd_find_ssh_files.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_hidden_files_and_directories_creation.yml b/detections/endpoint/linux_auditd_hidden_files_and_directories_creation.yml index f888933bba..483150c621 100644 --- a/detections/endpoint/linux_auditd_hidden_files_and_directories_creation.yml +++ b/detections/endpoint/linux_auditd_hidden_files_and_directories_creation.yml @@ -1,10 +1,10 @@ name: Linux Auditd Hidden Files And Directories Creation id: 555cc358-bf16-4e05-9b3a-0f89c73b7261 -version: 4 -date: '2025-01-16' +version: 5 +date: '2025-02-03' author: Teoderick Contreras, Splunk status: production -type: TTP +type: Anomaly description: The following analytic detects suspicious creation of hidden files and directories, which may indicate an attacker's attempt to conceal malicious activities or unauthorized data. Hidden files and directories are often used to evade detection by security tools and administrators, providing a stealthy means for storing malware, logs, or sensitive information. By monitoring for unusual or unauthorized creation of hidden files and directories, this analytic helps identify potential attempts to hide or unauthorized creation of hidden files and directories, this analytic helps identify potential attempts to hide malicious operations, enabling security teams to uncover and address hidden threats effectively. data_source: - Linux Auditd Execve @@ -28,7 +28,7 @@ rba: risk_objects: - field: dest type: system - score: 64 + score: 30 threat_objects: [] tags: analytic_story: diff --git a/detections/endpoint/linux_auditd_insert_kernel_module_using_insmod_utility.yml b/detections/endpoint/linux_auditd_insert_kernel_module_using_insmod_utility.yml index 10a1cc21ad..0b168373bc 100644 --- a/detections/endpoint/linux_auditd_insert_kernel_module_using_insmod_utility.yml +++ b/detections/endpoint/linux_auditd_insert_kernel_module_using_insmod_utility.yml @@ -1,7 +1,7 @@ name: Linux Auditd Insert Kernel Module Using Insmod Utility id: bc0ca53f-dea6-4906-9b12-09c396fdf1d3 -version: 4 -date: '2024-12-19' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -19,9 +19,9 @@ search: '`linux_auditd` type=SYSCALL comm=insmod | rename host as dest | stats c success dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_insert_kernel_module_using_insmod_utility_filter`' how_to_implement: To implement this detection, the process begins by ingesting auditd - data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line - executions and process details on Unix/Linux systems. These logs should be ingested - and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.006 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_install_kernel_module_using_modprobe_utility.yml b/detections/endpoint/linux_auditd_install_kernel_module_using_modprobe_utility.yml index 29a1db8488..a57cd34a93 100644 --- a/detections/endpoint/linux_auditd_install_kernel_module_using_modprobe_utility.yml +++ b/detections/endpoint/linux_auditd_install_kernel_module_using_modprobe_utility.yml @@ -1,16 +1,34 @@ name: Linux Auditd Install Kernel Module Using Modprobe Utility id: 95165985-ace5-4d42-9c42-93a89a5af901 -version: 3 -date: '2025-01-20' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly -description: The following analytic detects the installation of a Linux kernel module using the modprobe utility. It leverages data from Linux Auditd, focusing on process names and command-line executions. This activity is significant because installing a kernel module can indicate an attempt to deploy a rootkit or other malicious kernel-level code, potentially leading to elevated privileges and bypassing security detections. If confirmed malicious, this could allow an attacker to gain persistent, high-level access to the system, compromising its integrity and security. +description: The following analytic detects the installation of a Linux kernel module + using the modprobe utility. It leverages data from Linux Auditd, focusing on process + names and command-line executions. This activity is significant because installing + a kernel module can indicate an attempt to deploy a rootkit or other malicious kernel-level + code, potentially leading to elevated privileges and bypassing security detections. + If confirmed malicious, this could allow an attacker to gain persistent, high-level + access to the system, compromising its integrity and security. data_source: - Linux Auditd Syscall -search: '`linux_auditd` type=SYSCALL comm=modprobe | rename host as dest | stats count min(_time) as firstTime max(_time) as lastTime by comm exe SYSCALL UID ppid pid success dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `linux_auditd_install_kernel_module_using_modprobe_utility_filter`' -how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed -known_false_positives: Administrator or network operator can execute this command. Please update the filter macros to remove false positives. +search: '`linux_auditd` type=SYSCALL comm=modprobe | rename host as dest | stats count + min(_time) as firstTime max(_time) as lastTime by comm exe SYSCALL UID ppid pid + success dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| + `linux_auditd_install_kernel_module_using_modprobe_utility_filter`' +how_to_implement: To implement this detection, the process begins by ingesting auditd + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + which is essential for correctly parsing and categorizing the data. The next step + involves normalizing the field names to match the field names set by the Splunk + Common Information Model (CIM) to ensure consistency across different data sources + and enhance the efficiency of data modeling. This approach enables effective monitoring + and detection of linux endpoints where auditd is deployed +known_false_positives: Administrator or network operator can execute this command. + Please update the filter macros to remove false positives. references: - https://docs.fedoraproject.org/en-US/fedora/rawhide/system-administrators-guide/kernel-module-driver-configuration/Working_with_Kernel_Modules/ - https://security.stackexchange.com/questions/175953/how-to-load-a-malicious-lkm-at-startup @@ -21,7 +39,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -41,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.006 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security @@ -50,6 +72,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.006/linux_auditd_modprobe/linux_auditd_modprobe.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.006/linux_auditd_modprobe/linux_auditd_modprobe.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_kernel_module_using_rmmod_utility.yml b/detections/endpoint/linux_auditd_kernel_module_using_rmmod_utility.yml index 85736a7952..0d437219d2 100644 --- a/detections/endpoint/linux_auditd_kernel_module_using_rmmod_utility.yml +++ b/detections/endpoint/linux_auditd_kernel_module_using_rmmod_utility.yml @@ -1,7 +1,7 @@ name: Linux Auditd Kernel Module Using Rmmod Utility id: 31810b7a-0abe-42be-a210-0dec8106afee -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.006 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_nopasswd_entry_in_sudoers_file.yml b/detections/endpoint/linux_auditd_nopasswd_entry_in_sudoers_file.yml index b0d9f8aa6c..2470ddfe8f 100644 --- a/detections/endpoint/linux_auditd_nopasswd_entry_in_sudoers_file.yml +++ b/detections/endpoint/linux_auditd_nopasswd_entry_in_sudoers_file.yml @@ -1,7 +1,7 @@ name: Linux Auditd Nopasswd Entry In Sudoers File id: 651df959-ad17-4b73-a323-90cb96d5fa1b -version: 4 -date: '2025-01-27' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security @@ -74,6 +73,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_nopasswd/linux_auditd_nopasswd.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_nopasswd/linux_auditd_nopasswd.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_possible_access_or_modification_of_sshd_config_file.yml b/detections/endpoint/linux_auditd_possible_access_or_modification_of_sshd_config_file.yml index 965112d606..a9323c6d19 100644 --- a/detections/endpoint/linux_auditd_possible_access_or_modification_of_sshd_config_file.yml +++ b/detections/endpoint/linux_auditd_possible_access_or_modification_of_sshd_config_file.yml @@ -1,7 +1,7 @@ name: Linux Auditd Possible Access Or Modification Of Sshd Config File id: acb3ea33-70f7-47aa-b335-643b3aebcb2f -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1098.004 - - T1098 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_possible_access_to_credential_files.yml b/detections/endpoint/linux_auditd_possible_access_to_credential_files.yml index 499e0a23bb..62158c07f3 100644 --- a/detections/endpoint/linux_auditd_possible_access_to_credential_files.yml +++ b/detections/endpoint/linux_auditd_possible_access_to_credential_files.yml @@ -1,7 +1,7 @@ name: Linux Auditd Possible Access To Credential Files id: 0419cb7a-57ea-467b-974f-77c303dfe2a3 -version: 4 -date: '2025-01-27' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.008 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security @@ -76,6 +75,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/linux_auditd_access_credential/linux_auditd_access_credential.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/linux_auditd_access_credential/linux_auditd_access_credential.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_possible_access_to_sudoers_file.yml b/detections/endpoint/linux_auditd_possible_access_to_sudoers_file.yml index 8dda7e5e89..ce58e5dae8 100644 --- a/detections/endpoint/linux_auditd_possible_access_to_sudoers_file.yml +++ b/detections/endpoint/linux_auditd_possible_access_to_sudoers_file.yml @@ -1,7 +1,7 @@ name: Linux Auditd Possible Access To Sudoers File id: 8be88f46-f7e8-4ae6-b15e-cf1b13392834 -version: 4 -date: '2025-01-27' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security @@ -73,6 +72,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_sudoers_access/linux_auditd_sudoers_access.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_sudoers_access/linux_auditd_sudoers_access.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_possible_append_cronjob_entry_on_existing_cronjob_file.yml b/detections/endpoint/linux_auditd_possible_append_cronjob_entry_on_existing_cronjob_file.yml index d80e3059c5..7fac278e2a 100644 --- a/detections/endpoint/linux_auditd_possible_append_cronjob_entry_on_existing_cronjob_file.yml +++ b/detections/endpoint/linux_auditd_possible_append_cronjob_entry_on_existing_cronjob_file.yml @@ -1,7 +1,7 @@ name: Linux Auditd Possible Append Cronjob Entry On Existing Cronjob File id: fea71cf0-fa10-4ef6-9202-9682b2e0c477 -version: 4 -date: '2025-01-20' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -19,9 +19,9 @@ search: '`linux_auditd` type=PATH name IN("*/etc/cron*", "*/var/spool/cron/*", " by name nametype OGID dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `linux_auditd_possible_append_cronjob_entry_on_existing_cronjob_file_filter`' how_to_implement: To implement this detection, the process begins by ingesting auditd - data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line - executions and process details on Unix/Linux systems. These logs should be ingested - and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources @@ -45,7 +45,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.003 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_preload_hijack_library_calls.yml b/detections/endpoint/linux_auditd_preload_hijack_library_calls.yml index fdfa38e184..8eb1a95ce2 100644 --- a/detections/endpoint/linux_auditd_preload_hijack_library_calls.yml +++ b/detections/endpoint/linux_auditd_preload_hijack_library_calls.yml @@ -1,7 +1,7 @@ name: Linux Auditd Preload Hijack Library Calls id: 35c50572-a70b-452f-afa9-bebdf3c3ce36 -version: 4 -date: '2025-01-27' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.006 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security @@ -74,6 +73,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/linux_auditd_ldpreload/linux_auditd_ldpreload.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/linux_auditd_ldpreload/linux_auditd_ldpreload.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_preload_hijack_via_preload_file.yml b/detections/endpoint/linux_auditd_preload_hijack_via_preload_file.yml index 2d5b8c3d5e..d850271d2d 100644 --- a/detections/endpoint/linux_auditd_preload_hijack_via_preload_file.yml +++ b/detections/endpoint/linux_auditd_preload_hijack_via_preload_file.yml @@ -1,7 +1,7 @@ name: Linux Auditd Preload Hijack Via Preload File id: c1b7abca-55cb-4a39-bdfb-e28c1c12745f -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -47,7 +47,8 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: A [$type$] event has occurred on host - [$dest$] to modify the preload file. + message: A [$type$] event has occurred on host - [$dest$] to modify the preload + file. risk_objects: - field: dest type: system @@ -62,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.006 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_private_keys_and_certificate_enumeration.yml b/detections/endpoint/linux_auditd_private_keys_and_certificate_enumeration.yml index 29d3189d49..3734df8760 100644 --- a/detections/endpoint/linux_auditd_private_keys_and_certificate_enumeration.yml +++ b/detections/endpoint/linux_auditd_private_keys_and_certificate_enumeration.yml @@ -1,16 +1,40 @@ name: Linux Auditd Private Keys and Certificate Enumeration id: 892eb674-3344-4143-8e52-4775b1daf3f1 -version: 1 -date: '2025-01-15' +version: 2 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly -description: The following analytic detects suspicious attempts to find private keys, which may indicate an attacker's effort to access sensitive cryptographic information. Private keys are crucial for securing encrypted communications and data, and unauthorized access to them can lead to severe security breaches, including data decryption and identity theft. By monitoring for unusual or unauthorized searches for private keys, this analytic helps identify potential threats to cryptographic security, enabling security teams to take swift action to protect the integrity and confidentiality of encrypted information. +description: The following analytic detects suspicious attempts to find private keys, + which may indicate an attacker's effort to access sensitive cryptographic information. + Private keys are crucial for securing encrypted communications and data, and unauthorized + access to them can lead to severe security breaches, including data decryption and + identity theft. By monitoring for unusual or unauthorized searches for private keys, + this analytic helps identify potential threats to cryptographic security, enabling + security teams to take swift action to protect the integrity and confidentiality + of encrypted information. data_source: - Linux Auditd Execve -search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%.pem%") OR LIKE (process_exec, "%.cer%") OR LIKE (process_exec, "%.crt%") OR LIKE (process_exec, "%.pgp%") OR LIKE (process_exec, "%.key%") OR LIKE (process_exec, "%.gpg%")OR LIKE (process_exec, "%.ppk%") OR LIKE (process_exec, "%.p12%") OR LIKE (process_exec, "%.pfx%")OR LIKE (process_exec, "%.p7b%")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_private_keys_and_certificate_enumeration_filter`' -how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed -known_false_positives: Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. +search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as + dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, + "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%.pem%") OR + LIKE (process_exec, "%.cer%") OR LIKE (process_exec, "%.crt%") OR LIKE (process_exec, + "%.pgp%") OR LIKE (process_exec, "%.key%") OR LIKE (process_exec, "%.gpg%")OR LIKE + (process_exec, "%.ppk%") OR LIKE (process_exec, "%.p12%") OR LIKE (process_exec, + "%.pfx%")OR LIKE (process_exec, "%.p7b%")) | stats count min(_time) as firstTime + max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`| `linux_auditd_private_keys_and_certificate_enumeration_filter`' +how_to_implement: To implement this detection, the process begins by ingesting auditd + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + which is essential for correctly parsing and categorizing the data. The next step + involves normalizing the field names to match the field names set by the Splunk + Common Information Model (CIM) to ensure consistency across different data sources + and enhance the efficiency of data modeling. This approach enables effective monitoring + and detection of linux endpoints where auditd is deployed +known_false_positives: Administrator or network operator can use this application + for automation purposes. Please update the filter macros to remove false positives. references: - https://www.splunk.com/en_us/blog/security/deep-dive-on-persistence-privilege-escalation-technique-and-detection-in-linux-platform.html - https://github.com/peass-ng/PEASS-ng/tree/master/linPEAS @@ -20,7 +44,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -39,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.004 - - T1552 product: - Splunk Enterprise - Splunk Enterprise Security @@ -48,6 +76,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.004/linux_auditd_find_gpg/linux_auditd_find_gpg.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.004/linux_auditd_find_gpg/linux_auditd_find_gpg.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_service_restarted.yml b/detections/endpoint/linux_auditd_service_restarted.yml index a619b94f79..63fbdd633c 100644 --- a/detections/endpoint/linux_auditd_service_restarted.yml +++ b/detections/endpoint/linux_auditd_service_restarted.yml @@ -1,7 +1,7 @@ name: Linux Auditd Service Restarted id: 8eb3e858-18d3-44a4-a514-52cfa39f154a -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.006 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_service_started.yml b/detections/endpoint/linux_auditd_service_started.yml index 2e878c1779..d157eebc41 100644 --- a/detections/endpoint/linux_auditd_service_started.yml +++ b/detections/endpoint/linux_auditd_service_started.yml @@ -1,10 +1,10 @@ name: Linux Auditd Service Started id: b5eed06d-5c97-4092-a3a1-fa4b7e77c71a -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-03' author: Teoderick Contreras, Splunk status: production -type: TTP +type: Anomaly description: The following analytic detects the suspicious service started. This behavior is critical for a SOC to monitor because it may indicate attempts to gain unauthorized access or maintain control over a system. Such actions could be signs of malicious @@ -53,7 +53,7 @@ rba: risk_objects: - field: dest type: system - score: 64 + score: 40 threat_objects: [] tags: analytic_story: @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1569.002 - - T1569 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_setuid_using_chmod_utility.yml b/detections/endpoint/linux_auditd_setuid_using_chmod_utility.yml index 7c32e22160..db1157d54e 100644 --- a/detections/endpoint/linux_auditd_setuid_using_chmod_utility.yml +++ b/detections/endpoint/linux_auditd_setuid_using_chmod_utility.yml @@ -1,7 +1,7 @@ name: Linux Auditd Setuid Using Chmod Utility id: 8230c407-1b47-4d95-ac2e-718bd6381386 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.001 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_setuid_using_setcap_utility.yml b/detections/endpoint/linux_auditd_setuid_using_setcap_utility.yml index df8cc3f4ae..08a69f6ca0 100644 --- a/detections/endpoint/linux_auditd_setuid_using_setcap_utility.yml +++ b/detections/endpoint/linux_auditd_setuid_using_setcap_utility.yml @@ -1,16 +1,38 @@ name: Linux Auditd Setuid Using Setcap Utility id: 1474459a-302b-4255-8add-d82f96d14cd9 -version: 3 -date: '2025-01-16' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP -description: The following analytic detects the execution of the 'setcap' utility to enable the SUID bit on Linux systems. It leverages Linux Auditd data, focusing on process names and command-line arguments that indicate the use of 'setcap' with specific capabilities. This activity is significant because setting the SUID bit allows a user to temporarily gain root access, posing a substantial security risk. If confirmed malicious, an attacker could escalate privileges, execute arbitrary commands with elevated permissions, and potentially compromise the entire system. +description: The following analytic detects the execution of the 'setcap' utility + to enable the SUID bit on Linux systems. It leverages Linux Auditd data, focusing + on process names and command-line arguments that indicate the use of 'setcap' with + specific capabilities. This activity is significant because setting the SUID bit + allows a user to temporarily gain root access, posing a substantial security risk. + If confirmed malicious, an attacker could escalate privileges, execute arbitrary + commands with elevated permissions, and potentially compromise the entire system. data_source: - Linux Auditd Execve -search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where LIKE (process_exec, "%setcap %") AND (LIKE (process_exec, "% cap_setuid+ep %") OR LIKE (process_exec, "% cap_setuid=ep %") OR LIKE (process_exec, "% cap_net_bind_service+p %") OR LIKE (process_exec, "% cap_net_raw+ep %") OR LIKE (process_exec, "% cap_dac_read_search+ep %")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `linux_auditd_setuid_using_setcap_utility_filter`' -how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed -known_false_positives: Administrator or network operator can execute this command. Please update the filter macros to remove false positives. +search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as + dest | rename comm as process_name | rename exe as process | where LIKE (process_exec, + "%setcap %") AND (LIKE (process_exec, "% cap_setuid+ep %") OR LIKE (process_exec, + "% cap_setuid=ep %") OR LIKE (process_exec, "% cap_net_bind_service+p %") OR LIKE + (process_exec, "% cap_net_raw+ep %") OR LIKE (process_exec, "% cap_dac_read_search+ep + %")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec + dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| + `linux_auditd_setuid_using_setcap_utility_filter`' +how_to_implement: To implement this detection, the process begins by ingesting auditd + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + which is essential for correctly parsing and categorizing the data. The next step + involves normalizing the field names to match the field names set by the Splunk + Common Information Model (CIM) to ensure consistency across different data sources + and enhance the efficiency of data modeling. This approach enables effective monitoring + and detection of linux endpoints where auditd is deployed +known_false_positives: Administrator or network operator can execute this command. + Please update the filter macros to remove false positives. references: - https://www.hackingarticles.in/linux-privilege-escalation-using-capabilities/ drilldown_searches: @@ -19,7 +41,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -38,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.001 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security @@ -47,6 +73,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/linux_auditd_setuid/linux_auditd_setcap_priv.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/linux_auditd_setuid/linux_auditd_setcap_priv.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_sudo_or_su_execution.yml b/detections/endpoint/linux_auditd_sudo_or_su_execution.yml index b53ed7ef6c..ebf46c26c5 100644 --- a/detections/endpoint/linux_auditd_sudo_or_su_execution.yml +++ b/detections/endpoint/linux_auditd_sudo_or_su_execution.yml @@ -1,16 +1,35 @@ name: Linux Auditd Sudo Or Su Execution id: 817a5c89-5b92-4818-a22d-aa35e1361afe -version: 3 -date: '2025-01-20' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly -description: The following analytic detects the execution of the "sudo" or "su" command on a Linux operating system. It leverages data from Linux Auditd, focusing on process names and parent process names. This activity is significant because "sudo" and "su" commands are commonly used by adversaries to elevate privileges, potentially leading to unauthorized access or control over the system. If confirmed malicious, this activity could allow attackers to execute commands with root privileges, leading to severe security breaches, data exfiltration, or further system compromise. +description: The following analytic detects the execution of the "sudo" or "su" command + on a Linux operating system. It leverages data from Linux Auditd, focusing on process + names and parent process names. This activity is significant because "sudo" and + "su" commands are commonly used by adversaries to elevate privileges, potentially + leading to unauthorized access or control over the system. If confirmed malicious, + this activity could allow attackers to execute commands with root privileges, leading + to severe security breaches, data exfiltration, or further system compromise. data_source: - Linux Auditd Proctitle -search: '`linux_auditd` `linux_auditd_normalized_proctitle_process` | rename host as dest | where LIKE(process_exec, "%sudo %") OR LIKE(process_exec, "%su %") | stats count min(_time) as firstTime max(_time) as lastTime by process_exec proctitle normalized_proctitle_delimiter dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_sudo_or_su_execution_filter`' -how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed -known_false_positives: Administrator or network operator can execute this command. Please update the filter macros to remove false positives. +search: '`linux_auditd` `linux_auditd_normalized_proctitle_process` | rename host + as dest | where LIKE(process_exec, "%sudo %") OR LIKE(process_exec, "%su %") | stats + count min(_time) as firstTime max(_time) as lastTime by process_exec proctitle normalized_proctitle_delimiter + dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| + `linux_auditd_sudo_or_su_execution_filter`' +how_to_implement: To implement this detection, the process begins by ingesting auditd + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + which is essential for correctly parsing and categorizing the data. The next step + involves normalizing the field names to match the field names set by the Splunk + Common Information Model (CIM) to ensure consistency across different data sources + and enhance the efficiency of data modeling. This approach enables effective monitoring + and detection of linux endpoints where auditd is deployed +known_false_positives: Administrator or network operator can execute this command. + Please update the filter macros to remove false positives. references: - https://attack.mitre.org/techniques/T1548/003/ drilldown_searches: @@ -19,7 +38,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -38,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security @@ -47,6 +70,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_sudo_su/linux_auditd_sudo_su.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_sudo_su/linux_auditd_sudo_su.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_unix_shell_configuration_modification.yml b/detections/endpoint/linux_auditd_unix_shell_configuration_modification.yml index 50d90725bc..664416e29d 100644 --- a/detections/endpoint/linux_auditd_unix_shell_configuration_modification.yml +++ b/detections/endpoint/linux_auditd_unix_shell_configuration_modification.yml @@ -1,7 +1,7 @@ name: Linux Auditd Unix Shell Configuration Modification id: 66f737c6-3f7f-46ed-8e9b-cc0e5bf01f04 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.004 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_unload_module_via_modprobe.yml b/detections/endpoint/linux_auditd_unload_module_via_modprobe.yml index d3f5d76e2e..cdd0c0c95c 100644 --- a/detections/endpoint/linux_auditd_unload_module_via_modprobe.yml +++ b/detections/endpoint/linux_auditd_unload_module_via_modprobe.yml @@ -1,16 +1,36 @@ name: Linux Auditd Unload Module Via Modprobe id: 90964d6a-4b5f-409a-85bd-95e261e03fe9 -version: 3 -date: '2025-01-16' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP -description: The following analytic detects suspicious use of the `modprobe` command to unload kernel modules, which may indicate an attempt to disable critical system components or evade detection. The `modprobe` utility manages kernel modules, and unauthorized unloading of modules can disrupt system security features, remove logging capabilities, or conceal malicious activities. By monitoring for unusual or unauthorized `modprobe` operations involving module unloading, this analytic helps identify potential tampering with kernel functionality, enabling security teams to investigate and address possible threats to system integrity. +description: The following analytic detects suspicious use of the `modprobe` command + to unload kernel modules, which may indicate an attempt to disable critical system + components or evade detection. The `modprobe` utility manages kernel modules, and + unauthorized unloading of modules can disrupt system security features, remove logging + capabilities, or conceal malicious activities. By monitoring for unusual or unauthorized + `modprobe` operations involving module unloading, this analytic helps identify potential + tampering with kernel functionality, enabling security teams to investigate and + address possible threats to system integrity. data_source: - Linux Auditd Execve -search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where LIKE (process_exec, "%modprobe%") AND LIKE (process_exec, "%-r %") | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `linux_auditd_unload_module_via_modprobe_filter`' -how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed -known_false_positives: Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. +search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as + dest | rename comm as process_name | rename exe as process | where LIKE (process_exec, + "%modprobe%") AND LIKE (process_exec, "%-r %") | stats count min(_time) as firstTime + max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)`| + `security_content_ctime(lastTime)`| `linux_auditd_unload_module_via_modprobe_filter`' +how_to_implement: To implement this detection, the process begins by ingesting auditd + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + which is essential for correctly parsing and categorizing the data. The next step + involves normalizing the field names to match the field names set by the Splunk + Common Information Model (CIM) to ensure consistency across different data sources + and enhance the efficiency of data modeling. This approach enables effective monitoring + and detection of linux endpoints where auditd is deployed +known_false_positives: Administrator or network operator can use this application + for automation purposes. Please update the filter macros to remove false positives. references: - https://www.splunk.com/en_us/blog/security/deep-dive-on-persistence-privilege-escalation-technique-and-detection-in-linux-platform.html drilldown_searches: @@ -19,7 +39,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -39,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.006 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security @@ -48,6 +72,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.006/linux_auditd_modprobe_unload_module/linux_auditd_modprobe_unload_module.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.006/linux_auditd_modprobe_unload_module/linux_auditd_modprobe_unload_module.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_awk_privilege_escalation.yml b/detections/endpoint/linux_awk_privilege_escalation.yml index 1036c94106..412b476eef 100644 --- a/detections/endpoint/linux_awk_privilege_escalation.yml +++ b/detections/endpoint/linux_awk_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux AWK Privilege Escalation id: 4510cae0-96a2-4840-9919-91d262db210a -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_busybox_privilege_escalation.yml b/detections/endpoint/linux_busybox_privilege_escalation.yml index f6bbd0bde7..74ea49e117 100644 --- a/detections/endpoint/linux_busybox_privilege_escalation.yml +++ b/detections/endpoint/linux_busybox_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Busybox Privilege Escalation id: 387c4e78-f4a4-413d-ad44-e9f7bc4642c9 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_c89_privilege_escalation.yml b/detections/endpoint/linux_c89_privilege_escalation.yml index 3919b610e8..229db8dfc8 100644 --- a/detections/endpoint/linux_c89_privilege_escalation.yml +++ b/detections/endpoint/linux_c89_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux c89 Privilege Escalation id: 54c95f4d-3e5d-44be-9521-ea19ba62f7a8 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_c99_privilege_escalation.yml b/detections/endpoint/linux_c99_privilege_escalation.yml index 9e76c91bfe..6456f1654a 100644 --- a/detections/endpoint/linux_c99_privilege_escalation.yml +++ b/detections/endpoint/linux_c99_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux c99 Privilege Escalation id: e1c6dec5-2249-442d-a1f9-99a4bd228183 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_change_file_owner_to_root.yml b/detections/endpoint/linux_change_file_owner_to_root.yml index 89b8695a26..0135aa468d 100644 --- a/detections/endpoint/linux_change_file_owner_to_root.yml +++ b/detections/endpoint/linux_change_file_owner_to_root.yml @@ -1,7 +1,7 @@ name: Linux Change File Owner To Root id: c1400ea2-6257-11ec-ad49-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1222.002 - - T1222 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_common_process_for_elevation_control.yml b/detections/endpoint/linux_common_process_for_elevation_control.yml index 9bcb78b36d..221f4c30c6 100644 --- a/detections/endpoint/linux_common_process_for_elevation_control.yml +++ b/detections/endpoint/linux_common_process_for_elevation_control.yml @@ -1,7 +1,7 @@ name: Linux Common Process For Elevation Control id: 66ab15c0-63d0-11ec-9e70-acde48001122 -version: 5 -date: '2025-01-27' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -52,7 +52,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.001 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security @@ -61,6 +60,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/chmod_uid/sysmon_linux.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/chmod_uid/sysmon_linux.log source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux diff --git a/detections/endpoint/linux_composer_privilege_escalation.yml b/detections/endpoint/linux_composer_privilege_escalation.yml index 4128c46843..d3303e4046 100644 --- a/detections/endpoint/linux_composer_privilege_escalation.yml +++ b/detections/endpoint/linux_composer_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Composer Privilege Escalation id: a3bddf71-6ba3-42ab-a6b2-396929b16d92 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_cpulimit_privilege_escalation.yml b/detections/endpoint/linux_cpulimit_privilege_escalation.yml index 2d565e6a8b..42c898b210 100644 --- a/detections/endpoint/linux_cpulimit_privilege_escalation.yml +++ b/detections/endpoint/linux_cpulimit_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Cpulimit Privilege Escalation id: d4e40b7e-aad3-4a7d-aac8-550ea5222be5 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_csvtool_privilege_escalation.yml b/detections/endpoint/linux_csvtool_privilege_escalation.yml index 0b4a4ed4b6..4c17cce459 100644 --- a/detections/endpoint/linux_csvtool_privilege_escalation.yml +++ b/detections/endpoint/linux_csvtool_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Csvtool Privilege Escalation id: f8384f9e-1a5c-4c3a-96d6-8a7e5a38a8b8 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_data_destruction_command.yml b/detections/endpoint/linux_data_destruction_command.yml index 0ed0562b5d..d995933ae4 100644 --- a/detections/endpoint/linux_data_destruction_command.yml +++ b/detections/endpoint/linux_data_destruction_command.yml @@ -1,6 +1,6 @@ name: Linux Data Destruction Command id: b11d3979-b2f7-411b-bb1a-bd00e642173b -version: 4 +version: 5 date: '2024-11-13' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/linux_decode_base64_to_shell.yml b/detections/endpoint/linux_decode_base64_to_shell.yml index a60cd9db88..a332d7535a 100644 --- a/detections/endpoint/linux_decode_base64_to_shell.yml +++ b/detections/endpoint/linux_decode_base64_to_shell.yml @@ -1,6 +1,6 @@ name: Linux Decode Base64 to Shell id: 637b603e-1799-40fd-bf87-47ecbd551b66 -version: 6 +version: 7 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/linux_deletion_of_cron_jobs.yml b/detections/endpoint/linux_deletion_of_cron_jobs.yml index 6c57aa65d9..0e75efa4a7 100644 --- a/detections/endpoint/linux_deletion_of_cron_jobs.yml +++ b/detections/endpoint/linux_deletion_of_cron_jobs.yml @@ -1,7 +1,7 @@ name: Linux Deletion Of Cron Jobs id: 3b132a71-9335-4f33-9932-00bb4f6ac7e8 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -57,9 +57,8 @@ tags: - AcidPour asset_type: Endpoint mitre_attack_id: - - T1485 - T1070.004 - - T1070 + - T1485 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_deletion_of_init_daemon_script.yml b/detections/endpoint/linux_deletion_of_init_daemon_script.yml index 98d166fbbf..339d58c50b 100644 --- a/detections/endpoint/linux_deletion_of_init_daemon_script.yml +++ b/detections/endpoint/linux_deletion_of_init_daemon_script.yml @@ -1,7 +1,7 @@ name: Linux Deletion Of Init Daemon Script id: 729aab57-d26f-4156-b97f-ab8dda8f44b1 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -57,9 +57,8 @@ tags: - AcidPour asset_type: Endpoint mitre_attack_id: - - T1485 - T1070.004 - - T1070 + - T1485 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_deletion_of_services.yml b/detections/endpoint/linux_deletion_of_services.yml index 0105dcf5c9..2d27e43f5b 100644 --- a/detections/endpoint/linux_deletion_of_services.yml +++ b/detections/endpoint/linux_deletion_of_services.yml @@ -1,7 +1,7 @@ name: Linux Deletion Of Services id: b509bbd3-0331-4aaa-8e4a-d2affe100af6 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -62,9 +62,8 @@ tags: - AcidPour asset_type: Endpoint mitre_attack_id: - - T1485 - T1070.004 - - T1070 + - T1485 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_deletion_of_ssl_certificate.yml b/detections/endpoint/linux_deletion_of_ssl_certificate.yml index 3742f9eeed..94765cb179 100644 --- a/detections/endpoint/linux_deletion_of_ssl_certificate.yml +++ b/detections/endpoint/linux_deletion_of_ssl_certificate.yml @@ -1,7 +1,7 @@ name: Linux Deletion of SSL Certificate id: 839ab790-a60a-4f81-bfb3-02567063f615 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -58,9 +58,8 @@ tags: - AcidPour asset_type: Endpoint mitre_attack_id: - - T1485 - T1070.004 - - T1070 + - T1485 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_doas_conf_file_creation.yml b/detections/endpoint/linux_doas_conf_file_creation.yml index 5acb1dff95..8dfac80ecc 100644 --- a/detections/endpoint/linux_doas_conf_file_creation.yml +++ b/detections/endpoint/linux_doas_conf_file_creation.yml @@ -1,7 +1,7 @@ name: Linux Doas Conf File Creation id: f6343e86-6e09-11ec-9376-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_doas_tool_execution.yml b/detections/endpoint/linux_doas_tool_execution.yml index 3c242194f3..24876440f0 100644 --- a/detections/endpoint/linux_doas_tool_execution.yml +++ b/detections/endpoint/linux_doas_tool_execution.yml @@ -1,7 +1,7 @@ name: Linux Doas Tool Execution id: d5a62490-6e09-11ec-884e-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_docker_privilege_escalation.yml b/detections/endpoint/linux_docker_privilege_escalation.yml index a6c8d07606..6a3293283f 100644 --- a/detections/endpoint/linux_docker_privilege_escalation.yml +++ b/detections/endpoint/linux_docker_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Docker Privilege Escalation id: 2e7bfb78-85f6-47b5-bc2f-15813a4ef2b3 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_edit_cron_table_parameter.yml b/detections/endpoint/linux_edit_cron_table_parameter.yml index 9283c0bbfb..6da604bda5 100644 --- a/detections/endpoint/linux_edit_cron_table_parameter.yml +++ b/detections/endpoint/linux_edit_cron_table_parameter.yml @@ -1,7 +1,7 @@ name: Linux Edit Cron Table Parameter id: 0d370304-5f26-11ec-a4bb-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -42,7 +42,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.003 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_emacs_privilege_escalation.yml b/detections/endpoint/linux_emacs_privilege_escalation.yml index 2e3b916845..3e44cdc17f 100644 --- a/detections/endpoint/linux_emacs_privilege_escalation.yml +++ b/detections/endpoint/linux_emacs_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Emacs Privilege Escalation id: 92033cab-1871-483d-a03b-a7ce98665cfc -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml b/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml index 2b4da8e0f3..1335c47856 100644 --- a/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml +++ b/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml @@ -1,7 +1,7 @@ name: Linux File Created In Kernel Driver Directory id: b85bbeec-6326-11ec-9311-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.006 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_file_creation_in_init_boot_directory.yml b/detections/endpoint/linux_file_creation_in_init_boot_directory.yml index 810914e4f3..05900fd9fa 100644 --- a/detections/endpoint/linux_file_creation_in_init_boot_directory.yml +++ b/detections/endpoint/linux_file_creation_in_init_boot_directory.yml @@ -1,7 +1,7 @@ name: Linux File Creation In Init Boot Directory id: 97d9cfb2-61ad-11ec-bb2d-acde48001122 -version: 6 -date: '2025-01-27' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1037.004 - - T1037 product: - Splunk Enterprise - Splunk Enterprise Security @@ -66,6 +65,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.004/linux_init_profile/sysmon_linux.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.004/linux_init_profile/sysmon_linux.log source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux diff --git a/detections/endpoint/linux_file_creation_in_profile_directory.yml b/detections/endpoint/linux_file_creation_in_profile_directory.yml index c35c743ea6..d42712cf76 100644 --- a/detections/endpoint/linux_file_creation_in_profile_directory.yml +++ b/detections/endpoint/linux_file_creation_in_profile_directory.yml @@ -1,7 +1,7 @@ name: Linux File Creation In Profile Directory id: 46ba0082-61af-11ec-9826-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.004 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_find_privilege_escalation.yml b/detections/endpoint/linux_find_privilege_escalation.yml index faeeb076e0..6f3280fbc7 100644 --- a/detections/endpoint/linux_find_privilege_escalation.yml +++ b/detections/endpoint/linux_find_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Find Privilege Escalation id: 2ff4e0c2-8256-4143-9c07-1e39c7231111 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_gdb_privilege_escalation.yml b/detections/endpoint/linux_gdb_privilege_escalation.yml index fd91250e3a..ac12b85551 100644 --- a/detections/endpoint/linux_gdb_privilege_escalation.yml +++ b/detections/endpoint/linux_gdb_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux GDB Privilege Escalation id: 310b7da2-ab52-437f-b1bf-0bd458674308 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_gem_privilege_escalation.yml b/detections/endpoint/linux_gem_privilege_escalation.yml index 7976f81781..ad933d3de7 100644 --- a/detections/endpoint/linux_gem_privilege_escalation.yml +++ b/detections/endpoint/linux_gem_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Gem Privilege Escalation id: 0115482a-5dcb-4bb0-bcca-5d095d224236 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_gnu_awk_privilege_escalation.yml b/detections/endpoint/linux_gnu_awk_privilege_escalation.yml index 818ca801e4..2b34220074 100644 --- a/detections/endpoint/linux_gnu_awk_privilege_escalation.yml +++ b/detections/endpoint/linux_gnu_awk_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux GNU Awk Privilege Escalation id: 0dcf43b9-50d8-42a6-acd9-d1c9201fe6ae -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml b/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml index 49948ef473..cdde6977e4 100644 --- a/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml +++ b/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml @@ -1,7 +1,7 @@ name: Linux High Frequency Of File Deletion In Boot Folder id: e27fbc5d-0445-4c4a-bc39-87f060d5c602 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -58,9 +58,8 @@ tags: - AcidPour asset_type: Endpoint mitre_attack_id: - - T1485 - T1070.004 - - T1070 + - T1485 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml b/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml index c783597e9c..ae5aa85d0d 100644 --- a/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml +++ b/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml @@ -1,7 +1,7 @@ name: Linux High Frequency Of File Deletion In Etc Folder id: 9d867448-2aff-4d07-876c-89409a752ff8 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,9 +56,8 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1485 - T1070.004 - - T1070 + - T1485 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_impair_defenses_process_kill.yml b/detections/endpoint/linux_impair_defenses_process_kill.yml index 095729c786..6662f54760 100644 --- a/detections/endpoint/linux_impair_defenses_process_kill.yml +++ b/detections/endpoint/linux_impair_defenses_process_kill.yml @@ -1,7 +1,7 @@ name: Linux Impair Defenses Process Kill id: 435c6b33-adf9-47fe-be87-8e29fd6654f5 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -42,7 +42,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_indicator_removal_service_file_deletion.yml b/detections/endpoint/linux_indicator_removal_service_file_deletion.yml index 917a6f8fb6..de2d2e6acb 100644 --- a/detections/endpoint/linux_indicator_removal_service_file_deletion.yml +++ b/detections/endpoint/linux_indicator_removal_service_file_deletion.yml @@ -1,7 +1,7 @@ name: Linux Indicator Removal Service File Deletion id: 6c077f81-2a83-4537-afbc-0e62e3215d55 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1070.004 - - T1070 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml b/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml index cb4fd7b694..fc543070b2 100644 --- a/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml +++ b/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml @@ -1,7 +1,7 @@ name: Linux Insert Kernel Module Using Insmod Utility id: 18b5a1a0-6326-11ec-943a-acde48001122 -version: 5 -date: '2024-12-17' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.006 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml b/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml index 7668cca286..32b16133a8 100644 --- a/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml +++ b/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml @@ -1,7 +1,7 @@ name: Linux Install Kernel Module Using Modprobe Utility id: 387b278a-6326-11ec-aa2c-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.006 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_iptables_firewall_modification.yml b/detections/endpoint/linux_iptables_firewall_modification.yml index 3107d907e2..395f7c7c45 100644 --- a/detections/endpoint/linux_iptables_firewall_modification.yml +++ b/detections/endpoint/linux_iptables_firewall_modification.yml @@ -1,7 +1,7 @@ name: Linux Iptables Firewall Modification id: 309d59dc-1e1b-49b2-9800-7cf18d12f7b7 -version: 7 -date: '2025-01-27' +version: 8 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -73,7 +73,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.004 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security @@ -82,6 +81,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/cyclopsblink/sysmon_linux.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/cyclopsblink/sysmon_linux.log source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux diff --git a/detections/endpoint/linux_java_spawning_shell.yml b/detections/endpoint/linux_java_spawning_shell.yml index 4625c20fb7..a13f0d306e 100644 --- a/detections/endpoint/linux_java_spawning_shell.yml +++ b/detections/endpoint/linux_java_spawning_shell.yml @@ -1,6 +1,6 @@ name: Linux Java Spawning Shell id: 7b09db8a-5c20-11ec-9945-acde48001122 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/linux_kernel_module_enumeration.yml b/detections/endpoint/linux_kernel_module_enumeration.yml index 9939c3de7c..157f255449 100644 --- a/detections/endpoint/linux_kernel_module_enumeration.yml +++ b/detections/endpoint/linux_kernel_module_enumeration.yml @@ -1,6 +1,6 @@ name: Linux Kernel Module Enumeration id: 6df99886-0e04-4c11-8b88-325747419278 -version: 6 +version: 7 date: '2024-11-17' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/linux_kworker_process_in_writable_process_path.yml b/detections/endpoint/linux_kworker_process_in_writable_process_path.yml index 0672ad7b93..6f189c9c75 100644 --- a/detections/endpoint/linux_kworker_process_in_writable_process_path.yml +++ b/detections/endpoint/linux_kworker_process_in_writable_process_path.yml @@ -1,7 +1,7 @@ name: Linux Kworker Process In Writable Process Path id: 1cefb270-74a5-4e27-aa0c-2b6fa7c5b4ed -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -43,7 +43,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1036.004 - - T1036 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_make_privilege_escalation.yml b/detections/endpoint/linux_make_privilege_escalation.yml index a8e87a9bf6..8167787558 100644 --- a/detections/endpoint/linux_make_privilege_escalation.yml +++ b/detections/endpoint/linux_make_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Make Privilege Escalation id: 80b22836-5091-4944-80ee-f733ac443f4f -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_mysql_privilege_escalation.yml b/detections/endpoint/linux_mysql_privilege_escalation.yml index 370c6cc5e1..4fc1ec1c2a 100644 --- a/detections/endpoint/linux_mysql_privilege_escalation.yml +++ b/detections/endpoint/linux_mysql_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux MySQL Privilege Escalation id: c0d810f4-230c-44ea-b703-989da02ff145 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_ngrok_reverse_proxy_usage.yml b/detections/endpoint/linux_ngrok_reverse_proxy_usage.yml index eeaf7de9e4..ace58aa7ad 100644 --- a/detections/endpoint/linux_ngrok_reverse_proxy_usage.yml +++ b/detections/endpoint/linux_ngrok_reverse_proxy_usage.yml @@ -1,6 +1,6 @@ name: Linux Ngrok Reverse Proxy Usage id: bc84d574-708c-467d-b78a-4c1e20171f97 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/linux_node_privilege_escalation.yml b/detections/endpoint/linux_node_privilege_escalation.yml index 5e26a21d55..de6c9fa5c1 100644 --- a/detections/endpoint/linux_node_privilege_escalation.yml +++ b/detections/endpoint/linux_node_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Node Privilege Escalation id: 2e58a4ff-398f-42f4-8fd0-e01ebfe2a8ce -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml b/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml index 15ca07070f..42d8d99f84 100644 --- a/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml +++ b/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml @@ -1,7 +1,7 @@ name: Linux NOPASSWD Entry In Sudoers File id: ab1e0d52-624a-11ec-8e0b-acde48001122 -version: 5 -date: '2025-01-27' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security @@ -74,6 +73,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/nopasswd_sudoers/sysmon_linux.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/nopasswd_sudoers/sysmon_linux.log source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux diff --git a/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml b/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml index 033284562b..eeb2fe21ba 100644 --- a/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml +++ b/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml @@ -1,6 +1,6 @@ name: Linux Obfuscated Files or Information Base64 Decode id: 303b38b2-c03f-44e2-8f41-4594606fcfc7 -version: 6 +version: 7 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/linux_octave_privilege_escalation.yml b/detections/endpoint/linux_octave_privilege_escalation.yml index 37839dd3cb..ac9ee41409 100644 --- a/detections/endpoint/linux_octave_privilege_escalation.yml +++ b/detections/endpoint/linux_octave_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Octave Privilege Escalation id: 78f7487d-42ce-4f7f-8685-2159b25fb477 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_openvpn_privilege_escalation.yml b/detections/endpoint/linux_openvpn_privilege_escalation.yml index 452799d717..721061b734 100644 --- a/detections/endpoint/linux_openvpn_privilege_escalation.yml +++ b/detections/endpoint/linux_openvpn_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux OpenVPN Privilege Escalation id: d25feebe-fa1c-4754-8a1e-afb03bedc0f2 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_php_privilege_escalation.yml b/detections/endpoint/linux_php_privilege_escalation.yml index 521ece7f21..d65dc8062b 100644 --- a/detections/endpoint/linux_php_privilege_escalation.yml +++ b/detections/endpoint/linux_php_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux PHP Privilege Escalation id: 4fc4c031-e5be-4cc0-8cf9-49f9f507bcb5 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_pkexec_privilege_escalation.yml b/detections/endpoint/linux_pkexec_privilege_escalation.yml index e4fa7129d7..81844e155e 100644 --- a/detections/endpoint/linux_pkexec_privilege_escalation.yml +++ b/detections/endpoint/linux_pkexec_privilege_escalation.yml @@ -1,6 +1,6 @@ name: Linux pkexec Privilege Escalation id: 03e22c1c-8086-11ec-ac2e-acde48001122 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml b/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml index a7f1ec3741..99ccd2b813 100644 --- a/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml +++ b/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml @@ -1,7 +1,7 @@ name: Linux Possible Access Or Modification Of sshd Config File id: 7a85eb24-72da-11ec-ac76-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1098.004 - - T1098 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_possible_access_to_credential_files.yml b/detections/endpoint/linux_possible_access_to_credential_files.yml index e5f2c33dce..9bbbe61f67 100644 --- a/detections/endpoint/linux_possible_access_to_credential_files.yml +++ b/detections/endpoint/linux_possible_access_to_credential_files.yml @@ -1,7 +1,7 @@ name: Linux Possible Access To Credential Files id: 16107e0e-71fc-11ec-b862-acde48001122 -version: 6 -date: '2025-01-27' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.008 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security @@ -74,6 +73,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/copy_file_stdoutpipe/sysmon_linux.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/copy_file_stdoutpipe/sysmon_linux.log source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux diff --git a/detections/endpoint/linux_possible_access_to_sudoers_file.yml b/detections/endpoint/linux_possible_access_to_sudoers_file.yml index 2be5685254..92ff1b6f97 100644 --- a/detections/endpoint/linux_possible_access_to_sudoers_file.yml +++ b/detections/endpoint/linux_possible_access_to_sudoers_file.yml @@ -1,7 +1,7 @@ name: Linux Possible Access To Sudoers File id: 4479539c-71fc-11ec-b2e2-acde48001122 -version: 5 -date: '2025-01-27' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security @@ -73,6 +72,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/copy_file_stdoutpipe/sysmon_linux.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/copy_file_stdoutpipe/sysmon_linux.log source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux diff --git a/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml b/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml index 928b9536fa..484cd366c6 100644 --- a/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml +++ b/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml @@ -1,7 +1,7 @@ name: Linux Possible Append Command To At Allow Config File id: 7bc20606-5f40-11ec-a586-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.002 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml b/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml index bf67c01e6a..d003d753b3 100644 --- a/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml +++ b/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml @@ -1,7 +1,7 @@ name: Linux Possible Append Command To Profile Config File id: 9c94732a-61af-11ec-91e3-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.004 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file.yml b/detections/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file.yml index 5dc3a73b3b..419ae58634 100644 --- a/detections/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file.yml +++ b/detections/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file.yml @@ -1,7 +1,7 @@ name: Linux Possible Append Cronjob Entry on Existing Cronjob File id: b5b91200-5f27-11ec-bb4e-acde48001122 -version: 5 -date: '2024-12-19' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -47,7 +47,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.003 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_possible_cronjob_modification_with_editor.yml b/detections/endpoint/linux_possible_cronjob_modification_with_editor.yml index 859463e22c..2b2ebb78dc 100644 --- a/detections/endpoint/linux_possible_cronjob_modification_with_editor.yml +++ b/detections/endpoint/linux_possible_cronjob_modification_with_editor.yml @@ -1,7 +1,7 @@ name: Linux Possible Cronjob Modification With Editor id: dcc89bde-5f24-11ec-87ca-acde48001122 -version: 5 -date: '2024-12-19' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -44,7 +44,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.003 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_possible_ssh_key_file_creation.yml b/detections/endpoint/linux_possible_ssh_key_file_creation.yml index a67d49a356..63df17e210 100644 --- a/detections/endpoint/linux_possible_ssh_key_file_creation.yml +++ b/detections/endpoint/linux_possible_ssh_key_file_creation.yml @@ -1,7 +1,7 @@ name: Linux Possible Ssh Key File Creation id: c04ef40c-72da-11ec-8eac-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1098.004 - - T1098 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_preload_hijack_library_calls.yml b/detections/endpoint/linux_preload_hijack_library_calls.yml index 9ad2401c00..051c3c042d 100644 --- a/detections/endpoint/linux_preload_hijack_library_calls.yml +++ b/detections/endpoint/linux_preload_hijack_library_calls.yml @@ -1,7 +1,7 @@ name: Linux Preload Hijack Library Calls id: cbe2ca30-631e-11ec-8670-acde48001122 -version: 5 -date: '2025-01-27' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.006 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security @@ -73,6 +72,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/lib_hijack/sysmon_linux.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/lib_hijack/sysmon_linux.log source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux diff --git a/detections/endpoint/linux_proxy_socks_curl.yml b/detections/endpoint/linux_proxy_socks_curl.yml index 1093bc6413..2501295d79 100644 --- a/detections/endpoint/linux_proxy_socks_curl.yml +++ b/detections/endpoint/linux_proxy_socks_curl.yml @@ -1,6 +1,6 @@ name: Linux Proxy Socks Curl id: bd596c22-ad1e-44fc-b242-817253ce8b08 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/linux_puppet_privilege_escalation.yml b/detections/endpoint/linux_puppet_privilege_escalation.yml index 05c7c3d735..b6a4422129 100644 --- a/detections/endpoint/linux_puppet_privilege_escalation.yml +++ b/detections/endpoint/linux_puppet_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Puppet Privilege Escalation id: 1d19037f-466e-4d56-8d87-36fafd9aa3ce -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_rpm_privilege_escalation.yml b/detections/endpoint/linux_rpm_privilege_escalation.yml index 612f08ab5f..8f3021760f 100644 --- a/detections/endpoint/linux_rpm_privilege_escalation.yml +++ b/detections/endpoint/linux_rpm_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux RPM Privilege Escalation id: f8e58a23-cecd-495f-9c65-6c76b4cb9774 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_ruby_privilege_escalation.yml b/detections/endpoint/linux_ruby_privilege_escalation.yml index b004b42783..42301ecd19 100644 --- a/detections/endpoint/linux_ruby_privilege_escalation.yml +++ b/detections/endpoint/linux_ruby_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Ruby Privilege Escalation id: 097b28b5-7004-4d40-a715-7e390501788b -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_service_file_created_in_systemd_directory.yml b/detections/endpoint/linux_service_file_created_in_systemd_directory.yml index 5d09d54a8e..84f9f74176 100644 --- a/detections/endpoint/linux_service_file_created_in_systemd_directory.yml +++ b/detections/endpoint/linux_service_file_created_in_systemd_directory.yml @@ -1,7 +1,7 @@ name: Linux Service File Created In Systemd Directory id: c7495048-61b6-11ec-9a37-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.006 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_service_restarted.yml b/detections/endpoint/linux_service_restarted.yml index b51395a490..e38b12f9c0 100644 --- a/detections/endpoint/linux_service_restarted.yml +++ b/detections/endpoint/linux_service_restarted.yml @@ -1,7 +1,7 @@ name: Linux Service Restarted id: 084275ba-61b8-11ec-8d64-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.006 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_service_started_or_enabled.yml b/detections/endpoint/linux_service_started_or_enabled.yml index ca91f33339..c5ee30eed0 100644 --- a/detections/endpoint/linux_service_started_or_enabled.yml +++ b/detections/endpoint/linux_service_started_or_enabled.yml @@ -1,7 +1,7 @@ name: Linux Service Started Or Enabled id: e0428212-61b7-11ec-88a3-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.006 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_setuid_using_chmod_utility.yml b/detections/endpoint/linux_setuid_using_chmod_utility.yml index 4355cf7209..91fc08356f 100644 --- a/detections/endpoint/linux_setuid_using_chmod_utility.yml +++ b/detections/endpoint/linux_setuid_using_chmod_utility.yml @@ -1,7 +1,7 @@ name: Linux Setuid Using Chmod Utility id: bf0304b6-6250-11ec-9d7c-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.001 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_setuid_using_setcap_utility.yml b/detections/endpoint/linux_setuid_using_setcap_utility.yml index 7092cc2521..55265c8fdf 100644 --- a/detections/endpoint/linux_setuid_using_setcap_utility.yml +++ b/detections/endpoint/linux_setuid_using_setcap_utility.yml @@ -1,7 +1,7 @@ name: Linux Setuid Using Setcap Utility id: 9d96022e-6250-11ec-9a19-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.001 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_sqlite3_privilege_escalation.yml b/detections/endpoint/linux_sqlite3_privilege_escalation.yml index 60c9288b4e..276443066d 100644 --- a/detections/endpoint/linux_sqlite3_privilege_escalation.yml +++ b/detections/endpoint/linux_sqlite3_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Sqlite3 Privilege Escalation id: ab75dbb7-c3ba-4689-9c1b-8d2717bdcba1 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_ssh_authorized_keys_modification.yml b/detections/endpoint/linux_ssh_authorized_keys_modification.yml index a2a4c09110..d513ccb7c5 100644 --- a/detections/endpoint/linux_ssh_authorized_keys_modification.yml +++ b/detections/endpoint/linux_ssh_authorized_keys_modification.yml @@ -1,6 +1,6 @@ name: Linux SSH Authorized Keys Modification id: f5ab595e-28e5-4327-8077-5008ba97c850 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/linux_ssh_remote_services_script_execute.yml b/detections/endpoint/linux_ssh_remote_services_script_execute.yml index 6fcbed4dcd..cddd81fa59 100644 --- a/detections/endpoint/linux_ssh_remote_services_script_execute.yml +++ b/detections/endpoint/linux_ssh_remote_services_script_execute.yml @@ -1,6 +1,6 @@ name: Linux SSH Remote Services Script Execute id: aa1748dd-4a5c-457a-9cf6-ca7b4eb711b3 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml b/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml index ce2ed01432..07665db54f 100644 --- a/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml +++ b/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml @@ -1,7 +1,7 @@ name: Linux Stdout Redirection To Dev Null File id: de62b809-a04d-46b5-9a15-8298d330f0c8 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: experimental type: Anomaly @@ -49,7 +49,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.004 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_sudo_or_su_execution.yml b/detections/endpoint/linux_sudo_or_su_execution.yml index 4d09a93bfb..da149584d5 100644 --- a/detections/endpoint/linux_sudo_or_su_execution.yml +++ b/detections/endpoint/linux_sudo_or_su_execution.yml @@ -1,7 +1,7 @@ name: Linux Sudo OR Su Execution id: 4b00f134-6d6a-11ec-a90c-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -41,7 +41,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_sudoers_tmp_file_creation.yml b/detections/endpoint/linux_sudoers_tmp_file_creation.yml index 838f432cab..cd67ed8058 100644 --- a/detections/endpoint/linux_sudoers_tmp_file_creation.yml +++ b/detections/endpoint/linux_sudoers_tmp_file_creation.yml @@ -1,7 +1,7 @@ name: Linux Sudoers Tmp File Creation id: be254a5c-63e7-11ec-89da-acde48001122 -version: 5 -date: '2025-01-27' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security @@ -67,6 +66,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/sudoers_temp/sysmon_linux.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/sudoers_temp/sysmon_linux.log source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux diff --git a/detections/endpoint/linux_unix_shell_enable_all_sysrq_functions.yml b/detections/endpoint/linux_unix_shell_enable_all_sysrq_functions.yml index e6fab0a962..d183c538ae 100644 --- a/detections/endpoint/linux_unix_shell_enable_all_sysrq_functions.yml +++ b/detections/endpoint/linux_unix_shell_enable_all_sysrq_functions.yml @@ -1,7 +1,7 @@ name: Linux Unix Shell Enable All SysRq Functions id: e7a96937-3b58-4962-8dce-538e4763cf15 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.004 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_visudo_utility_execution.yml b/detections/endpoint/linux_visudo_utility_execution.yml index 93adeaf905..596d9a84c3 100644 --- a/detections/endpoint/linux_visudo_utility_execution.yml +++ b/detections/endpoint/linux_visudo_utility_execution.yml @@ -1,7 +1,7 @@ name: Linux Visudo Utility Execution id: 08c41040-624c-11ec-a71f-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/loading_of_dynwrapx_module.yml b/detections/endpoint/loading_of_dynwrapx_module.yml index 4b57f8a939..b84f0b040e 100644 --- a/detections/endpoint/loading_of_dynwrapx_module.yml +++ b/detections/endpoint/loading_of_dynwrapx_module.yml @@ -1,7 +1,7 @@ name: Loading Of Dynwrapx Module id: eac5e8ba-4857-11ec-9371-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - AsyncRAT asset_type: Endpoint mitre_attack_id: - - T1055 - T1055.001 product: - Splunk Enterprise diff --git a/detections/endpoint/local_account_discovery_with_wmic.yml b/detections/endpoint/local_account_discovery_with_wmic.yml index 7a5da713bb..85b07244d2 100644 --- a/detections/endpoint/local_account_discovery_with_wmic.yml +++ b/detections/endpoint/local_account_discovery_with_wmic.yml @@ -1,7 +1,7 @@ name: Local Account Discovery With Wmic id: 4902d7aa-0134-11ec-9d65-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -39,7 +39,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.001 product: - Splunk Enterprise diff --git a/detections/endpoint/logon_script_event_trigger_execution.yml b/detections/endpoint/logon_script_event_trigger_execution.yml index 78ab8e9852..b27836b375 100644 --- a/detections/endpoint/logon_script_event_trigger_execution.yml +++ b/detections/endpoint/logon_script_event_trigger_execution.yml @@ -1,7 +1,7 @@ name: Logon Script Event Trigger Execution id: 4c38c264-1f74-11ec-b5fa-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - Windows Persistence Techniques asset_type: Endpoint mitre_attack_id: - - T1037 - T1037.001 product: - Splunk Enterprise diff --git a/detections/endpoint/macos_lolbin.yml b/detections/endpoint/macos_lolbin.yml index 57a2ca77ce..364826a00d 100644 --- a/detections/endpoint/macos_lolbin.yml +++ b/detections/endpoint/macos_lolbin.yml @@ -1,7 +1,7 @@ name: MacOS LOLbin id: 58d270fb-5b39-418e-a855-4b8ac046805e -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.004 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/mailsniper_invoke_functions.yml b/detections/endpoint/mailsniper_invoke_functions.yml index c61b356b5d..63412c881e 100644 --- a/detections/endpoint/mailsniper_invoke_functions.yml +++ b/detections/endpoint/mailsniper_invoke_functions.yml @@ -1,7 +1,7 @@ name: Mailsniper Invoke functions id: a36972c8-b894-11eb-9f78-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: - Data Exfiltration asset_type: Endpoint mitre_attack_id: - - T1114 - T1114.001 product: - Splunk Enterprise diff --git a/detections/endpoint/malicious_powershell_executed_as_a_service.yml b/detections/endpoint/malicious_powershell_executed_as_a_service.yml index a846b2b6d5..9ce1a87d91 100644 --- a/detections/endpoint/malicious_powershell_executed_as_a_service.yml +++ b/detections/endpoint/malicious_powershell_executed_as_a_service.yml @@ -1,7 +1,7 @@ name: Malicious Powershell Executed As A Service id: 8e204dfd-cae0-4ea8-a61d-e972a1ff2ff8 -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Ryan Becwar status: production type: TTP @@ -62,7 +62,6 @@ tags: - Malicious PowerShell asset_type: Endpoint mitre_attack_id: - - T1569 - T1569.002 product: - Splunk Enterprise diff --git a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml index 228765bed3..ecc670ddcd 100644 --- a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml +++ b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml @@ -1,7 +1,7 @@ name: Malicious PowerShell Process - Execution Policy Bypass id: 9be56c82-b1cc-4318-87eb-d138afaaca39 -version: 9 -date: '2025-01-27' +version: 10 +date: '2025-02-10' author: Rico Valdez, Mauricio Velazco, Splunk status: production type: Anomaly @@ -69,7 +69,6 @@ tags: - Volt Typhoon asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise @@ -79,6 +78,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/encoded_powershell/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/encoded_powershell/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml b/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml index 4e23a604b3..eb1e0f4e3a 100644 --- a/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml +++ b/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml @@ -1,7 +1,7 @@ name: Malicious PowerShell Process With Obfuscation Techniques id: cde75cf6-3c7a-4dd6-af01-27cdb4511fd4 -version: 9 -date: '2024-11-13' +version: 10 +date: '2025-02-10' author: David Dorsey, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise diff --git a/detections/endpoint/microsoft_defender_atp_alerts.yml b/detections/endpoint/microsoft_defender_atp_alerts.yml index e18398545b..eba3aaecd3 100644 --- a/detections/endpoint/microsoft_defender_atp_alerts.yml +++ b/detections/endpoint/microsoft_defender_atp_alerts.yml @@ -1,6 +1,6 @@ name: Microsoft Defender ATP Alerts id: 38f034ed-1598-46c8-95e8-14edf05fdf5d -version: 2 +version: 3 date: '2025-01-20' author: Bryan Pluta, Bhavin Patel, Splunk status: production diff --git a/detections/endpoint/microsoft_defender_incident_alerts.yml b/detections/endpoint/microsoft_defender_incident_alerts.yml index 2133ecae98..4cae1ede0f 100644 --- a/detections/endpoint/microsoft_defender_incident_alerts.yml +++ b/detections/endpoint/microsoft_defender_incident_alerts.yml @@ -1,6 +1,6 @@ name: Microsoft Defender Incident Alerts id: 13435b55-afd8-46d4-9045-7d5457f430a5 -version: 2 +version: 3 date: '2025-01-20' author: Bryan Pluta, Bhavin Patel, Splunk status: production diff --git a/detections/endpoint/mimikatz_passtheticket_commandline_parameters.yml b/detections/endpoint/mimikatz_passtheticket_commandline_parameters.yml index 5a6def368f..5757d7a98d 100644 --- a/detections/endpoint/mimikatz_passtheticket_commandline_parameters.yml +++ b/detections/endpoint/mimikatz_passtheticket_commandline_parameters.yml @@ -1,7 +1,7 @@ name: Mimikatz PassTheTicket CommandLine Parameters id: 13bbd574-83ac-11ec-99d4-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -72,7 +72,6 @@ tags: - Active Directory Kerberos Attacks asset_type: Endpoint mitre_attack_id: - - T1550 - T1550.003 product: - Splunk Enterprise diff --git a/detections/endpoint/mmc_lolbas_execution_process_spawn.yml b/detections/endpoint/mmc_lolbas_execution_process_spawn.yml index a3e11e7507..a2db5e0210 100644 --- a/detections/endpoint/mmc_lolbas_execution_process_spawn.yml +++ b/detections/endpoint/mmc_lolbas_execution_process_spawn.yml @@ -1,7 +1,7 @@ name: Mmc LOLBAS Execution Process Spawn id: f6601940-4c74-11ec-b9b7-3e22fbd008af -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -75,7 +75,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.003 - T1218.014 product: diff --git a/detections/endpoint/monitor_registry_keys_for_print_monitors.yml b/detections/endpoint/monitor_registry_keys_for_print_monitors.yml index d40890a563..51119f9f76 100644 --- a/detections/endpoint/monitor_registry_keys_for_print_monitors.yml +++ b/detections/endpoint/monitor_registry_keys_for_print_monitors.yml @@ -1,7 +1,7 @@ name: Monitor Registry Keys for Print Monitors id: f5f6af30-7ba7-4295-bfe9-07de87c01bbc -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick, Bhavin Patel status: production type: TTP @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.010 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml b/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml index df154acdcd..dff28e7dd0 100644 --- a/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml +++ b/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml @@ -1,7 +1,7 @@ name: MS Exchange Mailbox Replication service writing Active Server Pages id: 985f322c-57a5-11ec-b9ac-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: experimental type: TTP @@ -56,10 +56,9 @@ tags: - BlackByte Ransomware asset_type: Endpoint mitre_attack_id: - - T1505 - - T1505.003 - - T1190 - T1133 + - T1190 + - T1505.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/ms_scripting_process_loading_ldap_module.yml b/detections/endpoint/ms_scripting_process_loading_ldap_module.yml index f6c51367ef..eb406c8ba5 100644 --- a/detections/endpoint/ms_scripting_process_loading_ldap_module.yml +++ b/detections/endpoint/ms_scripting_process_loading_ldap_module.yml @@ -1,7 +1,7 @@ name: MS Scripting Process Loading Ldap Module id: 0b0c40dc-14a6-11ec-b267-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -54,7 +54,6 @@ tags: - FIN7 asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.007 product: - Splunk Enterprise diff --git a/detections/endpoint/ms_scripting_process_loading_wmi_module.yml b/detections/endpoint/ms_scripting_process_loading_wmi_module.yml index 58ecca447c..bfe6fe971f 100644 --- a/detections/endpoint/ms_scripting_process_loading_wmi_module.yml +++ b/detections/endpoint/ms_scripting_process_loading_wmi_module.yml @@ -1,7 +1,7 @@ name: MS Scripting Process Loading WMI Module id: 2eba3d36-14a6-11ec-a682-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: - FIN7 asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.007 product: - Splunk Enterprise diff --git a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml b/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml index 05fa46f331..2163163ec3 100644 --- a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml +++ b/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml @@ -1,7 +1,7 @@ name: MSBuild Suspicious Spawned By Script Process id: 213b3148-24ea-11ec-93a2-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1127.001 - - T1127 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml b/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml index 904d7c0ff7..15849b0340 100644 --- a/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml +++ b/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml @@ -1,7 +1,7 @@ name: Mshta spawning Rundll32 OR Regsvr32 Process id: 4aa5d062-e893-11eb-9eb2-acde48001122 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -67,7 +67,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.005 product: - Splunk Enterprise diff --git a/detections/endpoint/msi_module_loaded_by_non_system_binary.yml b/detections/endpoint/msi_module_loaded_by_non_system_binary.yml index 22fa5c3e01..2c944989d3 100644 --- a/detections/endpoint/msi_module_loaded_by_non_system_binary.yml +++ b/detections/endpoint/msi_module_loaded_by_non_system_binary.yml @@ -1,7 +1,7 @@ name: MSI Module Loaded by Non-System Binary id: ccb98a66-5851-11ec-b91c-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -37,7 +37,6 @@ tags: - CVE-2021-41379 mitre_attack_id: - T1574.002 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/msmpeng_application_dll_side_loading.yml b/detections/endpoint/msmpeng_application_dll_side_loading.yml index c6a910d2c8..70f151f1ee 100644 --- a/detections/endpoint/msmpeng_application_dll_side_loading.yml +++ b/detections/endpoint/msmpeng_application_dll_side_loading.yml @@ -1,7 +1,7 @@ name: Msmpeng Application DLL Side Loading id: 8bb3f280-dd9b-11eb-84d5-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Sanjay Govind status: production type: TTP @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.002 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/net_profiler_uac_bypass.yml b/detections/endpoint/net_profiler_uac_bypass.yml index 4a11fbd77f..66a59db29f 100644 --- a/detections/endpoint/net_profiler_uac_bypass.yml +++ b/detections/endpoint/net_profiler_uac_bypass.yml @@ -1,7 +1,7 @@ name: NET Profiler UAC bypass id: 0252ca80-e30d-11eb-8aa3-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/network_discovery_using_route_windows_app.yml b/detections/endpoint/network_discovery_using_route_windows_app.yml index cf9e62d47b..acea9bdc52 100644 --- a/detections/endpoint/network_discovery_using_route_windows_app.yml +++ b/detections/endpoint/network_discovery_using_route_windows_app.yml @@ -1,7 +1,7 @@ name: Network Discovery Using Route Windows App id: dd83407e-439f-11ec-ab8e-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -45,7 +45,6 @@ tags: - Prestige Ransomware asset_type: Endpoint mitre_attack_id: - - T1016 - T1016.001 product: - Splunk Enterprise diff --git a/detections/endpoint/network_traffic_to_active_directory_web_services_protocol.yml b/detections/endpoint/network_traffic_to_active_directory_web_services_protocol.yml index 5a05f52cd4..96fc75806e 100644 --- a/detections/endpoint/network_traffic_to_active_directory_web_services_protocol.yml +++ b/detections/endpoint/network_traffic_to_active_directory_web_services_protocol.yml @@ -1,7 +1,7 @@ name: Network Traffic to Active Directory Web Services Protocol id: 68a0056c-34cb-455f-b03d-df935ea62c4f -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -37,13 +37,11 @@ tags: asset_type: Network atomic_guid: [] mitre_attack_id: - - T1087.002 - T1069.001 - - T1482 - - T1087.001 - - T1087 - T1069.002 - - T1069 + - T1087.001 + - T1087.002 + - T1482 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/nishang_powershelltcponeline.yml b/detections/endpoint/nishang_powershelltcponeline.yml index 3bca3b340a..676364635a 100644 --- a/detections/endpoint/nishang_powershelltcponeline.yml +++ b/detections/endpoint/nishang_powershelltcponeline.yml @@ -1,7 +1,7 @@ name: Nishang PowershellTCPOneLine id: 1a382c6c-7c2e-11eb-ac69-acde48001122 -version: 6 -date: '2024-12-16' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: - Cleo File Transfer Software asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise diff --git a/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml b/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml index fa4c8d036a..3a3b1fe2b8 100644 --- a/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml +++ b/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml @@ -1,7 +1,7 @@ name: Non Chrome Process Accessing Chrome Default Dir id: 81263de4-160a-11ec-944f-acde48001122 -version: 6 -date: '2025-01-27' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: - RedLine Stealer asset_type: Endpoint mitre_attack_id: - - T1555 - T1555.003 product: - Splunk Enterprise @@ -74,6 +73,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/non_chrome_process_accessing_chrome_default_dir/windows-xml.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/non_chrome_process_accessing_chrome_default_dir/windows-xml.log source: XmlWinEventLog:Security sourcetype: XmlWinEventLog diff --git a/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml b/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml index abc2b0fc09..8ba8350c73 100644 --- a/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml +++ b/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml @@ -1,7 +1,7 @@ name: Non Firefox Process Access Firefox Profile Dir id: e6fc13b0-1609-11ec-b533-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -62,7 +62,6 @@ tags: - Snake Keylogger asset_type: Endpoint mitre_attack_id: - - T1555 - T1555.003 product: - Splunk Enterprise diff --git a/detections/endpoint/notepad_with_no_command_line_arguments.yml b/detections/endpoint/notepad_with_no_command_line_arguments.yml index 1b8e50b748..9598488359 100644 --- a/detections/endpoint/notepad_with_no_command_line_arguments.yml +++ b/detections/endpoint/notepad_with_no_command_line_arguments.yml @@ -1,6 +1,6 @@ name: Notepad with no Command Line Arguments id: 5adbc5f1-9a2f-41c1-a810-f37e015f8179 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk type: TTP diff --git a/detections/endpoint/ntdsutil_export_ntds.yml b/detections/endpoint/ntdsutil_export_ntds.yml index fee86a72ef..6272375790 100644 --- a/detections/endpoint/ntdsutil_export_ntds.yml +++ b/detections/endpoint/ntdsutil_export_ntds.yml @@ -1,7 +1,7 @@ name: Ntdsutil Export NTDS id: da63bc76-61ae-11eb-ae93-0242ac130002 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Patrick Bareiss, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.003 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/overwriting_accessibility_binaries.yml b/detections/endpoint/overwriting_accessibility_binaries.yml index cf10053592..a81a27d1ef 100644 --- a/detections/endpoint/overwriting_accessibility_binaries.yml +++ b/detections/endpoint/overwriting_accessibility_binaries.yml @@ -1,7 +1,7 @@ name: Overwriting Accessibility Binaries id: 13c2f6c3-10c5-4deb-9ba1-7c4460ebe4ae -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: David Dorsey, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - Flax Typhoon asset_type: Endpoint mitre_attack_id: - - T1546 - T1546.008 product: - Splunk Enterprise diff --git a/detections/endpoint/permission_modification_using_takeown_app.yml b/detections/endpoint/permission_modification_using_takeown_app.yml index 8beee2753c..cb60ecf027 100644 --- a/detections/endpoint/permission_modification_using_takeown_app.yml +++ b/detections/endpoint/permission_modification_using_takeown_app.yml @@ -1,10 +1,10 @@ name: Permission Modification using Takeown App id: fa7ca5c6-c9d8-11eb-bce9-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-01-27' author: Teoderick Contreras, Splunk status: production -type: TTP +type: Anomaly description: The following analytic detects the modification of file or directory permissions using the takeown.exe Windows application. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process execution logs that include @@ -56,7 +56,7 @@ rba: risk_objects: - field: dest type: system - score: 56 + score: 30 threat_objects: - field: process_name type: process_name diff --git a/detections/endpoint/ping_sleep_batch_command.yml b/detections/endpoint/ping_sleep_batch_command.yml index 0b164dcc22..3123e4654a 100644 --- a/detections/endpoint/ping_sleep_batch_command.yml +++ b/detections/endpoint/ping_sleep_batch_command.yml @@ -1,7 +1,7 @@ name: Ping Sleep Batch Command id: ce058d6c-79f2-11ec-b476-acde48001122 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -71,7 +71,6 @@ tags: - Meduza Stealer asset_type: Endpoint mitre_attack_id: - - T1497 - T1497.003 product: - Splunk Enterprise diff --git a/detections/endpoint/possible_browser_pass_view_parameter.yml b/detections/endpoint/possible_browser_pass_view_parameter.yml index 5a2fdbcd71..65339f563a 100644 --- a/detections/endpoint/possible_browser_pass_view_parameter.yml +++ b/detections/endpoint/possible_browser_pass_view_parameter.yml @@ -1,7 +1,7 @@ name: Possible Browser Pass View Parameter id: 8ba484e8-4b97-11ec-b19a-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -46,7 +46,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1555.003 - - T1555 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/possible_lateral_movement_powershell_spawn.yml b/detections/endpoint/possible_lateral_movement_powershell_spawn.yml index a5e4e662a0..0829ca7479 100644 --- a/detections/endpoint/possible_lateral_movement_powershell_spawn.yml +++ b/detections/endpoint/possible_lateral_movement_powershell_spawn.yml @@ -1,7 +1,7 @@ name: Possible Lateral Movement PowerShell Spawn id: cb909b3e-512b-11ec-aa31-3e22fbd008af -version: 8 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Mauricio Velazco, Michael Haag, Splunk status: production type: TTP @@ -76,14 +76,13 @@ tags: - CISA AA24-241A asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.003 - T1021.006 - T1047 - T1053.005 - - T1543.003 - T1059.001 - T1218.014 + - T1543.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/potential_system_network_configuration_discovery_activity.yml b/detections/endpoint/potential_system_network_configuration_discovery_activity.yml index 593947e09e..7939bcde78 100644 --- a/detections/endpoint/potential_system_network_configuration_discovery_activity.yml +++ b/detections/endpoint/potential_system_network_configuration_discovery_activity.yml @@ -1,6 +1,6 @@ name: Potential System Network Configuration Discovery Activity id: 3f0b95e3-3195-46ac-bea3-84fb59e7fac5 -version: 1 +version: 2 date: '2025-01-20' author: Bhavin Patel, Splunk status: production diff --git a/detections/endpoint/powershell_4104_hunting.yml b/detections/endpoint/powershell_4104_hunting.yml index bdf4328edc..e4c1ddafe7 100644 --- a/detections/endpoint/powershell_4104_hunting.yml +++ b/detections/endpoint/powershell_4104_hunting.yml @@ -1,7 +1,7 @@ name: PowerShell 4104 Hunting id: d6f2b006-0041-11ec-8885-acde48001122 -version: 10 -date: '2025-01-27' +version: 11 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -74,7 +74,6 @@ tags: - CISA AA24-241A asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise @@ -84,6 +83,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml b/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml index 4448706801..d69d9be400 100644 --- a/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml +++ b/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml @@ -1,7 +1,7 @@ name: PowerShell - Connect To Internet With Hidden Window id: ee18ed37-0802-4268-9435-b3b91aaa18db -version: 11 -date: '2024-11-13' +version: 12 +date: '2025-02-10' author: David Dorsey, Michael Haag Splunk status: production type: Hunting @@ -55,7 +55,6 @@ tags: - CVE-2021-44228 mitre_attack_id: - T1059.001 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/powershell_com_hijacking_inprocserver32_modification.yml b/detections/endpoint/powershell_com_hijacking_inprocserver32_modification.yml index 568bb5677c..2999af89df 100644 --- a/detections/endpoint/powershell_com_hijacking_inprocserver32_modification.yml +++ b/detections/endpoint/powershell_com_hijacking_inprocserver32_modification.yml @@ -1,7 +1,7 @@ name: Powershell COM Hijacking InprocServer32 Modification id: ea61e291-af05-4716-932a-67faddb6ae6f -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -56,9 +56,8 @@ tags: - Malicious PowerShell asset_type: Endpoint mitre_attack_id: - - T1546.015 - - T1059 - T1059.001 + - T1546.015 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/powershell_creating_thread_mutex.yml b/detections/endpoint/powershell_creating_thread_mutex.yml index 636784f5f6..17dc9e26a6 100644 --- a/detections/endpoint/powershell_creating_thread_mutex.yml +++ b/detections/endpoint/powershell_creating_thread_mutex.yml @@ -1,7 +1,7 @@ name: Powershell Creating Thread Mutex id: 637557ec-ca08-11eb-bd0a-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: - Malicious PowerShell asset_type: Endpoint mitre_attack_id: - - T1027 - T1027.005 - T1059.001 product: diff --git a/detections/endpoint/powershell_disable_security_monitoring.yml b/detections/endpoint/powershell_disable_security_monitoring.yml index acf1715048..1564ed0507 100644 --- a/detections/endpoint/powershell_disable_security_monitoring.yml +++ b/detections/endpoint/powershell_disable_security_monitoring.yml @@ -1,7 +1,7 @@ name: Powershell Disable Security Monitoring id: c148a894-dd93-11eb-bf2a-acde48001122 -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/powershell_domain_enumeration.yml b/detections/endpoint/powershell_domain_enumeration.yml index f0d3a6b92e..b5d57545c4 100644 --- a/detections/endpoint/powershell_domain_enumeration.yml +++ b/detections/endpoint/powershell_domain_enumeration.yml @@ -1,7 +1,7 @@ name: PowerShell Domain Enumeration id: e1866ce2-ca22-11eb-8e44-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise diff --git a/detections/endpoint/powershell_enable_powershell_remoting.yml b/detections/endpoint/powershell_enable_powershell_remoting.yml index 8cfdb6a12c..412a67fcd6 100644 --- a/detections/endpoint/powershell_enable_powershell_remoting.yml +++ b/detections/endpoint/powershell_enable_powershell_remoting.yml @@ -1,7 +1,7 @@ name: PowerShell Enable PowerShell Remoting id: 40e3b299-19a5-4460-96e9-e1467f714f8e -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk type: Anomaly status: production @@ -53,7 +53,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.001 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/powershell_enable_smb1protocol_feature.yml b/detections/endpoint/powershell_enable_smb1protocol_feature.yml index 5778e667c4..4027bd9cbf 100644 --- a/detections/endpoint/powershell_enable_smb1protocol_feature.yml +++ b/detections/endpoint/powershell_enable_smb1protocol_feature.yml @@ -1,7 +1,7 @@ name: Powershell Enable SMB1Protocol Feature id: afed80b2-d34b-11eb-a952-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -54,7 +54,6 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1027 - T1027.005 product: - Splunk Enterprise diff --git a/detections/endpoint/powershell_execute_com_object.yml b/detections/endpoint/powershell_execute_com_object.yml index afa898ec22..0829d8c7a5 100644 --- a/detections/endpoint/powershell_execute_com_object.yml +++ b/detections/endpoint/powershell_execute_com_object.yml @@ -1,7 +1,7 @@ name: Powershell Execute COM Object id: 65711630-f9bf-11eb-8d72-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -55,9 +55,8 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1546.015 - - T1546 - T1059.001 + - T1546.015 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml b/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml index d57deb4a84..be8d0a5b04 100644 --- a/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml +++ b/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml @@ -1,7 +1,7 @@ name: Powershell Fileless Process Injection via GetProcAddress id: a26d9db4-c883-11eb-9d75-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1059 - T1055 - T1059.001 product: diff --git a/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml b/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml index 220cb14ad7..c6cf407c05 100644 --- a/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml +++ b/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml @@ -1,7 +1,7 @@ name: Powershell Fileless Script Contains Base64 Encoded Content id: 8acbc04c-c882-11eb-b060-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: - IcedID - NjRAT mitre_attack_id: - - T1059 - T1027 - T1059.001 product: diff --git a/detections/endpoint/powershell_get_localgroup_discovery.yml b/detections/endpoint/powershell_get_localgroup_discovery.yml index cf5e6ada50..95170cb2f8 100644 --- a/detections/endpoint/powershell_get_localgroup_discovery.yml +++ b/detections/endpoint/powershell_get_localgroup_discovery.yml @@ -1,7 +1,7 @@ name: PowerShell Get LocalGroup Discovery id: b71adfcc-155b-11ec-9413-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -41,7 +41,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.001 product: - Splunk Enterprise diff --git a/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml b/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml index 09e77be336..633fbc71a1 100644 --- a/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml +++ b/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml @@ -1,7 +1,7 @@ name: Powershell Get LocalGroup Discovery with Script Block Logging id: d7c6ad22-155c-11ec-bb64-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -35,7 +35,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.001 product: - Splunk Enterprise diff --git a/detections/endpoint/powershell_load_module_in_meterpreter.yml b/detections/endpoint/powershell_load_module_in_meterpreter.yml index de6090bb3f..48f13d3839 100644 --- a/detections/endpoint/powershell_load_module_in_meterpreter.yml +++ b/detections/endpoint/powershell_load_module_in_meterpreter.yml @@ -1,7 +1,7 @@ name: Powershell Load Module in Meterpreter id: d5905da5-d050-48db-9259-018d8f034fcf -version: 4 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - MetaSploit asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise diff --git a/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml b/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml index d848c784db..d7d526e11e 100644 --- a/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml +++ b/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml @@ -1,16 +1,31 @@ name: PowerShell Loading DotNET into Memory via Reflection id: 85bc3f30-ca28-11eb-bd21-acde48001122 -version: 6 -date: '2025-01-16' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly data_source: - Powershell Script Block Logging 4104 -description: The following analytic detects the use of PowerShell scripts to load .NET assemblies into memory via reflection, a technique often used in malicious activities such as those by Empire and Cobalt Strike. It leverages PowerShell Script Block Logging (EventCode=4104) to capture and analyze the full command executed. This behavior is significant as it can indicate advanced attack techniques aiming to execute code in memory, bypassing traditional defenses. If confirmed malicious, this activity could lead to unauthorized code execution, privilege escalation, and persistent access within the environment. -search: '`powershell` EventCode=4104 ScriptBlockText IN ("*Reflection.Assembly]::Load*", "*Reflection.Assembly.Load*", "*UnsafeLoadFrom*", "*.LoadFrom(*", "*.LoadModule(*", "*.LoadWithPartialName*", "*ReflectionOnlyLoad*") | stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText | rename Computer as dest, UserID as user| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `powershell_loading_dotnet_into_memory_via_reflection_filter`' -how_to_implement: To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. -known_false_positives: False positives should be limited as day to day scripts do not use this method. +description: The following analytic detects the use of PowerShell scripts to load + .NET assemblies into memory via reflection, a technique often used in malicious + activities such as those by Empire and Cobalt Strike. It leverages PowerShell Script + Block Logging (EventCode=4104) to capture and analyze the full command executed. + This behavior is significant as it can indicate advanced attack techniques aiming + to execute code in memory, bypassing traditional defenses. If confirmed malicious, + this activity could lead to unauthorized code execution, privilege escalation, and + persistent access within the environment. +search: '`powershell` EventCode=4104 ScriptBlockText IN ("*Reflection.Assembly]::Load*", + "*Reflection.Assembly.Load*", "*UnsafeLoadFrom*", "*.LoadFrom(*", "*.LoadModule(*", + "*.LoadWithPartialName*", "*ReflectionOnlyLoad*") | stats count min(_time) as firstTime + max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText | rename + Computer as dest, UserID as user| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `powershell_loading_dotnet_into_memory_via_reflection_filter`' +how_to_implement: To successfully implement this analytic, you will need to enable + PowerShell Script Block Logging on some or all endpoints. Additional setup here + https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. +known_false_positives: False positives should be limited as day to day scripts do + not use this method. references: - https://docs.microsoft.com/en-us/dotnet/api/system.reflection.assembly?view=net-5.0 - https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. @@ -23,7 +38,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" and "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$$", "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$$", + "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) + as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk + Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -48,7 +68,6 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise @@ -58,6 +77,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/reflection.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/reflection.log source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational - sourcetype: XmlWinEventLog \ No newline at end of file + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/powershell_processing_stream_of_data.yml b/detections/endpoint/powershell_processing_stream_of_data.yml index 24967a1f8b..76d78cf424 100644 --- a/detections/endpoint/powershell_processing_stream_of_data.yml +++ b/detections/endpoint/powershell_processing_stream_of_data.yml @@ -1,7 +1,7 @@ name: Powershell Processing Stream Of Data id: 0d718b52-c9f1-11eb-bc61-acde48001122 -version: 6 -date: '2024-11-22' +version: 8 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: - PXA Stealer asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise diff --git a/detections/endpoint/powershell_remote_services_add_trustedhost.yml b/detections/endpoint/powershell_remote_services_add_trustedhost.yml index f8535f004f..7a96343fb7 100644 --- a/detections/endpoint/powershell_remote_services_add_trustedhost.yml +++ b/detections/endpoint/powershell_remote_services_add_trustedhost.yml @@ -1,7 +1,7 @@ name: Powershell Remote Services Add TrustedHost id: bef21d24-297e-45e3-9b9a-c6ac45450474 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.006 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/powershell_remove_windows_defender_directory.yml b/detections/endpoint/powershell_remove_windows_defender_directory.yml index 6f0ea6b1e1..8b6f9c3a6d 100644 --- a/detections/endpoint/powershell_remove_windows_defender_directory.yml +++ b/detections/endpoint/powershell_remove_windows_defender_directory.yml @@ -1,7 +1,7 @@ name: Powershell Remove Windows Defender Directory id: adf47620-79fa-11ec-b248-acde48001122 -version: 6 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/powershell_start_bitstransfer.yml b/detections/endpoint/powershell_start_bitstransfer.yml index 104e8afe41..6b50ec5b4f 100644 --- a/detections/endpoint/powershell_start_bitstransfer.yml +++ b/detections/endpoint/powershell_start_bitstransfer.yml @@ -1,6 +1,6 @@ name: PowerShell Start-BitsTransfer id: 39e2605a-90d8-11eb-899e-acde48001122 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/powershell_using_memory_as_backing_store.yml b/detections/endpoint/powershell_using_memory_as_backing_store.yml index a57cf47628..e33e455cd2 100644 --- a/detections/endpoint/powershell_using_memory_as_backing_store.yml +++ b/detections/endpoint/powershell_using_memory_as_backing_store.yml @@ -1,7 +1,7 @@ name: Powershell Using memory As Backing Store id: c396a0c4-c9f2-11eb-b4f5-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.001 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/powershell_windows_defender_exclusion_commands.yml b/detections/endpoint/powershell_windows_defender_exclusion_commands.yml index 7e80adf439..04e6fb422d 100644 --- a/detections/endpoint/powershell_windows_defender_exclusion_commands.yml +++ b/detections/endpoint/powershell_windows_defender_exclusion_commands.yml @@ -1,7 +1,7 @@ name: Powershell Windows Defender Exclusion Commands id: 907ac95c-4dd9-11ec-ba2c-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml b/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml index 0bac5ac032..06ea69848f 100644 --- a/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml +++ b/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml @@ -1,6 +1,6 @@ name: Prevent Automatic Repair Mode using Bcdedit id: 7742aa92-c9d9-11eb-bbfc-acde48001122 -version: 4 +version: 5 date: '2024-11-13' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/print_processor_registry_autostart.yml b/detections/endpoint/print_processor_registry_autostart.yml index e162953369..04f8f2a5d4 100644 --- a/detections/endpoint/print_processor_registry_autostart.yml +++ b/detections/endpoint/print_processor_registry_autostart.yml @@ -1,7 +1,7 @@ name: Print Processor Registry Autostart id: 1f5b68aa-2037-11ec-898e-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: experimental type: TTP @@ -51,7 +51,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.012 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/print_spooler_adding_a_printer_driver.yml b/detections/endpoint/print_spooler_adding_a_printer_driver.yml index 1c47ffd8df..8afd39363a 100644 --- a/detections/endpoint/print_spooler_adding_a_printer_driver.yml +++ b/detections/endpoint/print_spooler_adding_a_printer_driver.yml @@ -1,7 +1,7 @@ name: Print Spooler Adding A Printer Driver id: 313681a2-da8e-11eb-adad-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - CVE-2021-1675 mitre_attack_id: - T1547.012 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml b/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml index 5e37c7894e..7ad22f6b32 100644 --- a/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml +++ b/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml @@ -1,7 +1,7 @@ name: Print Spooler Failed to Load a Plug-in id: 1adc9548-da7c-11eb-8f13-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Michael Haag, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: - CVE-2021-1675 mitre_attack_id: - T1547.012 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml index 4cf346c8fa..820170d6e4 100644 --- a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml +++ b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml @@ -1,7 +1,7 @@ name: Process Creating LNK file in Suspicious Location id: 5d814af1-1041-47b5-a9ac-d754e82e9a26 -version: 9 -date: '2024-11-13' +version: 10 +date: '2025-02-10' author: Jose Hernandez, Michael Haag, Splunk status: production type: TTP @@ -70,7 +70,6 @@ tags: - Gozi Malware asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.002 product: - Splunk Enterprise diff --git a/detections/endpoint/process_kill_base_on_file_path.yml b/detections/endpoint/process_kill_base_on_file_path.yml index 22d03dda5e..1ec53796f1 100644 --- a/detections/endpoint/process_kill_base_on_file_path.yml +++ b/detections/endpoint/process_kill_base_on_file_path.yml @@ -1,7 +1,7 @@ name: Process Kill Base On File Path id: 5ffaa42c-acdb-11eb-9ad3-acde48001122 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/processes_launching_netsh.yml b/detections/endpoint/processes_launching_netsh.yml index e719a57984..212cf0f860 100644 --- a/detections/endpoint/processes_launching_netsh.yml +++ b/detections/endpoint/processes_launching_netsh.yml @@ -1,7 +1,7 @@ name: Processes launching netsh id: b89919ed-fe5f-492c-b139-95dbb162040e -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Josef Kuepker, Splunk status: production type: Anomaly @@ -74,7 +74,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.004 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/randomly_generated_scheduled_task_name.yml b/detections/endpoint/randomly_generated_scheduled_task_name.yml index ddca4c00e3..d54a781091 100644 --- a/detections/endpoint/randomly_generated_scheduled_task_name.yml +++ b/detections/endpoint/randomly_generated_scheduled_task_name.yml @@ -1,7 +1,7 @@ name: Randomly Generated Scheduled Task Name id: 9d22a780-5165-11ec-ad4f-3e22fbd008af -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: experimental type: Hunting @@ -33,7 +33,6 @@ tags: - Scheduled Tasks asset_type: Endpoint mitre_attack_id: - - T1053 - T1053.005 product: - Splunk Enterprise diff --git a/detections/endpoint/randomly_generated_windows_service_name.yml b/detections/endpoint/randomly_generated_windows_service_name.yml index da693af615..eac52741ca 100644 --- a/detections/endpoint/randomly_generated_windows_service_name.yml +++ b/detections/endpoint/randomly_generated_windows_service_name.yml @@ -1,7 +1,7 @@ name: Randomly Generated Windows Service Name id: 2032a95a-5165-11ec-a2c3-3e22fbd008af -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: experimental type: Hunting @@ -30,7 +30,6 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1543 - T1543.003 product: - Splunk Enterprise diff --git a/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml b/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml index 15539d184d..b217c5d2a0 100644 --- a/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml +++ b/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml @@ -1,6 +1,6 @@ name: Recon AVProduct Through Pwh or WMI id: 28077620-c9f6-11eb-8785-acde48001122 -version: 5 +version: 6 date: '2024-11-13' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml b/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml index 3ba5e16d48..89aa7cb4e4 100644 --- a/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml +++ b/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml @@ -1,7 +1,7 @@ name: Recursive Delete of Directory In Batch CMD id: ba570b3a-d356-11eb-8358-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1070.004 - - T1070 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml index f11cc03166..096acf7bf7 100644 --- a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml +++ b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml @@ -1,7 +1,7 @@ name: Reg exe Manipulating Windows Services Registry Keys id: 8470d755-0c13-45b3-bd63-387a373c10cf -version: 8 -date: '2024-11-13' +version: 10 +date: '2025-02-10' author: Rico Valdez, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.011 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/registry_keys_for_creating_shim_databases.yml b/detections/endpoint/registry_keys_for_creating_shim_databases.yml index 7d20f02115..aeec02af3e 100644 --- a/detections/endpoint/registry_keys_for_creating_shim_databases.yml +++ b/detections/endpoint/registry_keys_for_creating_shim_databases.yml @@ -1,7 +1,7 @@ name: Registry Keys for Creating SHIM Databases id: f5f6af30-7aa7-4295-bfe9-07fe87c01bbb -version: 10 -date: '2024-12-08' +version: 12 +date: '2025-02-10' author: Patrick Bareiss, Teoderick Contreras, Splunk, Steven Dick, Bhavin Patel status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.011 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index 9f542cbcf2..841571bdaf 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -1,7 +1,7 @@ name: Registry Keys Used For Persistence id: f5f6af30-7aa7-4295-bfe9-07fe87c01a4b -version: 15 -date: '2025-01-27' +version: 16 +date: '2025-02-10' author: Jose Hernandez, David Dorsey, Teoderick Contreras, Rod Soto, Splunk status: production type: TTP @@ -109,7 +109,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.001 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security @@ -118,6 +117,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml index 37f1c77d98..fe8be39dd9 100644 --- a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml +++ b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Registry Keys Used For Privilege Escalation id: c9f4b923-f8af-4155-b697-1354f5bcbc5e -version: 11 -date: '2024-12-08' +version: 12 +date: '2025-02-10' author: David Dorsey, Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.012 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml b/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml index fa6a03e4f6..89f088a05b 100644 --- a/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml +++ b/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml @@ -1,7 +1,7 @@ name: Regsvr32 Silent and Install Param Dll Loading id: f421c250-24e7-11ec-bc43-acde48001122 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -76,7 +76,6 @@ tags: - Suspicious Regsvr32 Activity asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.010 product: - Splunk Enterprise diff --git a/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml b/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml index 624108b462..43b74c27f5 100644 --- a/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml +++ b/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml @@ -1,7 +1,7 @@ name: Regsvr32 with Known Silent Switch Cmdline id: c9ef7dc4-eeaf-11eb-b2b6-acde48001122 -version: 6 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -76,7 +76,6 @@ tags: - AsyncRAT asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.010 product: - Splunk Enterprise diff --git a/detections/endpoint/remote_desktop_process_running_on_system.yml b/detections/endpoint/remote_desktop_process_running_on_system.yml index 98b7d2a398..90532d273c 100644 --- a/detections/endpoint/remote_desktop_process_running_on_system.yml +++ b/detections/endpoint/remote_desktop_process_running_on_system.yml @@ -1,7 +1,7 @@ name: Remote Desktop Process Running On System id: f5939373-8054-40ad-8c64-cec478a22a4a -version: 8 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: David Dorsey, Splunk status: experimental type: Hunting @@ -40,7 +40,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.001 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml index 538d923090..c9b9804885 100644 --- a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml +++ b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml @@ -1,7 +1,7 @@ name: Remote Process Instantiation via DCOM and PowerShell id: d4f42098-4680-11ec-ad07-3e22fbd008af -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -66,7 +66,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.003 product: - Splunk Enterprise diff --git a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml index 4f4648445b..2b3c8abaab 100644 --- a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml +++ b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml @@ -1,7 +1,7 @@ name: Remote Process Instantiation via DCOM and PowerShell Script Block id: fa1c3040-4680-11ec-a618-3e22fbd008af -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -54,7 +54,6 @@ tags: - Active Directory Lateral Movement asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.003 product: - Splunk Enterprise diff --git a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml index 8b574d9bb7..fc7a0db67d 100644 --- a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml +++ b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml @@ -1,7 +1,7 @@ name: Remote Process Instantiation via WinRM and PowerShell id: ba24cda8-4716-11ec-8009-3e22fbd008af -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: - Active Directory Lateral Movement asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.006 product: - Splunk Enterprise diff --git a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml index d2cff18278..63c06643c1 100644 --- a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml +++ b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml @@ -1,7 +1,7 @@ name: Remote Process Instantiation via WinRM and PowerShell Script Block id: 7d4c618e-4716-11ec-951c-3e22fbd008af -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: - Active Directory Lateral Movement asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.006 product: - Splunk Enterprise diff --git a/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml b/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml index 4d5ae43729..f2d3dcf4d5 100644 --- a/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml +++ b/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml @@ -1,7 +1,7 @@ name: Remote Process Instantiation via WinRM and Winrs id: 0dd296a2-4338-11ec-ba02-3e22fbd008af -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: - Active Directory Lateral Movement asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.006 product: - Splunk Enterprise diff --git a/detections/endpoint/rubeus_command_line_parameters.yml b/detections/endpoint/rubeus_command_line_parameters.yml index 9a0fe4997a..8d0e78f4ef 100644 --- a/detections/endpoint/rubeus_command_line_parameters.yml +++ b/detections/endpoint/rubeus_command_line_parameters.yml @@ -1,7 +1,7 @@ name: Rubeus Command Line Parameters id: cca37478-8377-11ec-b59a-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -78,9 +78,7 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1550 - T1550.003 - - T1558 - T1558.003 - T1558.004 product: diff --git a/detections/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access.yml b/detections/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access.yml index e9200fe464..5950c1ca67 100644 --- a/detections/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access.yml +++ b/detections/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access.yml @@ -1,7 +1,7 @@ name: Rubeus Kerberos Ticket Exports Through Winlogon Access id: 5ed8c50a-8869-11ec-876f-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1550 - T1550.003 product: - Splunk Enterprise diff --git a/detections/endpoint/runas_execution_in_commandline.yml b/detections/endpoint/runas_execution_in_commandline.yml index dd66057bfe..0ed47331a5 100644 --- a/detections/endpoint/runas_execution_in_commandline.yml +++ b/detections/endpoint/runas_execution_in_commandline.yml @@ -1,7 +1,7 @@ name: Runas Execution in CommandLine id: 4807e716-43a4-11ec-a0e7-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -44,7 +44,6 @@ tags: - Windows Privilege Escalation asset_type: Endpoint mitre_attack_id: - - T1134 - T1134.001 product: - Splunk Enterprise diff --git a/detections/endpoint/rundll32_control_rundll_hunt.yml b/detections/endpoint/rundll32_control_rundll_hunt.yml index dc0beb376a..b1ad8f7ef5 100644 --- a/detections/endpoint/rundll32_control_rundll_hunt.yml +++ b/detections/endpoint/rundll32_control_rundll_hunt.yml @@ -1,7 +1,7 @@ name: Rundll32 Control RunDLL Hunt id: c8e7ced0-10c5-11ec-8b03-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -50,7 +50,6 @@ tags: cve: - CVE-2021-40444 mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml b/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml index aa845361b4..1d2585be25 100644 --- a/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml +++ b/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml @@ -1,7 +1,7 @@ name: Rundll32 Control RunDLL World Writable Directory id: 1adffe86-10c3-11ec-8ce6-acde48001122 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -81,7 +81,6 @@ tags: cve: - CVE-2021-40444 mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/rundll32_dnsquery.yml b/detections/endpoint/rundll32_dnsquery.yml index f72c6c3ba3..398448fbaf 100644 --- a/detections/endpoint/rundll32_dnsquery.yml +++ b/detections/endpoint/rundll32_dnsquery.yml @@ -1,7 +1,7 @@ name: Rundll32 DNSQuery id: f1483f5e-ee29-11eb-9d23-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/rundll32_lockworkstation.yml b/detections/endpoint/rundll32_lockworkstation.yml index b3a0ca0968..4f3f8a2188 100644 --- a/detections/endpoint/rundll32_lockworkstation.yml +++ b/detections/endpoint/rundll32_lockworkstation.yml @@ -1,7 +1,7 @@ name: Rundll32 LockWorkStation id: fa90f372-f91d-11eb-816c-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -62,7 +62,6 @@ tags: - Ransomware asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/rundll32_process_creating_exe_dll_files.yml b/detections/endpoint/rundll32_process_creating_exe_dll_files.yml index 7381fd77d0..b3203c8ad4 100644 --- a/detections/endpoint/rundll32_process_creating_exe_dll_files.yml +++ b/detections/endpoint/rundll32_process_creating_exe_dll_files.yml @@ -1,7 +1,7 @@ name: Rundll32 Process Creating Exe Dll Files id: 6338266a-ee2a-11eb-bf68-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -54,7 +54,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml b/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml index b668edd1ef..23f1723414 100644 --- a/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml +++ b/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml @@ -1,7 +1,7 @@ name: Rundll32 with no Command Line Arguments with Network id: 35307032-a12d-11eb-835f-acde48001122 -version: 8 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Steven Dick, Michael Haag, Splunk status: production type: TTP @@ -78,7 +78,6 @@ tags: cve: - CVE-2021-34527 mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/rundll_loading_dll_by_ordinal.yml b/detections/endpoint/rundll_loading_dll_by_ordinal.yml index b8fccdd6c4..fc41b88df5 100644 --- a/detections/endpoint/rundll_loading_dll_by_ordinal.yml +++ b/detections/endpoint/rundll_loading_dll_by_ordinal.yml @@ -1,7 +1,7 @@ name: RunDLL Loading DLL By Ordinal id: 6c135f8d-5e60-454e-80b7-c56eed739833 -version: 9 -date: '2024-11-13' +version: 10 +date: '2025-02-10' author: Michael Haag, David Dorsey, Splunk status: production type: TTP @@ -72,7 +72,6 @@ tags: - IcedID asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/ryuk_wake_on_lan_command.yml b/detections/endpoint/ryuk_wake_on_lan_command.yml index e7f88ed5c7..4bfc808d08 100644 --- a/detections/endpoint/ryuk_wake_on_lan_command.yml +++ b/detections/endpoint/ryuk_wake_on_lan_command.yml @@ -1,7 +1,7 @@ name: Ryuk Wake on LAN Command id: 538d0152-7aaa-11eb-beaa-acde48001122 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -68,7 +68,6 @@ tags: - Ryuk Ransomware asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.003 product: - Splunk Enterprise diff --git a/detections/endpoint/sam_database_file_access_attempt.yml b/detections/endpoint/sam_database_file_access_attempt.yml index e76cbb1396..2ce1ddaa93 100644 --- a/detections/endpoint/sam_database_file_access_attempt.yml +++ b/detections/endpoint/sam_database_file_access_attempt.yml @@ -1,7 +1,7 @@ name: SAM Database File Access Attempt id: 57551656-ebdb-11eb-afdf-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Mauricio Velazco, Splunk status: production type: Hunting @@ -42,7 +42,6 @@ tags: - CVE-2021-36934 mitre_attack_id: - T1003.002 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/sc_exe_manipulating_windows_services.yml b/detections/endpoint/sc_exe_manipulating_windows_services.yml index ab462622b5..d08cad9a5b 100644 --- a/detections/endpoint/sc_exe_manipulating_windows_services.yml +++ b/detections/endpoint/sc_exe_manipulating_windows_services.yml @@ -1,7 +1,7 @@ name: Sc exe Manipulating Windows Services id: f0c693d8-2a89-4ce7-80b4-98fea4c3ea6d -version: 7 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Rico Valdez, Splunk status: production type: TTP @@ -76,7 +76,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1543.003 - - T1543 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml b/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml index fff2339458..1d84e7384b 100644 --- a/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml +++ b/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml @@ -1,7 +1,7 @@ name: SchCache Change By App Connect And Create ADSI Object id: 991eb510-0fc6-11ec-82d3-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml b/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml index 7732be5bf9..f23eb706b0 100644 --- a/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml +++ b/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml @@ -1,7 +1,7 @@ name: Scheduled Task Creation on Remote Endpoint using At id: 4be54858-432f-11ec-8209-3e22fbd008af -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: - Scheduled Tasks asset_type: Endpoint mitre_attack_id: - - T1053 - T1053.002 product: - Splunk Enterprise diff --git a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml index 3b47886f19..5090e71991 100644 --- a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml +++ b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml @@ -1,7 +1,7 @@ name: Scheduled Task Deleted Or Created via CMD id: d5af132c-7c17-439c-9d31-13d55340f36c -version: 10 -date: '2025-01-27' +version: 12 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -95,7 +95,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.005 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security @@ -104,6 +103,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml b/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml index 80d3a28e57..d44dbd1f24 100644 --- a/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml +++ b/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml @@ -1,7 +1,7 @@ name: Scheduled Task Initiation on Remote Endpoint id: 95cf4608-4302-11ec-8194-3e22fbd008af -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk, Badoodish, Github Community status: production type: TTP @@ -64,7 +64,6 @@ tags: - Scheduled Tasks asset_type: Endpoint mitre_attack_id: - - T1053 - T1053.005 product: - Splunk Enterprise diff --git a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml index a32d7dca97..48b5d1fa98 100644 --- a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml +++ b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml @@ -1,7 +1,7 @@ name: Schtasks scheduling job on remote system id: 1297fb80-f42a-4b4a-9c8a-88c066237cf6 -version: 11 -date: '2024-12-10' +version: 12 +date: '2025-02-10' author: David Dorsey, Mauricio Velazco, Splunk status: production type: TTP @@ -76,7 +76,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.005 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml index 72e8073ffc..ff5ff09caa 100644 --- a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml +++ b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml @@ -1,7 +1,7 @@ name: Schtasks used for forcing a reboot id: 1297fb80-f42a-4b4a-9c8a-88c066437cf6 -version: 7 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.005 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/screensaver_event_trigger_execution.yml b/detections/endpoint/screensaver_event_trigger_execution.yml index 1b68e6996f..b7668b1a51 100644 --- a/detections/endpoint/screensaver_event_trigger_execution.yml +++ b/detections/endpoint/screensaver_event_trigger_execution.yml @@ -1,7 +1,7 @@ name: Screensaver Event Trigger Execution id: 58cea3ec-1f6d-11ec-8560-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1546 - T1546.002 product: - Splunk Enterprise diff --git a/detections/endpoint/sdclt_uac_bypass.yml b/detections/endpoint/sdclt_uac_bypass.yml index 4efac5ec1b..c6c89c02b0 100644 --- a/detections/endpoint/sdclt_uac_bypass.yml +++ b/detections/endpoint/sdclt_uac_bypass.yml @@ -1,7 +1,7 @@ name: Sdclt UAC Bypass id: d71efbf6-da63-11eb-8c6e-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Steven Dick, Teoderick Contreras, Splunk status: production type: TTP @@ -75,7 +75,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/sdelete_application_execution.yml b/detections/endpoint/sdelete_application_execution.yml index 30f375f28a..10aefc21a4 100644 --- a/detections/endpoint/sdelete_application_execution.yml +++ b/detections/endpoint/sdelete_application_execution.yml @@ -1,7 +1,7 @@ name: Sdelete Application Execution id: 31702fc0-2682-11ec-85c3-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -65,9 +65,8 @@ tags: - Masquerading - Rename System Utilities asset_type: Endpoint mitre_attack_id: - - T1485 - T1070.004 - - T1070 + - T1485 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml index f973ba81b6..fb76934525 100644 --- a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml +++ b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml @@ -1,7 +1,7 @@ name: SecretDumps Offline NTDS Dumping Tool id: 5672819c-be09-11eb-bbfb-acde48001122 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.003 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml b/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml index 735ed9149a..1abd21eb3c 100644 --- a/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml +++ b/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml @@ -1,6 +1,6 @@ name: ServicePrincipalNames Discovery with SetSPN id: ae8b3efc-2d2e-11ec-8b57-acde48001122 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/services_lolbas_execution_process_spawn.yml b/detections/endpoint/services_lolbas_execution_process_spawn.yml index 7d8de9c979..50ab6ea4fd 100644 --- a/detections/endpoint/services_lolbas_execution_process_spawn.yml +++ b/detections/endpoint/services_lolbas_execution_process_spawn.yml @@ -1,7 +1,7 @@ name: Services LOLBAS Execution Process Spawn id: ba9e1954-4c04-11ec-8b74-3e22fbd008af -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -77,7 +77,6 @@ tags: - CISA AA23-347A asset_type: Endpoint mitre_attack_id: - - T1543 - T1543.003 product: - Splunk Enterprise diff --git a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml index edfccceae6..00822bc0c3 100644 --- a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml +++ b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml @@ -1,7 +1,7 @@ name: Set Default PowerShell Execution Policy To Unrestricted or Bypass id: c2590137-0b08-4985-9ec5-6ae23d92f63d -version: 12 -date: '2024-11-13' +version: 13 +date: '2025-02-10' author: Steven Dick, Patrick Bareiss, Splunk status: production type: TTP @@ -79,7 +79,6 @@ tags: - DarkGate Malware asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise diff --git a/detections/endpoint/shim_database_file_creation.yml b/detections/endpoint/shim_database_file_creation.yml index 21a14c236b..21bd64b76b 100644 --- a/detections/endpoint/shim_database_file_creation.yml +++ b/detections/endpoint/shim_database_file_creation.yml @@ -1,7 +1,7 @@ name: Shim Database File Creation id: 6e4c4588-ba2f-42fa-97e6-9f6f548eaa33 -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: David Dorsey, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.011 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml index 9e30f471ff..37302453aa 100644 --- a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml +++ b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml @@ -1,7 +1,7 @@ name: Shim Database Installation With Suspicious Parameters id: 404620de-46d8-48b6-90cc-8a8d7b0876a3 -version: 8 -date: '2024-12-16' +version: 9 +date: '2025-02-10' author: David Dorsey, Splunk status: production type: TTP @@ -17,8 +17,21 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = sdbinst.exe NOT Processes.process IN ("\"C:\\Windows\\System32\\sdbinst.exe\"", "C:\\Windows\\System32\\sdbinst.exe", "*-mm", "*-?", "*-m -bg") by Processes.process_name Processes.parent_process_name Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `shim_database_installation_with_suspicious_parameters_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +search: '| tstats `security_content_summariesonly` values(Processes.process) as process + min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where Processes.process_name = sdbinst.exe NOT Processes.process IN ("\"C:\\Windows\\System32\\sdbinst.exe\"", + "C:\\Windows\\System32\\sdbinst.exe", "*-mm", "*-?", "*-m -bg") by Processes.process_name + Processes.parent_process_name Processes.dest Processes.user | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `shim_database_installation_with_suspicious_parameters_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. known_false_positives: None identified references: [] drilldown_searches: @@ -53,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.011 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security @@ -62,6 +74,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.011/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.011/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/short_lived_windows_accounts.yml b/detections/endpoint/short_lived_windows_accounts.yml index 528b8e0280..2004bdfab1 100644 --- a/detections/endpoint/short_lived_windows_accounts.yml +++ b/detections/endpoint/short_lived_windows_accounts.yml @@ -1,7 +1,7 @@ name: Short Lived Windows Accounts id: b25f6f62-0782-43c1-b403-083231ffd97d -version: 7 -date: '2024-11-22' +version: 8 +date: '2025-02-10' author: David Dorsey, Bhavin Patel, Splunk status: production type: TTP @@ -64,9 +64,8 @@ tags: - Active Directory Lateral Movement asset_type: Windows mitre_attack_id: - - T1136.001 - - T1136 - T1078.003 + - T1136.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/silentcleanup_uac_bypass.yml b/detections/endpoint/silentcleanup_uac_bypass.yml index 9c6c70c9c5..a18bda03a1 100644 --- a/detections/endpoint/silentcleanup_uac_bypass.yml +++ b/detections/endpoint/silentcleanup_uac_bypass.yml @@ -1,7 +1,7 @@ name: SilentCleanup UAC Bypass id: 56d7cfcc-da63-11eb-92d4-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Steven Dick, Teoderick Contreras, Splunk status: production type: TTP @@ -74,7 +74,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/single_letter_process_on_endpoint.yml b/detections/endpoint/single_letter_process_on_endpoint.yml index 29bfc12c8d..8c6caa9566 100644 --- a/detections/endpoint/single_letter_process_on_endpoint.yml +++ b/detections/endpoint/single_letter_process_on_endpoint.yml @@ -1,7 +1,7 @@ name: Single Letter Process On Endpoint id: a4214f0b-e01c-41bc-8cc4-d2b71e3056b4 -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: David Dorsey, Splunk status: production type: TTP @@ -67,7 +67,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1204 - T1204.002 product: - Splunk Enterprise diff --git a/detections/endpoint/slui_runas_elevated.yml b/detections/endpoint/slui_runas_elevated.yml index 02cbd1a2ae..fccaeca2c1 100644 --- a/detections/endpoint/slui_runas_elevated.yml +++ b/detections/endpoint/slui_runas_elevated.yml @@ -1,7 +1,7 @@ name: SLUI RunAs Elevated id: 8d124810-b3e4-11eb-96c7-acde48001122 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/slui_spawning_a_process.yml b/detections/endpoint/slui_spawning_a_process.yml index a9b5887f11..118a53b0ef 100644 --- a/detections/endpoint/slui_spawning_a_process.yml +++ b/detections/endpoint/slui_spawning_a_process.yml @@ -1,7 +1,7 @@ name: SLUI Spawning a Process id: 879c4330-b3e0-11eb-b1b1-acde48001122 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/spoolsv_spawning_rundll32.yml b/detections/endpoint/spoolsv_spawning_rundll32.yml index 04f2ce636b..70da48f52e 100644 --- a/detections/endpoint/spoolsv_spawning_rundll32.yml +++ b/detections/endpoint/spoolsv_spawning_rundll32.yml @@ -1,7 +1,7 @@ name: Spoolsv Spawning Rundll32 id: 15d905f6-da6b-11eb-ab82-acde48001122 -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Michael Haag, Splunk status: production type: TTP @@ -72,7 +72,6 @@ tags: - CVE-2021-34527 mitre_attack_id: - T1547.012 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/spoolsv_suspicious_loaded_modules.yml b/detections/endpoint/spoolsv_suspicious_loaded_modules.yml index eda8f672d8..07a521d03e 100644 --- a/detections/endpoint/spoolsv_suspicious_loaded_modules.yml +++ b/detections/endpoint/spoolsv_suspicious_loaded_modules.yml @@ -1,7 +1,7 @@ name: Spoolsv Suspicious Loaded Modules id: a5e451f8-da81-11eb-b245-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk status: production type: TTP @@ -55,7 +55,6 @@ tags: - CVE-2021-34527 mitre_attack_id: - T1547.012 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/spoolsv_suspicious_process_access.yml b/detections/endpoint/spoolsv_suspicious_process_access.yml index ee46ef235d..a41111a7b1 100644 --- a/detections/endpoint/spoolsv_suspicious_process_access.yml +++ b/detections/endpoint/spoolsv_suspicious_process_access.yml @@ -1,6 +1,6 @@ name: Spoolsv Suspicious Process Access id: 799b606e-da81-11eb-93f8-acde48001122 -version: 5 +version: 6 date: '2024-11-13' author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/spoolsv_writing_a_dll.yml b/detections/endpoint/spoolsv_writing_a_dll.yml index e4665434d5..3111e77d23 100644 --- a/detections/endpoint/spoolsv_writing_a_dll.yml +++ b/detections/endpoint/spoolsv_writing_a_dll.yml @@ -1,7 +1,7 @@ name: Spoolsv Writing a DLL id: d5bf5cf2-da71-11eb-92c2-acde48001122 -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Michael Haag, Splunk status: production type: TTP @@ -70,7 +70,6 @@ tags: - CVE-2021-34527 mitre_attack_id: - T1547.012 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml b/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml index 255480b538..de8fec23dd 100644 --- a/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml +++ b/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml @@ -1,7 +1,7 @@ name: Spoolsv Writing a DLL - Sysmon id: 347fd388-da87-11eb-836d-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Michael Haag, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - CVE-2021-34527 mitre_attack_id: - T1547.012 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_computer_account_name_change.yml b/detections/endpoint/suspicious_computer_account_name_change.yml index 25a57db4be..e7aaee43b7 100644 --- a/detections/endpoint/suspicious_computer_account_name_change.yml +++ b/detections/endpoint/suspicious_computer_account_name_change.yml @@ -1,7 +1,7 @@ name: Suspicious Computer Account Name Change id: 35a61ed8-61c4-11ec-bc1e-acde48001122 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - CVE-2021-42287 - CVE-2021-42278 mitre_attack_id: - - T1078 - T1078.002 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_copy_on_system32.yml b/detections/endpoint/suspicious_copy_on_system32.yml index 552376e126..74724bd7d7 100644 --- a/detections/endpoint/suspicious_copy_on_system32.yml +++ b/detections/endpoint/suspicious_copy_on_system32.yml @@ -1,7 +1,7 @@ name: Suspicious Copy on System32 id: ce633e56-25b2-11ec-9e76-acde48001122 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -76,7 +76,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1036.003 - - T1036 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_event_log_service_behavior.yml b/detections/endpoint/suspicious_event_log_service_behavior.yml index bac4d7f013..6900ba2b70 100644 --- a/detections/endpoint/suspicious_event_log_service_behavior.yml +++ b/detections/endpoint/suspicious_event_log_service_behavior.yml @@ -1,7 +1,7 @@ name: Suspicious Event Log Service Behavior id: 2b85aa3d-f5f6-4c2e-a081-a09f6e1c2e40 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -33,7 +33,6 @@ tags: - Clop Ransomware asset_type: Endpoint mitre_attack_id: - - T1070 - T1070.001 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml b/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml index f966afa7c3..0af0bc7214 100644 --- a/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml +++ b/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml @@ -1,7 +1,7 @@ name: Suspicious IcedID Rundll32 Cmdline id: bed761f8-ee29-11eb-8bf3-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_kerberos_service_ticket_request.yml b/detections/endpoint/suspicious_kerberos_service_ticket_request.yml index b8c5f71cac..2f08209956 100644 --- a/detections/endpoint/suspicious_kerberos_service_ticket_request.yml +++ b/detections/endpoint/suspicious_kerberos_service_ticket_request.yml @@ -1,7 +1,7 @@ name: Suspicious Kerberos Service Ticket Request id: 8b1297bc-6204-11ec-b7c4-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - CVE-2021-42287 - CVE-2021-42278 mitre_attack_id: - - T1078 - T1078.002 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml index 31415533bd..4484fb6321 100644 --- a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml +++ b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml @@ -1,7 +1,7 @@ name: Suspicious microsoft workflow compiler rename id: f0db4464-55d9-11eb-ae93-0242ac130002 -version: 8 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -47,9 +47,8 @@ tags: - Graceful Wipe Out Attack asset_type: Endpoint mitre_attack_id: - - T1036 - - T1127 - T1036.003 + - T1127 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_msbuild_path.yml b/detections/endpoint/suspicious_msbuild_path.yml index 1ee9e409d7..fc2f44999f 100644 --- a/detections/endpoint/suspicious_msbuild_path.yml +++ b/detections/endpoint/suspicious_msbuild_path.yml @@ -1,7 +1,7 @@ name: Suspicious msbuild path id: f5198224-551c-11eb-ae93-0242ac130002 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -72,8 +72,6 @@ tags: - Graceful Wipe Out Attack asset_type: Endpoint mitre_attack_id: - - T1036 - - T1127 - T1036.003 - T1127.001 product: diff --git a/detections/endpoint/suspicious_msbuild_rename.yml b/detections/endpoint/suspicious_msbuild_rename.yml index 438fcdeb92..f9bd30e77d 100644 --- a/detections/endpoint/suspicious_msbuild_rename.yml +++ b/detections/endpoint/suspicious_msbuild_rename.yml @@ -1,7 +1,7 @@ name: Suspicious MSBuild Rename id: 4006adac-5937-11eb-ae93-0242ac130002 -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -48,8 +48,6 @@ tags: - Graceful Wipe Out Attack asset_type: Endpoint mitre_attack_id: - - T1036 - - T1127 - T1036.003 - T1127.001 product: diff --git a/detections/endpoint/suspicious_msbuild_spawn.yml b/detections/endpoint/suspicious_msbuild_spawn.yml index 1c23444d24..897b1fd22e 100644 --- a/detections/endpoint/suspicious_msbuild_spawn.yml +++ b/detections/endpoint/suspicious_msbuild_spawn.yml @@ -1,7 +1,7 @@ name: Suspicious MSBuild Spawn id: a115fba6-5514-11eb-ae93-0242ac130002 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -67,7 +67,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1127 - T1127.001 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_mshta_child_process.yml b/detections/endpoint/suspicious_mshta_child_process.yml index 55035b8d46..7e5a50e44b 100644 --- a/detections/endpoint/suspicious_mshta_child_process.yml +++ b/detections/endpoint/suspicious_mshta_child_process.yml @@ -1,7 +1,7 @@ name: Suspicious mshta child process id: 60023bb6-5500-11eb-ae93-0242ac130002 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -74,7 +74,6 @@ tags: - Lumma Stealer asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.005 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_mshta_spawn.yml b/detections/endpoint/suspicious_mshta_spawn.yml index 95a3c39c82..bffd402f2c 100644 --- a/detections/endpoint/suspicious_mshta_spawn.yml +++ b/detections/endpoint/suspicious_mshta_spawn.yml @@ -1,7 +1,7 @@ name: Suspicious mshta spawn id: 4d33a488-5b5f-11eb-ae93-0242ac130002 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.005 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_plistbuddy_usage.yml b/detections/endpoint/suspicious_plistbuddy_usage.yml index 76c97f45ec..f3dc262cfd 100644 --- a/detections/endpoint/suspicious_plistbuddy_usage.yml +++ b/detections/endpoint/suspicious_plistbuddy_usage.yml @@ -1,7 +1,7 @@ name: Suspicious PlistBuddy Usage id: c3194009-e0eb-4f84-87a9-4070f8688f00 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: experimental type: TTP @@ -53,7 +53,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1543.001 - - T1543 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_plistbuddy_usage_via_osquery.yml b/detections/endpoint/suspicious_plistbuddy_usage_via_osquery.yml index 6bb4e11150..ec7ee9dc78 100644 --- a/detections/endpoint/suspicious_plistbuddy_usage_via_osquery.yml +++ b/detections/endpoint/suspicious_plistbuddy_usage_via_osquery.yml @@ -1,7 +1,7 @@ name: Suspicious PlistBuddy Usage via OSquery id: 20ba6c32-c733-4a32-b64e-2688cf231399 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: experimental type: TTP @@ -37,7 +37,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1543.001 - - T1543 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml b/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml index 1bce9c0f7d..d239401dda 100644 --- a/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml +++ b/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml @@ -1,7 +1,7 @@ name: Suspicious Process DNS Query Known Abuse Web Services id: 3cf0dc36-484d-11ec-a6bc-acde48001122 -version: 8 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.005 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_process_with_discord_dns_query.yml b/detections/endpoint/suspicious_process_with_discord_dns_query.yml index 29366f73c9..4dd954857d 100644 --- a/detections/endpoint/suspicious_process_with_discord_dns_query.yml +++ b/detections/endpoint/suspicious_process_with_discord_dns_query.yml @@ -1,7 +1,7 @@ name: Suspicious Process With Discord DNS Query id: 4d4332ae-792c-11ec-89c1-acde48001122 -version: 6 -date: '2024-11-22' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.005 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_reg_exe_process.yml b/detections/endpoint/suspicious_reg_exe_process.yml index 1d7dfc280a..0add6178bb 100644 --- a/detections/endpoint/suspicious_reg_exe_process.yml +++ b/detections/endpoint/suspicious_reg_exe_process.yml @@ -1,6 +1,6 @@ name: Suspicious Reg exe Process id: a6b3ab4e-dd77-4213-95fa-fc94701995e0 -version: 8 +version: 9 date: '2024-11-13' author: David Dorsey, Splunk status: production diff --git a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml index 65c6989495..598771f5eb 100644 --- a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml +++ b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml @@ -1,7 +1,7 @@ name: Suspicious Regsvr32 Register Suspicious Path id: 62732736-6250-11eb-ae93-0242ac130002 -version: 10 -date: '2025-01-27' +version: 12 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -82,7 +82,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.010 product: - Splunk Enterprise @@ -92,6 +91,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.010/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.010/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml index 31ca3d198e..3a91a79903 100644 --- a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml +++ b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml @@ -1,7 +1,7 @@ name: Suspicious Rundll32 dllregisterserver id: 8c00a385-9b86-4ac0-8932-c9ec3713b159 -version: 6 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -78,7 +78,6 @@ tags: - IcedID asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml b/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml index 519b5bc050..a409f211ca 100644 --- a/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Suspicious Rundll32 no Command Line Arguments id: e451bd16-e4c5-4109-8eb1-c4c6ecf048b4 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -74,7 +74,6 @@ tags: cve: - CVE-2021-34527 mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_rundll32_plugininit.yml b/detections/endpoint/suspicious_rundll32_plugininit.yml index ab0d1c31be..1d83ad1012 100644 --- a/detections/endpoint/suspicious_rundll32_plugininit.yml +++ b/detections/endpoint/suspicious_rundll32_plugininit.yml @@ -1,7 +1,7 @@ name: Suspicious Rundll32 PluginInit id: 92d51712-ee29-11eb-b1ae-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - IcedID asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_rundll32_startw.yml b/detections/endpoint/suspicious_rundll32_startw.yml index 2c39e6dec8..734b077b09 100644 --- a/detections/endpoint/suspicious_rundll32_startw.yml +++ b/detections/endpoint/suspicious_rundll32_startw.yml @@ -1,7 +1,7 @@ name: Suspicious Rundll32 StartW id: 9319dda5-73f2-4d43-a85a-67ce961bddb7 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: - Graceful Wipe Out Attack asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml index 7fce587c31..8e78c248d6 100644 --- a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml +++ b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml @@ -1,7 +1,7 @@ name: Suspicious Scheduled Task from Public Directory id: 7feb7972-7ac3-11eb-bac8-acde48001122 -version: 5 -date: '2025-01-27' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -81,7 +81,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.005 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security @@ -90,6 +89,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/schtasks/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/schtasks/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/suspicious_ticket_granting_ticket_request.yml b/detections/endpoint/suspicious_ticket_granting_ticket_request.yml index 069de0c8e2..e51bfe28b4 100644 --- a/detections/endpoint/suspicious_ticket_granting_ticket_request.yml +++ b/detections/endpoint/suspicious_ticket_granting_ticket_request.yml @@ -1,7 +1,7 @@ name: Suspicious Ticket Granting Ticket Request id: d77d349e-6269-11ec-9cfe-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -39,7 +39,6 @@ tags: - Active Directory Privilege Escalation asset_type: Endpoint mitre_attack_id: - - T1078 - T1078.002 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_wevtutil_usage.yml b/detections/endpoint/suspicious_wevtutil_usage.yml index 321027b633..39b6278f58 100644 --- a/detections/endpoint/suspicious_wevtutil_usage.yml +++ b/detections/endpoint/suspicious_wevtutil_usage.yml @@ -1,7 +1,7 @@ name: Suspicious wevtutil Usage id: 2827c0fd-e1be-4868-ae25-59d28e0f9d4f -version: 8 -date: '2024-11-13' +version: 10 +date: '2025-02-10' author: David Dorsey, Michael Haag, Teoderick Contreras, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1070.001 - - T1070 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/svchost_lolbas_execution_process_spawn.yml b/detections/endpoint/svchost_lolbas_execution_process_spawn.yml index 256c4e7869..ef195b0980 100644 --- a/detections/endpoint/svchost_lolbas_execution_process_spawn.yml +++ b/detections/endpoint/svchost_lolbas_execution_process_spawn.yml @@ -1,7 +1,7 @@ name: Svchost LOLBAS Execution Process Spawn id: 09e5c72a-4c0d-11ec-aa29-3e22fbd008af -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -75,7 +75,6 @@ tags: - Scheduled Tasks asset_type: Endpoint mitre_attack_id: - - T1053 - T1053.005 product: - Splunk Enterprise diff --git a/detections/endpoint/system_processes_run_from_unexpected_locations.yml b/detections/endpoint/system_processes_run_from_unexpected_locations.yml index 689b31f757..4821dfd05e 100644 --- a/detections/endpoint/system_processes_run_from_unexpected_locations.yml +++ b/detections/endpoint/system_processes_run_from_unexpected_locations.yml @@ -1,7 +1,7 @@ name: System Processes Run From Unexpected Locations id: a34aae96-ccf8-4aef-952c-3ea21444444d -version: 9 -date: '2024-11-13' +version: 10 +date: '2025-02-10' author: David Dorsey, Michael Haag, Splunk status: production type: Anomaly @@ -72,7 +72,6 @@ tags: - DarkGate Malware asset_type: Endpoint mitre_attack_id: - - T1036 - T1036.003 product: - Splunk Enterprise diff --git a/detections/endpoint/system_user_discovery_with_query.yml b/detections/endpoint/system_user_discovery_with_query.yml index 249c62b457..cd0788aeb9 100644 --- a/detections/endpoint/system_user_discovery_with_query.yml +++ b/detections/endpoint/system_user_discovery_with_query.yml @@ -1,7 +1,7 @@ name: System User Discovery With Query id: ad03bfcf-8a91-4bc2-a500-112993deba87 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-05' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -17,9 +17,8 @@ data_source: - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="query.exe") - (Processes.process=*user*) by Processes.dest Processes.user Processes.parent_process - Processes.process_name Processes.process Processes.process_id Processes.parent_process_id + as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="query.exe" OR Processes.original_file_name="query.exe") + AND Processes.process="*user*" AND ((NOT Processes.process="*/server*") OR Processes.process IN ("*/server:localhost*", "*/server:127.0.0.1*")) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `system_user_discovery_with_query_filter`' how_to_implement: The detection is based on data that originates from Endpoint Detection diff --git a/detections/endpoint/time_provider_persistence_registry.yml b/detections/endpoint/time_provider_persistence_registry.yml index 98a2391ac9..9ebc6d728f 100644 --- a/detections/endpoint/time_provider_persistence_registry.yml +++ b/detections/endpoint/time_provider_persistence_registry.yml @@ -1,7 +1,7 @@ name: Time Provider Persistence Registry id: 5ba382c4-2105-11ec-8d8f-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.003 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml b/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml index 669ef87e2e..03661c70d7 100644 --- a/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml +++ b/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml @@ -1,7 +1,7 @@ name: UAC Bypass MMC Load Unsigned Dll id: 7f04349c-e30d-11eb-bc7f-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -55,9 +55,8 @@ tags: - Windows Defense Evasion Tactics asset_type: Endpoint mitre_attack_id: - - T1548.002 - - T1548 - T1218.014 + - T1548.002 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/uac_bypass_with_colorui_com_object.yml b/detections/endpoint/uac_bypass_with_colorui_com_object.yml index c93938fb95..3b5ec1cdb6 100644 --- a/detections/endpoint/uac_bypass_with_colorui_com_object.yml +++ b/detections/endpoint/uac_bypass_with_colorui_com_object.yml @@ -1,7 +1,7 @@ name: UAC Bypass With Colorui COM Object id: 2bcccd20-fc2b-11eb-8d22-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -54,7 +54,6 @@ tags: - LockBit Ransomware asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.003 product: - Splunk Enterprise diff --git a/detections/endpoint/uninstall_app_using_msiexec.yml b/detections/endpoint/uninstall_app_using_msiexec.yml index 95e609aade..06248d5f3b 100644 --- a/detections/endpoint/uninstall_app_using_msiexec.yml +++ b/detections/endpoint/uninstall_app_using_msiexec.yml @@ -1,7 +1,7 @@ name: Uninstall App Using MsiExec id: 1fca2b28-f922-11eb-b2dd-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.007 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/unload_sysmon_filter_driver.yml b/detections/endpoint/unload_sysmon_filter_driver.yml index 93302c30ba..74f3715365 100644 --- a/detections/endpoint/unload_sysmon_filter_driver.yml +++ b/detections/endpoint/unload_sysmon_filter_driver.yml @@ -1,7 +1,7 @@ name: Unload Sysmon Filter Driver id: e5928ff3-23eb-4d8b-b8a4-dcbc844fdfbe -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/unloading_amsi_via_reflection.yml b/detections/endpoint/unloading_amsi_via_reflection.yml index 3fba97f093..63a2cee57d 100644 --- a/detections/endpoint/unloading_amsi_via_reflection.yml +++ b/detections/endpoint/unloading_amsi_via_reflection.yml @@ -1,7 +1,7 @@ name: Unloading AMSI via Reflection id: a21e3484-c94d-11eb-b55b-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -57,9 +57,8 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1562 - T1059.001 - - T1059 + - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/unusual_number_of_kerberos_service_tickets_requested.yml b/detections/endpoint/unusual_number_of_kerberos_service_tickets_requested.yml index 7735319ec4..58affd514e 100644 --- a/detections/endpoint/unusual_number_of_kerberos_service_tickets_requested.yml +++ b/detections/endpoint/unusual_number_of_kerberos_service_tickets_requested.yml @@ -1,7 +1,7 @@ name: Unusual Number of Kerberos Service Tickets Requested id: eb3e6702-8936-11ec-98fe-acde48001122 -version: 6 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Dean Luxton, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: - Active Directory Kerberos Attacks asset_type: Endpoint mitre_attack_id: - - T1558 - T1558.003 product: - Splunk Enterprise diff --git a/detections/endpoint/vbscript_execution_using_wscript_app.yml b/detections/endpoint/vbscript_execution_using_wscript_app.yml index e9fd89ca8c..a7a87ba473 100644 --- a/detections/endpoint/vbscript_execution_using_wscript_app.yml +++ b/detections/endpoint/vbscript_execution_using_wscript_app.yml @@ -1,7 +1,7 @@ name: Vbscript Execution Using Wscript App id: 35159940-228f-11ec-8a49-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.005 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/verclsid_clsid_execution.yml b/detections/endpoint/verclsid_clsid_execution.yml index fa5b44a719..f45344915b 100644 --- a/detections/endpoint/verclsid_clsid_execution.yml +++ b/detections/endpoint/verclsid_clsid_execution.yml @@ -1,7 +1,7 @@ name: Verclsid CLSID Execution id: 61e9a56a-20fa-11ec-8ba3-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -45,7 +45,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.012 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/w3wp_spawning_shell.yml b/detections/endpoint/w3wp_spawning_shell.yml index 30d7cd3caa..21d2e3fb4f 100644 --- a/detections/endpoint/w3wp_spawning_shell.yml +++ b/detections/endpoint/w3wp_spawning_shell.yml @@ -1,7 +1,7 @@ name: W3WP Spawning Shell id: 0f03423c-7c6a-11eb-bc47-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -79,7 +79,6 @@ tags: - CVE-2021-34523 - CVE-2021-31207 mitre_attack_id: - - T1505 - T1505.003 product: - Splunk Enterprise diff --git a/detections/endpoint/wbemprox_com_object_execution.yml b/detections/endpoint/wbemprox_com_object_execution.yml index 6e770d7563..3a63ebc37c 100644 --- a/detections/endpoint/wbemprox_com_object_execution.yml +++ b/detections/endpoint/wbemprox_com_object_execution.yml @@ -1,7 +1,7 @@ name: Wbemprox COM Object Execution id: 9d911ce0-c3be-11eb-b177-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - LockBit Ransomware asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.003 product: - Splunk Enterprise diff --git a/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml b/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml index fe60773917..5a0d5637a2 100644 --- a/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml +++ b/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml @@ -1,7 +1,7 @@ name: Wermgr Process Connecting To IP Check Web Services id: ed313326-a0f9-11eb-a89c-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: - Trickbot asset_type: Endpoint mitre_attack_id: - - T1590 - T1590.005 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml b/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml index 9f00ab5ca2..66a85dd28f 100644 --- a/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml +++ b/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml @@ -1,7 +1,7 @@ name: Windows Access Token Manipulation SeDebugPrivilege id: 6ece9ed0-5f92-4315-889d-48560472b188 -version: 10 -date: '2025-01-27' +version: 11 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -70,7 +70,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1134.002 - - T1134 product: - Splunk Enterprise - Splunk Enterprise Security @@ -79,6 +78,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/brute_ratel/sedebugprivilege_token/security-xml.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/brute_ratel/sedebugprivilege_token/security-xml.log source: XmlWinEventLog:Security sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_access_token_manipulation_winlogon_duplicate_token_handle.yml b/detections/endpoint/windows_access_token_manipulation_winlogon_duplicate_token_handle.yml index 4dbd423a92..dd647d1112 100644 --- a/detections/endpoint/windows_access_token_manipulation_winlogon_duplicate_token_handle.yml +++ b/detections/endpoint/windows_access_token_manipulation_winlogon_duplicate_token_handle.yml @@ -1,7 +1,7 @@ name: Windows Access Token Manipulation Winlogon Duplicate Token Handle id: dda126d7-1d99-4f0b-b72a-4c14031f9398 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -35,7 +35,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1134.001 - - T1134 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_access_token_winlogon_duplicate_handle_in_uncommon_path.yml b/detections/endpoint/windows_access_token_winlogon_duplicate_handle_in_uncommon_path.yml index b3cc876fb9..662e51dcaf 100644 --- a/detections/endpoint/windows_access_token_winlogon_duplicate_handle_in_uncommon_path.yml +++ b/detections/endpoint/windows_access_token_winlogon_duplicate_handle_in_uncommon_path.yml @@ -1,7 +1,7 @@ name: Windows Access Token Winlogon Duplicate Handle In Uncommon Path id: b8f7ed6b-0556-4c84-bffd-839c262b0278 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1134.001 - - T1134 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_account_access_removal_via_logoff_exec.yml b/detections/endpoint/windows_account_access_removal_via_logoff_exec.yml index 709d34b600..efd6e3dd18 100644 --- a/detections/endpoint/windows_account_access_removal_via_logoff_exec.yml +++ b/detections/endpoint/windows_account_access_removal_via_logoff_exec.yml @@ -1,21 +1,27 @@ name: Windows Account Access Removal via Logoff Exec id: 223572ab-8768-4e20-9b39-c38707af80dc -version: 1 -date: '2024-12-17' +version: 2 +date: '2025-02-10' author: Teoderick Contreras, Splunk data_source: - Sysmon EventID 1 type: Anomaly status: production -description: The following analytic detects the process of logging off a user through the use of the quser and logoff commands. By monitoring for these commands, the analytic identifies actions where a user session is forcibly terminated, which could be part of an administrative task or a potentially unauthorized access attempt. This detection helps identify potential misuse or malicious activity where a user’s access is revoked without proper authorization, providing insight into potential security incidents involving account management or session manipulation. -search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes - where Processes.process_name = logoff.exe - by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_guid Processes.dest Processes.user - | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `windows_account_access_removal_via_logoff_exec_filter`' -how_to_implement: The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. +description: The following analytic detects the process of logging off a user through + the use of the quser and logoff commands. By monitoring for these commands, the + analytic identifies actions where a user session is forcibly terminated, which could + be part of an administrative task or a potentially unauthorized access attempt. + This detection helps identify potential misuse or malicious activity where a user’s + access is revoked without proper authorization, providing insight into potential + security incidents involving account management or session manipulation. +search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.process_name = logoff.exe + by Processes.parent_process_name Processes.parent_process Processes.process_name + Processes.process Processes.process_guid Processes.dest Processes.user | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_account_access_removal_via_logoff_exec_filter`' +how_to_implement: The following Hunting analytic requires PowerShell operational logs + to be imported. Modify the powershell macro as needed to match the sourcetype or + add index. This analytic is specific to 4104, or PowerShell Script Block Logging. known_false_positives: Administrators or power users may use this command. references: - https://devblogs.microsoft.com/scripting/automating-quser-through-powershell/ @@ -25,7 +31,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -43,9 +54,8 @@ tags: - Crypto Stealer asset_type: Endpoint mitre_attack_id: - - T1531 - T1059.001 - - T1059 + - T1531 product: - Splunk Enterprise - Splunk Enterprise Security @@ -54,6 +64,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/powershell_log_process_tree/powershell_logoff.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/powershell_log_process_tree/powershell_logoff.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_account_discovery_for_none_disable_user_account.yml b/detections/endpoint/windows_account_discovery_for_none_disable_user_account.yml index 501c9abd55..7ddbfdb697 100644 --- a/detections/endpoint/windows_account_discovery_for_none_disable_user_account.yml +++ b/detections/endpoint/windows_account_discovery_for_none_disable_user_account.yml @@ -1,7 +1,7 @@ name: Windows Account Discovery for None Disable User Account id: eddbf5ba-b89e-47ca-995e-2d259804e55e -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -35,7 +35,6 @@ tags: - CISA AA23-347A asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.001 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_ad_abnormal_object_access_activity.yml b/detections/endpoint/windows_ad_abnormal_object_access_activity.yml index d950358d37..30e8c78866 100644 --- a/detections/endpoint/windows_ad_abnormal_object_access_activity.yml +++ b/detections/endpoint/windows_ad_abnormal_object_access_activity.yml @@ -1,7 +1,7 @@ name: Windows AD Abnormal Object Access Activity id: 71b289db-5f2c-4c43-8256-8bf26ae7324a -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Steven Dick status: production type: Anomaly @@ -60,7 +60,6 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml b/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml index 9b011c912c..87740e631d 100644 --- a/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml +++ b/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml @@ -1,6 +1,6 @@ name: Windows AD AdminSDHolder ACL Modified id: 00d877c3-7b7b-443d-9562-6b231e2abab9 -version: 5 +version: 6 date: '2024-11-13' author: Mauricio Velazco, Dean Luxton, Splunk type: TTP diff --git a/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml b/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml index 1a951ffa45..79de518830 100644 --- a/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml +++ b/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml @@ -1,7 +1,7 @@ name: Windows AD Cross Domain SID History Addition id: 41bbb371-28ba-439c-bb5c-d9930c28365d -version: 5 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Dean Luxton type: TTP status: production @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1134.005 - - T1134 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_ad_domain_replication_acl_addition.yml b/detections/endpoint/windows_ad_domain_replication_acl_addition.yml index 5afac44a1b..a303064df9 100644 --- a/detections/endpoint/windows_ad_domain_replication_acl_addition.yml +++ b/detections/endpoint/windows_ad_domain_replication_acl_addition.yml @@ -1,6 +1,6 @@ name: Windows AD Domain Replication ACL Addition id: 8c372853-f459-4995-afdc-280c114d33ab -version: 7 +version: 8 date: '2024-12-10' author: Dean Luxton type: TTP diff --git a/detections/endpoint/windows_ad_privileged_account_sid_history_addition.yml b/detections/endpoint/windows_ad_privileged_account_sid_history_addition.yml index b27e21cabe..c41aece18f 100644 --- a/detections/endpoint/windows_ad_privileged_account_sid_history_addition.yml +++ b/detections/endpoint/windows_ad_privileged_account_sid_history_addition.yml @@ -1,7 +1,7 @@ name: Windows AD Privileged Account SID History Addition id: 6b521149-b91c-43aa-ba97-c2cac59ec830 -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Dean Luxton type: TTP status: production @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1134.005 - - T1134 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_ad_privileged_object_access_activity.yml b/detections/endpoint/windows_ad_privileged_object_access_activity.yml index 022e799c23..505c7fd59b 100644 --- a/detections/endpoint/windows_ad_privileged_object_access_activity.yml +++ b/detections/endpoint/windows_ad_privileged_object_access_activity.yml @@ -1,7 +1,7 @@ name: Windows AD Privileged Object Access Activity id: dc2f58bc-8cd2-4e51-962a-694b963acde0 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -64,7 +64,6 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_ad_replication_request_initiated_by_user_account.yml b/detections/endpoint/windows_ad_replication_request_initiated_by_user_account.yml index 559582d368..942a561d39 100644 --- a/detections/endpoint/windows_ad_replication_request_initiated_by_user_account.yml +++ b/detections/endpoint/windows_ad_replication_request_initiated_by_user_account.yml @@ -1,7 +1,7 @@ name: Windows AD Replication Request Initiated by User Account id: 51307514-1236-49f6-8686-d46d93cc2821 -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Dean Luxton type: TTP status: production @@ -73,7 +73,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.006 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml b/detections/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml index 1d6a7be15c..7ec27540f3 100644 --- a/detections/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml +++ b/detections/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml @@ -1,7 +1,7 @@ name: Windows AD Replication Request Initiated from Unsanctioned Location id: 50998483-bb15-457b-a870-965080d9e3d3 -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Dean Luxton type: TTP status: production @@ -77,7 +77,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.006 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml b/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml index 00764a6d79..06ebf8cd4c 100644 --- a/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml +++ b/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml @@ -1,7 +1,7 @@ name: Windows AD Same Domain SID History Addition id: 5fde0b7c-df7a-40b1-9b3a-294c00f0289d -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Dean Luxton type: TTP status: production @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1134.005 - - T1134 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_ad_sid_history_attribute_modified.yml b/detections/endpoint/windows_ad_sid_history_attribute_modified.yml index 55ba1e1045..65a1e2eedf 100644 --- a/detections/endpoint/windows_ad_sid_history_attribute_modified.yml +++ b/detections/endpoint/windows_ad_sid_history_attribute_modified.yml @@ -1,7 +1,7 @@ name: Windows AD SID History Attribute Modified id: 1155e47d-307f-4247-beab-71071e3a458c -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk type: TTP status: production @@ -56,7 +56,6 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1134 - T1134.005 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_admon_default_group_policy_object_modified.yml b/detections/endpoint/windows_admon_default_group_policy_object_modified.yml index dba80bbc1b..4194594106 100644 --- a/detections/endpoint/windows_admon_default_group_policy_object_modified.yml +++ b/detections/endpoint/windows_admon_default_group_policy_object_modified.yml @@ -1,7 +1,7 @@ name: Windows Admon Default Group Policy Object Modified id: 83458004-db60-4170-857d-8572f16f070b -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - T1484.001 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_admon_group_policy_object_created.yml b/detections/endpoint/windows_admon_group_policy_object_created.yml index 83a1435afa..88224156c8 100644 --- a/detections/endpoint/windows_admon_group_policy_object_created.yml +++ b/detections/endpoint/windows_admon_group_policy_object_created.yml @@ -1,7 +1,7 @@ name: Windows Admon Group Policy Object Created id: 69201633-30d9-48ef-b1b6-e680805f0582 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - T1484.001 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_alternate_datastream___base64_content.yml b/detections/endpoint/windows_alternate_datastream___base64_content.yml index 7a95b21409..ecd4e049de 100644 --- a/detections/endpoint/windows_alternate_datastream___base64_content.yml +++ b/detections/endpoint/windows_alternate_datastream___base64_content.yml @@ -1,7 +1,7 @@ name: Windows Alternate DataStream - Base64 Content id: 683f48de-982f-4a7e-9aac-9cec550da498 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Steven Dick, Teoderick Contreras, Michael Haag, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: - Windows Defense Evasion Tactics asset_type: Endpoint mitre_attack_id: - - T1564 - T1564.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_alternate_datastream___executable_content.yml b/detections/endpoint/windows_alternate_datastream___executable_content.yml index 9ff5c8ee67..b60c3f31df 100644 --- a/detections/endpoint/windows_alternate_datastream___executable_content.yml +++ b/detections/endpoint/windows_alternate_datastream___executable_content.yml @@ -1,7 +1,7 @@ name: Windows Alternate DataStream - Executable Content id: a258bf2a-34fd-4986-8086-78f506e00206 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Steven Dick, Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - Windows Defense Evasion Tactics asset_type: Endpoint mitre_attack_id: - - T1564 - T1564.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_alternate_datastream___process_execution.yml b/detections/endpoint/windows_alternate_datastream___process_execution.yml index 3e11a4fef5..8f69a19e36 100644 --- a/detections/endpoint/windows_alternate_datastream___process_execution.yml +++ b/detections/endpoint/windows_alternate_datastream___process_execution.yml @@ -1,7 +1,7 @@ name: Windows Alternate DataStream - Process Execution id: 30c32c5c-41fe-45db-84fe-275e4320da3f -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -65,7 +65,6 @@ tags: - Windows Defense Evasion Tactics asset_type: Endpoint mitre_attack_id: - - T1564 - T1564.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_apache_benchmark_binary.yml b/detections/endpoint/windows_apache_benchmark_binary.yml index 17a494d0c6..ecbb29f74e 100644 --- a/detections/endpoint/windows_apache_benchmark_binary.yml +++ b/detections/endpoint/windows_apache_benchmark_binary.yml @@ -1,6 +1,6 @@ name: Windows Apache Benchmark Binary id: 894f48ea-8d85-4dcd-9132-c66cdb407c9b -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_archive_collected_data_via_rar.yml b/detections/endpoint/windows_archive_collected_data_via_rar.yml index d3403433b5..7a1bc686a4 100644 --- a/detections/endpoint/windows_archive_collected_data_via_rar.yml +++ b/detections/endpoint/windows_archive_collected_data_via_rar.yml @@ -1,7 +1,7 @@ name: Windows Archive Collected Data via Rar id: 2015de95-fe91-413d-9d62-2fe011b67e82 -version: 5 -date: '2025-01-27' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1560.001 - - T1560 product: - Splunk Enterprise - Splunk Enterprise Security @@ -76,6 +75,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility_darkgate/rar_sys.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility_darkgate/rar_sys.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_attempt_to_stop_security_service.yml b/detections/endpoint/windows_attempt_to_stop_security_service.yml index 44e85bbc42..79ccda8ff8 100644 --- a/detections/endpoint/windows_attempt_to_stop_security_service.yml +++ b/detections/endpoint/windows_attempt_to_stop_security_service.yml @@ -1,18 +1,42 @@ name: Windows Attempt To Stop Security Service id: 9ed27cea-4e27-4eff-b2c6-aac9e78a7517 -version: 1 -date: '2025-01-13' +version: 3 +date: '2025-02-10' author: Rico Valdez, Nasreddine Bencherchali, Splunk status: production type: TTP -description: The following analytic detects attempts to stop security-related services on an endpoint, which may indicate malicious activity. It leverages data from Endpoint Detection and Response (EDR) agents, specifically searching for processes involving the "sc.exe" or "net.exe" command with the "stop" parameter or the PowerShell "Stop-Service" cmdlet. This activity is significant because disabling security services can undermine the organization's security posture, potentially leading to unauthorized access, data exfiltration, or further attacks like malware installation or privilege escalation. If confirmed malicious, this behavior could compromise the endpoint and the entire network, necessitating immediate investigation and response. +description: The following analytic detects attempts to stop security-related services + on an endpoint, which may indicate malicious activity. It leverages data from Endpoint + Detection and Response (EDR) agents, specifically searching for processes involving + the "sc.exe" or "net.exe" command with the "stop" parameter or the PowerShell "Stop-Service" + cmdlet. This activity is significant because disabling security services can undermine + the organization's security posture, potentially leading to unauthorized access, + data exfiltration, or further attacks like malware installation or privilege escalation. + If confirmed malicious, this behavior could compromise the endpoint and the entire + network, necessitating immediate investigation and response. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where ((`process_net` OR `process_sc`) Processes.process="* stop *") OR Processes.process="*Stop-Service *" by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |lookup security_services_lookup service as process OUTPUTNEW category, description | search category=security | `windows_attempt_to_stop_security_service_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: None identified. Attempts to disable security-related services should be identified and understood. +search: '| tstats `security_content_summariesonly` values(Processes.process) as process + min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where ((`process_net` OR `process_sc`) Processes.process="* stop *") OR Processes.process="*Stop-Service + *" by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name + Processes.process_name Processes.original_file_name Processes.process Processes.process_id + Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` |lookup security_services_lookup service as + process OUTPUTNEW category, description | search category=security | `windows_attempt_to_stop_security_service_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. +known_false_positives: None identified. Attempts to disable security-related services + should be identified and understood. references: - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-14---disable-arbitrary-security-windows-service - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ @@ -22,7 +46,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$user$" and "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", + "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) + as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk + Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -51,7 +80,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security @@ -60,6 +88,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_defend_service_stop/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_defend_service_stop/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_autoit3_execution.yml b/detections/endpoint/windows_autoit3_execution.yml index 27d70e95ba..e6ddf3ce77 100644 --- a/detections/endpoint/windows_autoit3_execution.yml +++ b/detections/endpoint/windows_autoit3_execution.yml @@ -1,6 +1,6 @@ name: Windows AutoIt3 Execution id: 0ecb40d9-492b-4a57-9f87-515dd742794c -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml b/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml index a14fab9b60..873c2df5da 100644 --- a/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml +++ b/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml @@ -1,7 +1,7 @@ name: Windows Binary Proxy Execution Mavinject DLL Injection id: ccf4b61b-1b26-4f2e-a089-f2009c569c57 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.013 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_bitlockertogo_process_execution.yml b/detections/endpoint/windows_bitlockertogo_process_execution.yml index a6607a72a8..ac6f6b6ac4 100644 --- a/detections/endpoint/windows_bitlockertogo_process_execution.yml +++ b/detections/endpoint/windows_bitlockertogo_process_execution.yml @@ -1,10 +1,10 @@ name: Windows BitLockerToGo Process Execution id: 68cbc9e9-2882-46f2-b636-3b5080589d58 -version: 2 +version: 3 date: '2025-01-21' author: Michael Haag, Nasreddine Bencherchali, Splunk data_source: -- Sysmon Event ID 1 +- Sysmon EventID 1 - Windows Event Log Security 4688 type: Hunting status: production diff --git a/detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml b/detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml index 974d986e9f..9a96351ff5 100644 --- a/detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml +++ b/detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml @@ -1,7 +1,7 @@ name: Windows Boot or Logon Autostart Execution In Startup Folder id: 99d157cb-923f-4a00-aee9-1f385412146f -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.001 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_bootloader_inventory.yml b/detections/endpoint/windows_bootloader_inventory.yml index 375c844994..7346f0b9f4 100644 --- a/detections/endpoint/windows_bootloader_inventory.yml +++ b/detections/endpoint/windows_bootloader_inventory.yml @@ -1,7 +1,7 @@ name: Windows BootLoader Inventory id: 4f7e3913-4db3-4ccd-afe4-31198982305d -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: experimental type: Hunting @@ -33,7 +33,6 @@ tags: atomic_guid: [] mitre_attack_id: - T1542.001 - - T1542 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_cached_domain_credentials_reg_query.yml b/detections/endpoint/windows_cached_domain_credentials_reg_query.yml index b0cf4007cc..3b9b8d4394 100644 --- a/detections/endpoint/windows_cached_domain_credentials_reg_query.yml +++ b/detections/endpoint/windows_cached_domain_credentials_reg_query.yml @@ -1,7 +1,7 @@ name: Windows Cached Domain Credentials Reg Query id: 40ccb8e0-1785-466e-901e-6a8b75c04ecd -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.005 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_certutil_download_with_url_argument.yml b/detections/endpoint/windows_certutil_download_with_url_argument.yml index e7ac8ebf6c..87ff45c03c 100644 --- a/detections/endpoint/windows_certutil_download_with_url_argument.yml +++ b/detections/endpoint/windows_certutil_download_with_url_argument.yml @@ -1,6 +1,6 @@ name: Windows CertUtil Download With URL Argument id: 4fc5ca00-4c7c-46b3-8772-c98a4b8bd944 -version: 2 +version: 3 date: '2025-01-07' author: Nasreddine Bencherchali, Splunk status: production diff --git a/detections/endpoint/windows_change_default_file_association_for_no_file_ext.yml b/detections/endpoint/windows_change_default_file_association_for_no_file_ext.yml index 36f61bdd44..161c19a39e 100644 --- a/detections/endpoint/windows_change_default_file_association_for_no_file_ext.yml +++ b/detections/endpoint/windows_change_default_file_association_for_no_file_ext.yml @@ -1,7 +1,7 @@ name: Windows Change Default File Association For No File Ext id: dbdf52ad-d6a1-4b68-975f-0a10939d8e38 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.001 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_cmdline_tool_execution_from_non_shell_process.yml b/detections/endpoint/windows_cmdline_tool_execution_from_non_shell_process.yml index 76789b01ac..ea35cf83bc 100644 --- a/detections/endpoint/windows_cmdline_tool_execution_from_non_shell_process.yml +++ b/detections/endpoint/windows_cmdline_tool_execution_from_non_shell_process.yml @@ -1,18 +1,42 @@ name: Windows Cmdline Tool Execution From Non-Shell Process id: 2afa393f-b88d-41b7-9793-623c93a2dfde -version: 1 -date: '2025-01-13' +version: 3 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly -description: The following analytic identifies instances where `ipconfig.exe`, `systeminfo.exe`, or similar tools are executed by a non-standard shell parent process, excluding CMD, PowerShell, or Explorer. This detection leverages Endpoint Detection and Response (EDR) telemetry to monitor process creation events. Such behavior is significant as it may indicate adversaries using injected processes to perform system discovery, a tactic observed in FIN7's JSSLoader. If confirmed malicious, this activity could allow attackers to gather critical host information, aiding in further exploitation or lateral movement within the network. +description: The following analytic identifies instances where `ipconfig.exe`, `systeminfo.exe`, + or similar tools are executed by a non-standard shell parent process, excluding + CMD, PowerShell, or Explorer. This detection leverages Endpoint Detection and Response + (EDR) telemetry to monitor process creation events. Such behavior is significant + as it may indicate adversaries using injected processes to perform system discovery, + a tactic observed in FIN7's JSSLoader. If confirmed malicious, this activity could + allow attackers to gather critical host information, aiding in further exploitation + or lateral movement within the network. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN ("ipconfig.exe", "systeminfo.exe", "net1.exe", "arp.exe", "nslookup.exe", "route.exe", "netstat.exe", "whoami.exe") AND NOT Processes.parent_process_name IN ("cmd.exe", "powershell.exe", "powershell_ise.exe", "pwsh.exe", "explorer.exe", "-", "unknown") by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.original_file_name Processes.process_id Processes.process Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_cmdline_tool_execution_from_non_shell_process_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: A network operator or systems administrator may utilize an automated host discovery application that may generate false positives. Filter as needed. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN ("ipconfig.exe", + "systeminfo.exe", "net1.exe", "arp.exe", "nslookup.exe", "route.exe", "netstat.exe", + "whoami.exe") AND NOT Processes.parent_process_name IN ("cmd.exe", "powershell.exe", + "powershell_ise.exe", "pwsh.exe", "explorer.exe", "-", "unknown") by Processes.parent_process_name + Processes.parent_process Processes.process_name Processes.original_file_name Processes.process_id + Processes.process Processes.dest Processes.user | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_cmdline_tool_execution_from_non_shell_process_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. +known_false_positives: A network operator or systems administrator may utilize an + automated host discovery application that may generate false positives. Filter as + needed. references: - https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation - https://attack.mitre.org/groups/G0046/ @@ -23,7 +47,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" and "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", + "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) + as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk + Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -53,7 +82,6 @@ tags: - Gozi Malware asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.007 product: - Splunk Enterprise @@ -63,6 +91,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/jssloader/sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/jssloader/sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml b/detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml index 80717d56c4..0e083199b3 100644 --- a/detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml +++ b/detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml @@ -1,7 +1,7 @@ name: Windows COM Hijacking InprocServer32 Modification id: b7bd83c0-92b5-4fc7-b286-23eccfa2c561 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.015 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml b/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml index 68a89ff942..749ef2a798 100644 --- a/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml +++ b/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml @@ -1,7 +1,7 @@ name: Windows Command Shell DCRat ForkBomb Payload id: 2bb1a362-7aa8-444a-92ed-1987e8da83e1 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.003 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_create_local_account.yml b/detections/endpoint/windows_create_local_account.yml index 91781c15e8..f6cc478ad7 100644 --- a/detections/endpoint/windows_create_local_account.yml +++ b/detections/endpoint/windows_create_local_account.yml @@ -1,7 +1,7 @@ name: Windows Create Local Account id: 3fb2e8e3-7bc0-4567-9722-c5ab9f8595eb -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1136.001 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_create_local_administrator_account_via_net.yml b/detections/endpoint/windows_create_local_administrator_account_via_net.yml index 518245a6d4..c555bb46ba 100644 --- a/detections/endpoint/windows_create_local_administrator_account_via_net.yml +++ b/detections/endpoint/windows_create_local_administrator_account_via_net.yml @@ -1,17 +1,40 @@ name: Windows Create Local Administrator Account Via Net id: 2c568c34-bb57-4b43-9d75-19c605b98e70 -version: 1 -date: '2025-01-13' +version: 3 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: Anomaly -description: The following analytic detects the creation of a local administrator account using the "net.exe" command. It leverages Endpoint Detection and Response (EDR) data to identify processes named "net.exe" with the "/add" parameter and keywords related to administrator accounts. This activity is significant as it may indicate an attacker attempting to gain persistent access or escalate privileges. If confirmed malicious, this could lead to unauthorized access, data theft, or further system compromise. Review the process details, user context, and related artifacts to determine the legitimacy of the activity. +description: The following analytic detects the creation of a local administrator + account using the "net.exe" command. It leverages Endpoint Detection and Response + (EDR) data to identify processes named "net.exe" with the "/add" parameter and keywords + related to administrator accounts. This activity is significant as it may indicate + an attacker attempting to gain persistent access or escalate privileges. If confirmed + malicious, this could lead to unauthorized access, data theft, or further system + compromise. Review the process details, user context, and related artifacts to determine + the legitimacy of the activity. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count values(Processes.user) as user values(Processes.parent_process) as parent_process values(parent_process_name) as parent_process_name min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` AND Processes.process=*/add* AND Processes.process IN ("*administrators*", "*administratoren*", "*administrateurs*", "*administrador*", "*amministratori*", "*administratorer*", "*Rendszergazda*", "*Администратор*", "*Administratör*") by Processes.process Processes.process_name Processes.parent_process_name Processes.dest Processes.user| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_create_local_administrator_account_via_net_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +search: '| tstats `security_content_summariesonly` count values(Processes.user) as + user values(Processes.parent_process) as parent_process values(parent_process_name) + as parent_process_name min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where `process_net` AND Processes.process=*/add* AND Processes.process IN ("*administrators*", + "*administratoren*", "*administrateurs*", "*administrador*", "*amministratori*", + "*administratorer*", "*Rendszergazda*", "*Администратор*", "*Administratör*") by + Processes.process Processes.process_name Processes.parent_process_name Processes.dest + Processes.user| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `windows_create_local_administrator_account_via_net_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. known_false_positives: Administrators often leverage net.exe to create admin accounts. references: [] drilldown_searches: @@ -20,7 +43,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$user$" and "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", + "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) + as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk + Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -49,7 +77,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1136.001 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security @@ -58,6 +85,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_credential_dumping_lsass_memory_createdump.yml b/detections/endpoint/windows_credential_dumping_lsass_memory_createdump.yml index 1308709d7f..b33e006ced 100644 --- a/detections/endpoint/windows_credential_dumping_lsass_memory_createdump.yml +++ b/detections/endpoint/windows_credential_dumping_lsass_memory_createdump.yml @@ -1,6 +1,6 @@ name: Windows Credential Dumping LSASS Memory Createdump id: b3b7ce35-fce5-4c73-85f4-700aeada81a9 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_credentials_from_password_stores_chrome_copied_in_temp_dir.yml b/detections/endpoint/windows_credentials_from_password_stores_chrome_copied_in_temp_dir.yml index 25c6142e2f..862f0b722b 100644 --- a/detections/endpoint/windows_credentials_from_password_stores_chrome_copied_in_temp_dir.yml +++ b/detections/endpoint/windows_credentials_from_password_stores_chrome_copied_in_temp_dir.yml @@ -1,7 +1,7 @@ name: Windows Credentials from Password Stores Chrome Copied in TEMP Dir id: 4d14c86d-fdee-4393-94da-238d2706902f -version: 2 -date: '2024-11-13' +version: 3 +date: '2025-02-10' author: Teoderick Contreras, Splunk data_source: - Sysmon Event ID 11 @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1555.003 - - T1555 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_credentials_from_web_browsers_saved_in_temp_folder.yml b/detections/endpoint/windows_credentials_from_web_browsers_saved_in_temp_folder.yml index f597206fbb..468917413d 100644 --- a/detections/endpoint/windows_credentials_from_web_browsers_saved_in_temp_folder.yml +++ b/detections/endpoint/windows_credentials_from_web_browsers_saved_in_temp_folder.yml @@ -1,7 +1,7 @@ name: Windows Credentials from Web Browsers Saved in TEMP Folder id: b36b23ea-763c-417b-bd4a-6a378dabad1a -version: 2 -date: '2024-11-13' +version: 3 +date: '2025-02-10' author: Teoderick Contreras, Splunk data_source: - Sysmon Event ID 11 @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1555.003 - - T1555 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_credentials_in_registry_reg_query.yml b/detections/endpoint/windows_credentials_in_registry_reg_query.yml index 5465160a3a..c0718bc539 100644 --- a/detections/endpoint/windows_credentials_in_registry_reg_query.yml +++ b/detections/endpoint/windows_credentials_in_registry_reg_query.yml @@ -1,7 +1,7 @@ name: Windows Credentials in Registry Reg Query id: a8b3124e-2278-4b73-ae9c-585117079fb2 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.002 - - T1552 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_curl_download_to_suspicious_path.yml b/detections/endpoint/windows_curl_download_to_suspicious_path.yml index a267aa3e2f..fc5ad0009f 100644 --- a/detections/endpoint/windows_curl_download_to_suspicious_path.yml +++ b/detections/endpoint/windows_curl_download_to_suspicious_path.yml @@ -1,6 +1,6 @@ name: Windows Curl Download to Suspicious Path id: c32f091e-30db-11ec-8738-acde48001122 -version: 7 +version: 8 date: '2025-01-27' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_curl_upload_to_remote_destination.yml b/detections/endpoint/windows_curl_upload_to_remote_destination.yml index 0ebd3235eb..8b99b345c5 100644 --- a/detections/endpoint/windows_curl_upload_to_remote_destination.yml +++ b/detections/endpoint/windows_curl_upload_to_remote_destination.yml @@ -1,6 +1,6 @@ name: Windows Curl Upload to Remote Destination id: 42f8f1a2-4228-11ec-aade-acde48001122 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_default_group_policy_object_modified.yml b/detections/endpoint/windows_default_group_policy_object_modified.yml index 4955cf8b89..efebc1aedd 100644 --- a/detections/endpoint/windows_default_group_policy_object_modified.yml +++ b/detections/endpoint/windows_default_group_policy_object_modified.yml @@ -1,7 +1,7 @@ name: Windows Default Group Policy Object Modified id: fe6a6cc4-9e0d-4d66-bcf4-2c7f44860876 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - T1484.001 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_default_group_policy_object_modified_with_gpme.yml b/detections/endpoint/windows_default_group_policy_object_modified_with_gpme.yml index 6c21379d47..51664cc7ba 100644 --- a/detections/endpoint/windows_default_group_policy_object_modified_with_gpme.yml +++ b/detections/endpoint/windows_default_group_policy_object_modified_with_gpme.yml @@ -1,7 +1,7 @@ name: Windows Default Group Policy Object Modified with GPME id: eaf688b3-bb8f-454d-b105-920a862cd8cb -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - T1484.001 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_defender_exclusion_registry_entry.yml b/detections/endpoint/windows_defender_exclusion_registry_entry.yml index f097a09992..185bb0b799 100644 --- a/detections/endpoint/windows_defender_exclusion_registry_entry.yml +++ b/detections/endpoint/windows_defender_exclusion_registry_entry.yml @@ -1,7 +1,7 @@ name: Windows Defender Exclusion Registry Entry id: 13395a44-4dd9-11ec-9df7-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_delete_or_modify_system_firewall.yml b/detections/endpoint/windows_delete_or_modify_system_firewall.yml index bcb293d9d4..db9789944c 100644 --- a/detections/endpoint/windows_delete_or_modify_system_firewall.yml +++ b/detections/endpoint/windows_delete_or_modify_system_firewall.yml @@ -1,7 +1,7 @@ name: Windows Delete or Modify System Firewall id: b188d11a-eba7-419d-b8b6-cc265b4f2c4f -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -61,7 +61,6 @@ tags: - ShrinkLocker asset_type: Endpoint mitre_attack_id: - - T1562 - T1562.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_detect_network_scanner_behavior.yml b/detections/endpoint/windows_detect_network_scanner_behavior.yml index 7a05993d0d..0f75aeb776 100644 --- a/detections/endpoint/windows_detect_network_scanner_behavior.yml +++ b/detections/endpoint/windows_detect_network_scanner_behavior.yml @@ -1,63 +1,80 @@ -name: Windows Detect Network Scanner Behavior -id: 78e678d2-bf64-4fe6-aa52-2f7b11dddee7 -version: 2 -date: '2025-01-09' -author: Steven Dick -status: production -type: Anomaly -description: The following analytic detects when an application is used to connect a large number of unique ports/targets within a short time frame. Network enumeration may be used by adversaries as a method of discovery, lateral movement, or remote execution. This analytic may require significant tuning depending on the organization and applications being actively used, highly recommended to pre-populate the filter macro prior to activation. -data_source: -- Sysmon EventID 3 -search: '| tstats `security_content_summariesonly` count latest(All_Traffic.dest_port) as dest_port dc(All_Traffic.dest_port) as port_count dc(All_Traffic.dest) as dest_count min(_time) as firstTime max(_time) as lastTime values(All_Traffic.process_id) as process_id from datamodel=Network_Traffic.All_Traffic where sourcetype=XmlWinEventLog All_Traffic.app = "*\\*" All_Traffic.dest_port < 32000 NOT All_Traffic.dest_port IN (8443,8080,5353,3268,443,389,88,80,53,25) by host,All_Traffic.app,All_Traffic.src,All_Traffic.src_ip,All_Traffic.user _time span=5m -| `drop_dm_object_name(All_Traffic)` -| rex field=app ".*\\\(?.*)$" -| where port_count > 10 OR dest_count > 10 -| stats latest(src) as src, latest(src_ip) as src_ip, max(dest_count) as dest_count, max(port_count) as port_count, latest(dest_port) as dest_port, min(firstTime) as firstTime, max(lastTime) as lastTime, max(count) as count by host,user,app,process_name -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_detect_network_scanner_behavior_filter`' -how_to_implement: This detection relies on Sysmon EventID 3 events being ingested AND tagged into the Network_Traffic datamodel. -known_false_positives: Various, could be noisy depending on processes in the organization and sysmon configuration used. Adjusted port/dest count thresholds as needed. -references: -- https://attack.mitre.org/techniques/T1595 -drilldown_searches: -- name: View the detection results for - "$src$" and "$user$" - search: '%original_detection_search% | search src = "$src$" user = "$user$"' - earliest_offset: $info_min_time$ - latest_offset: $info_max_time$ -- name: View risk events for the last 7 days for - "$src$" and "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' - earliest_offset: $info_min_time$ - latest_offset: $info_max_time$ -rba: - message: A process exhibiting network scanning behavior [$process_name$] was detected on $src$ - risk_objects: - - field: src - type: system - score: 25 - - field: user - type: user - score: 25 - threat_objects: - - field: process_name - type: process_name -tags: - analytic_story: - - Network Discovery - - Windows Discovery Techniques - asset_type: Endpoint - mitre_attack_id: - - T1595 - - T1595.001 - - T1595.002 - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - security_domain: network -tests: -- name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1595/sysmon_scanning_events/sysmon_scanning_events.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog +name: Windows Detect Network Scanner Behavior +id: 78e678d2-bf64-4fe6-aa52-2f7b11dddee7 +version: 4 +date: '2025-02-10' +author: Steven Dick +status: production +type: Anomaly +description: The following analytic detects when an application is used to connect + a large number of unique ports/targets within a short time frame. Network enumeration + may be used by adversaries as a method of discovery, lateral movement, or remote + execution. This analytic may require significant tuning depending on the organization + and applications being actively used, highly recommended to pre-populate the filter + macro prior to activation. +data_source: +- Sysmon EventID 3 +search: '| tstats `security_content_summariesonly` count latest(All_Traffic.dest_port) + as dest_port dc(All_Traffic.dest_port) as port_count dc(All_Traffic.dest) as dest_count + min(_time) as firstTime max(_time) as lastTime values(All_Traffic.process_id) as + process_id from datamodel=Network_Traffic.All_Traffic where sourcetype=XmlWinEventLog + All_Traffic.app = "*\\*" All_Traffic.dest_port < 32000 NOT All_Traffic.dest_port + IN (8443,8080,5353,3268,443,389,88,80,53,25) by host,All_Traffic.app,All_Traffic.src,All_Traffic.src_ip,All_Traffic.user + _time span=5m | `drop_dm_object_name(All_Traffic)` | rex field=app ".*\\\(?.*)$" + | where port_count > 10 OR dest_count > 10 | stats latest(src) as src, latest(src_ip) + as src_ip, max(dest_count) as dest_count, max(port_count) as port_count, latest(dest_port) + as dest_port, min(firstTime) as firstTime, max(lastTime) as lastTime, max(count) + as count by host,user,app,process_name | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `windows_detect_network_scanner_behavior_filter`' +how_to_implement: This detection relies on Sysmon EventID 3 events being ingested + AND tagged into the Network_Traffic datamodel. +known_false_positives: Various, could be noisy depending on processes in the organization + and sysmon configuration used. Adjusted port/dest count thresholds as needed. +references: +- https://attack.mitre.org/techniques/T1595 +drilldown_searches: +- name: View the detection results for - "$src$" and "$user$" + search: '%original_detection_search% | search src = "$src$" user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$src$" and "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: A process exhibiting network scanning behavior [$process_name$] was detected + on $src$ + risk_objects: + - field: src + type: system + score: 25 + - field: user + type: user + score: 25 + threat_objects: + - field: process_name + type: process_name +tags: + analytic_story: + - Network Discovery + - Windows Discovery Techniques + asset_type: Endpoint + mitre_attack_id: + - T1595.001 + - T1595.002 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: network +tests: +- name: True Positive Test + attack_data: + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1595/sysmon_scanning_events/sysmon_scanning_events.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_disable_memory_crash_dump.yml b/detections/endpoint/windows_disable_memory_crash_dump.yml index c8c1b362d2..c53c115e73 100644 --- a/detections/endpoint/windows_disable_memory_crash_dump.yml +++ b/detections/endpoint/windows_disable_memory_crash_dump.yml @@ -1,6 +1,6 @@ name: Windows Disable Memory Crash Dump id: 59e54602-9680-11ec-a8a6-acde48001122 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml b/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml index b21faffa59..89f5df049c 100644 --- a/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml +++ b/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml @@ -1,7 +1,7 @@ name: Windows Disable or Modify Tools Via Taskkill id: a43ae66f-c410-4b3d-8741-9ce1ad17ddb0 -version: 6 -date: '2024-11-22' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: - Crypto Stealer asset_type: Endpoint mitre_attack_id: - - T1562 - T1562.001 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_disable_or_stop_browser_process.yml b/detections/endpoint/windows_disable_or_stop_browser_process.yml index 3c49e0a8d1..2447b0a67e 100644 --- a/detections/endpoint/windows_disable_or_stop_browser_process.yml +++ b/detections/endpoint/windows_disable_or_stop_browser_process.yml @@ -1,10 +1,10 @@ name: Windows Disable or Stop Browser Process id: 220d34b7-b6c7-45fe-8dbb-c35cdd9fe6d5 -version: 2 -date: '2024-11-13' +version: 3 +date: '2025-02-10' author: Teoderick Contreras, Splunk data_source: -- Sysmon Event ID 1 +- Sysmon EventID 1 type: TTP status: production description: The following analytic detects the use of the taskkill command in a process @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_disable_windows_event_logging_disable_http_logging.yml b/detections/endpoint/windows_disable_windows_event_logging_disable_http_logging.yml index 8419dcfa0e..05bec76722 100644 --- a/detections/endpoint/windows_disable_windows_event_logging_disable_http_logging.yml +++ b/detections/endpoint/windows_disable_windows_event_logging_disable_http_logging.yml @@ -1,7 +1,7 @@ name: Windows Disable Windows Event Logging Disable HTTP Logging id: 23fb6787-255f-4d5b-9a66-9fd7504032b5 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -77,10 +77,8 @@ tags: - Windows Defense Evasion Tactics asset_type: Endpoint mitre_attack_id: - - T1562.002 - - T1562 - - T1505 - T1505.004 + - T1562.002 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_disableantispyware_registry.yml b/detections/endpoint/windows_disableantispyware_registry.yml index 4395bd7e96..0dda67a09d 100644 --- a/detections/endpoint/windows_disableantispyware_registry.yml +++ b/detections/endpoint/windows_disableantispyware_registry.yml @@ -1,7 +1,7 @@ name: Windows DisableAntiSpyware Registry id: 23150a40-9301-4195-b802-5bb4f43067fb -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Rod Soto, Jose Hernandez, Michael Haag, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_dism_remove_defender.yml b/detections/endpoint/windows_dism_remove_defender.yml index 8a4786b5ea..8371b710fb 100644 --- a/detections/endpoint/windows_dism_remove_defender.yml +++ b/detections/endpoint/windows_dism_remove_defender.yml @@ -1,7 +1,7 @@ name: Windows DISM Remove Defender id: 8567da9e-47f0-11ec-99a9-acde48001122 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -74,7 +74,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml b/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml index 69a5506c40..709369aecf 100644 --- a/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml +++ b/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml @@ -1,7 +1,7 @@ name: Windows DLL Search Order Hijacking Hunt with Sysmon id: 79c7d1fc-64c7-91be-a616-ccda752efe81 -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -35,7 +35,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.001 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_dll_search_order_hijacking_with_iscsicpl.yml b/detections/endpoint/windows_dll_search_order_hijacking_with_iscsicpl.yml index 5ddb5d8355..d5d279ce64 100644 --- a/detections/endpoint/windows_dll_search_order_hijacking_with_iscsicpl.yml +++ b/detections/endpoint/windows_dll_search_order_hijacking_with_iscsicpl.yml @@ -1,6 +1,6 @@ name: Windows DLL Search Order Hijacking with iscsicpl id: f39ee679-3b1e-4f47-841c-5c3c580acda2 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_dll_side_loading_in_calc.yml b/detections/endpoint/windows_dll_side_loading_in_calc.yml index bbaa20e218..6e02110e63 100644 --- a/detections/endpoint/windows_dll_side_loading_in_calc.yml +++ b/detections/endpoint/windows_dll_side_loading_in_calc.yml @@ -1,7 +1,7 @@ name: Windows DLL Side-Loading In Calc id: af01f6db-26ac-440e-8d89-2793e303f137 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.002 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml b/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml index 1e661f00bf..3d856442b6 100644 --- a/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml +++ b/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml @@ -1,7 +1,7 @@ name: Windows DLL Side-Loading Process Child Of Calc id: 295ca9ed-e97b-4520-90f7-dfb6469902e1 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.002 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_dns_query_request_by_telegram_bot_api.yml b/detections/endpoint/windows_dns_query_request_by_telegram_bot_api.yml index 39e7c9496e..94664fd032 100644 --- a/detections/endpoint/windows_dns_query_request_by_telegram_bot_api.yml +++ b/detections/endpoint/windows_dns_query_request_by_telegram_bot_api.yml @@ -1,20 +1,27 @@ name: Windows DNS Query Request by Telegram Bot API id: 86f66f44-94d9-412d-a71d-5d8ed0fef72e -version: 1 -date: '2024-12-12' +version: 2 +date: '2025-02-10' author: Teoderick Contreras, Splunk data_source: - Sysmon EventID 22 type: Anomaly status: production -description: The following analytic detects the execution of a DNS query by a process to the associated Telegram API domain, which could indicate access via a Telegram bot commonly used by malware for command and control (C2) communications. By monitoring DNS queries related to Telegram's infrastructure, the detection identifies potential attempts to establish covert communication channels between a compromised system and external malicious actors. This behavior is often observed in cyberattacks where Telegram bots are used to receive commands or exfiltrate data, making it a key indicator of suspicious or malicious activity within a network. +description: The following analytic detects the execution of a DNS query by a process + to the associated Telegram API domain, which could indicate access via a Telegram + bot commonly used by malware for command and control (C2) communications. By monitoring + DNS queries related to Telegram's infrastructure, the detection identifies potential + attempts to establish covert communication channels between a compromised system + and external malicious actors. This behavior is often observed in cyberattacks where + Telegram bots are used to receive commands or exfiltrate data, making it a key indicator + of suspicious or malicious activity within a network. search: '`sysmon` EventCode=22 query = "api.telegram.org" process_name != "telegram.exe" - | stats count min(_time) as firstTime max(_time) as lastTime by query answer QueryResults QueryStatus process_name process_guid Computer - | rename Computer as dest - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `windows_dns_query_request_by_telegram_bot_api_filter`' -how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name and eventcode = 22 dnsquery executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + | stats count min(_time) as firstTime max(_time) as lastTime by query answer QueryResults + QueryStatus process_name process_guid Computer | rename Computer as dest | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `windows_dns_query_request_by_telegram_bot_api_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name and eventcode = 22 dnsquery executions from your endpoints. + If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. known_false_positives: a third part automation using telegram API. references: - https://www.splunk.com/en_us/blog/security/threat-advisory-telegram-crypto-botnet-strt-ta01.html @@ -24,7 +31,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -39,10 +51,8 @@ tags: - Crypto Stealer asset_type: Endpoint mitre_attack_id: - - T1102.002 - T1071.004 - - T1071 - - T1102 + - T1102.002 product: - Splunk Enterprise - Splunk Enterprise Security @@ -51,6 +61,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1102.002/telegram_api_dns/telegram_dns.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1102.002/telegram_api_dns/telegram_dns.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_domain_account_discovery_via_get_netcomputer.yml b/detections/endpoint/windows_domain_account_discovery_via_get_netcomputer.yml index eb09f87426..ad894aeeb8 100644 --- a/detections/endpoint/windows_domain_account_discovery_via_get_netcomputer.yml +++ b/detections/endpoint/windows_domain_account_discovery_via_get_netcomputer.yml @@ -1,7 +1,7 @@ name: Windows Domain Account Discovery Via Get-NetComputer id: a7fbbc4e-4571-424a-b627-6968e1c939e4 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -53,7 +53,6 @@ tags: - CISA AA23-347A asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml b/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml index a356cdce76..55465e1839 100644 --- a/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml +++ b/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml @@ -1,7 +1,7 @@ name: Windows DotNet Binary in Non Standard Path id: fddf3b56-7933-11ec-98a6-acde48001122 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -82,9 +82,7 @@ tags: - WhisperGate asset_type: Endpoint mitre_attack_id: - - T1036 - T1036.003 - - T1218 - T1218.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_driver_load_non_standard_path.yml b/detections/endpoint/windows_driver_load_non_standard_path.yml index bf5adb05b7..e36e98bcbd 100644 --- a/detections/endpoint/windows_driver_load_non_standard_path.yml +++ b/detections/endpoint/windows_driver_load_non_standard_path.yml @@ -1,7 +1,7 @@ name: Windows Driver Load Non-Standard Path id: 9216ef3d-066a-4958-8f27-c84589465e62 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-01-27' author: Michael Haag, Splunk status: production type: TTP @@ -17,7 +17,7 @@ data_source: - Windows Event Log System 7045 search: >- `wineventlog_system` EventCode=7045 ServiceType="kernel mode driver" - | regex ImagePath!="(?i)^(\w:\\\\Windows\\\\|\w:\\\\Program\sFile|\\\\systemroot\\\\|%SystemRoot%|system32\\\\)" + | regex ImagePath!="(?i)^(\w:\\\\Windows\\\\|\w:\\\\Program\sFile|\\\\systemroot\\\\|%SystemRoot%|system32\\\\|\\\\ProgramData\\\\Microsoft\\\\Windows\sDefender\\\\Definition\sUpdates\\\\)" | stats count min(_time) as firstTime max(_time) as lastTime by Computer EventCode ImagePath ServiceName ServiceType | rename Computer as dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_driver_load_non_standard_path_filter` diff --git a/detections/endpoint/windows_esx_admins_group_creation_via_net.yml b/detections/endpoint/windows_esx_admins_group_creation_via_net.yml index 0fecbadc81..373e172977 100644 --- a/detections/endpoint/windows_esx_admins_group_creation_via_net.yml +++ b/detections/endpoint/windows_esx_admins_group_creation_via_net.yml @@ -1,6 +1,6 @@ name: Windows ESX Admins Group Creation via Net id: 3d7df60b-3332-4667-8090-afe03e08dce0 -version: 4 +version: 5 date: '2025-01-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_esx_admins_group_creation_via_powershell.yml b/detections/endpoint/windows_esx_admins_group_creation_via_powershell.yml index 71b3808e94..fd301786bb 100644 --- a/detections/endpoint/windows_esx_admins_group_creation_via_powershell.yml +++ b/detections/endpoint/windows_esx_admins_group_creation_via_powershell.yml @@ -1,6 +1,6 @@ name: Windows ESX Admins Group Creation via PowerShell id: f48a5557-be06-4b96-b8e8-be563e387620 -version: 3 +version: 4 date: '2024-11-13' author: Michael Haag, Splunk data_source: diff --git a/detections/endpoint/windows_event_for_service_disabled.yml b/detections/endpoint/windows_event_for_service_disabled.yml index 070028f5ee..aef5a45b51 100644 --- a/detections/endpoint/windows_event_for_service_disabled.yml +++ b/detections/endpoint/windows_event_for_service_disabled.yml @@ -1,7 +1,7 @@ name: Windows Event For Service Disabled id: 9c2620a8-94a1-11ec-b40c-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -32,7 +32,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_event_log_cleared.yml b/detections/endpoint/windows_event_log_cleared.yml index 2bfd8a88e7..cff4ffa150 100644 --- a/detections/endpoint/windows_event_log_cleared.yml +++ b/detections/endpoint/windows_event_log_cleared.yml @@ -1,7 +1,7 @@ name: Windows Event Log Cleared id: ad517544-aff9-4c96-bd99-d6eb43bfbb6a -version: 12 -date: '2024-12-10' +version: 13 +date: '2025-02-10' author: Rico Valdez, Michael Haag, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Clop Ransomware asset_type: Endpoint mitre_attack_id: - - T1070 - T1070.001 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_excessive_disabled_services_event.yml b/detections/endpoint/windows_excessive_disabled_services_event.yml index 9f17eac2d5..047bd056e9 100644 --- a/detections/endpoint/windows_excessive_disabled_services_event.yml +++ b/detections/endpoint/windows_excessive_disabled_services_event.yml @@ -1,7 +1,7 @@ name: Windows Excessive Disabled Services Event id: c3f85976-94a5-11ec-9a58-acde48001122 -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_excessive_usage_of_net_app.yml b/detections/endpoint/windows_excessive_usage_of_net_app.yml index 68d8e0a30f..10716cc575 100644 --- a/detections/endpoint/windows_excessive_usage_of_net_app.yml +++ b/detections/endpoint/windows_excessive_usage_of_net_app.yml @@ -1,6 +1,6 @@ name: Windows Excessive Usage Of Net App id: 355ba810-0a20-4215-8485-9ce3f87f2e38 -version: 1 +version: 2 date: '2025-01-13' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml b/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml index 576e79a52b..abbcec0359 100644 --- a/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml +++ b/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml @@ -1,6 +1,6 @@ name: Windows Execute Arbitrary Commands with MSDT id: e1d5145f-38fe-42b9-a5d5-457796715f97 -version: 8 +version: 9 date: '2024-12-10' author: Michael Haag, Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/windows_export_certificate.yml b/detections/endpoint/windows_export_certificate.yml index bb27c581d8..745605dc64 100644 --- a/detections/endpoint/windows_export_certificate.yml +++ b/detections/endpoint/windows_export_certificate.yml @@ -1,7 +1,7 @@ name: Windows Export Certificate id: d8ddfa9b-b724-4df9-9dbe-f34cc0936714 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -51,7 +51,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.004 - - T1552 - T1649 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_file_transfer_protocol_in_non_common_process_path.yml b/detections/endpoint/windows_file_transfer_protocol_in_non_common_process_path.yml index 314c2ed9fd..cbe465f6fb 100644 --- a/detections/endpoint/windows_file_transfer_protocol_in_non_common_process_path.yml +++ b/detections/endpoint/windows_file_transfer_protocol_in_non_common_process_path.yml @@ -1,7 +1,7 @@ name: Windows File Transfer Protocol In Non-Common Process Path id: 0f43758f-1fe9-470a-a9e4-780acc4d5407 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1071.003 - - T1071 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_files_and_dirs_access_rights_modification_via_icacls.yml b/detections/endpoint/windows_files_and_dirs_access_rights_modification_via_icacls.yml index 6f4b92d1c5..356e3e7925 100644 --- a/detections/endpoint/windows_files_and_dirs_access_rights_modification_via_icacls.yml +++ b/detections/endpoint/windows_files_and_dirs_access_rights_modification_via_icacls.yml @@ -1,7 +1,7 @@ name: Windows Files and Dirs Access Rights Modification Via Icacls id: c76b796c-27e1-4520-91c4-4a58695c749e -version: 5 -date: '2024-12-16' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -72,7 +72,6 @@ tags: - 3309f53e-b22b-4eb6-8fd2-a6cf58b355a9 mitre_attack_id: - T1222.001 - - T1222 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml b/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml index 936ae3761c..dd165dc33e 100644 --- a/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml +++ b/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml @@ -1,7 +1,7 @@ name: Windows Find Domain Organizational Units with GetDomainOU id: 0ada2f82-b7af-40cc-b1d7-1e5985afcb4e -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Gowthamaraj Rajendran, Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml b/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml index e855820ea9..ffed352753 100644 --- a/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml +++ b/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml @@ -1,7 +1,7 @@ name: Windows Find Interesting ACL with FindInterestingDomainAcl id: e4a96dfd-667a-4487-b942-ccef5a1e81e8 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Gowthamaraj Rajendran, Mauricio Velazco, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_findstr_gpp_discovery.yml b/detections/endpoint/windows_findstr_gpp_discovery.yml index b141be9c81..2ce7f83865 100644 --- a/detections/endpoint/windows_findstr_gpp_discovery.yml +++ b/detections/endpoint/windows_findstr_gpp_discovery.yml @@ -1,7 +1,7 @@ name: Windows Findstr GPP Discovery id: 1631ac2d-f2a9-42fa-8a59-d6e210d472f5 -version: 4 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk type: TTP status: production @@ -70,7 +70,6 @@ tags: - Active Directory Privilege Escalation asset_type: Endpoint mitre_attack_id: - - T1552 - T1552.006 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml b/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml index aac21bf7bb..c8bcb30a51 100644 --- a/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml +++ b/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml @@ -1,7 +1,7 @@ name: Windows Forest Discovery with GetForestDomain id: a14803b2-4bd9-4c08-8b57-c37980edebe8 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Gowthamaraj Rajendran, Mauricio Velazco, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_gather_victim_host_information_camera.yml b/detections/endpoint/windows_gather_victim_host_information_camera.yml index 44ac29e470..9bf473e971 100644 --- a/detections/endpoint/windows_gather_victim_host_information_camera.yml +++ b/detections/endpoint/windows_gather_victim_host_information_camera.yml @@ -1,7 +1,7 @@ name: Windows Gather Victim Host Information Camera id: e4df4676-ea41-4397-b160-3ee0140dc332 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -59,7 +59,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1592.001 - - T1592 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_gather_victim_identity_sam_info.yml b/detections/endpoint/windows_gather_victim_identity_sam_info.yml index 58829b5f21..783965ba95 100644 --- a/detections/endpoint/windows_gather_victim_identity_sam_info.yml +++ b/detections/endpoint/windows_gather_victim_identity_sam_info.yml @@ -1,7 +1,7 @@ name: Windows Gather Victim Identity SAM Info id: a18e85d7-8b98-4399-820c-d46a1ca3516f -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -34,7 +34,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1589.001 - - T1589 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_gather_victim_network_info_through_ip_check_web_services.yml b/detections/endpoint/windows_gather_victim_network_info_through_ip_check_web_services.yml index 1f6f6dcc37..ddc18ae497 100644 --- a/detections/endpoint/windows_gather_victim_network_info_through_ip_check_web_services.yml +++ b/detections/endpoint/windows_gather_victim_network_info_through_ip_check_web_services.yml @@ -1,7 +1,7 @@ name: Windows Gather Victim Network Info Through Ip Check Web Services id: 70f7c952-0758-46d6-9148-d8969c4481d1 -version: 8 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -42,7 +42,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1590.005 - - T1590 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml b/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml index 8d7779ac20..79e2ef2681 100644 --- a/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml +++ b/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml @@ -1,7 +1,7 @@ name: Windows Get Local Admin with FindLocalAdminAccess id: d2988160-3ce9-4310-b59d-905334920cdd -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Gowthamaraj Rajendran, Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_group_discovery_via_net.yml b/detections/endpoint/windows_group_discovery_via_net.yml index b351dac9de..bd02d34030 100644 --- a/detections/endpoint/windows_group_discovery_via_net.yml +++ b/detections/endpoint/windows_group_discovery_via_net.yml @@ -1,17 +1,37 @@ name: Windows Group Discovery Via Net id: c5c8e0f3-147a-43da-bf04-4cfaec27dc44 -version: 1 -date: '2025-01-13' +version: 2 +date: '2025-02-10' author: Michael Haag, Mauricio Velazco, Splunk status: production type: Hunting -description: The following analytic identifies the execution of `net.exe` with command-line arguments used to query global, local and domain groups. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments. This activity is significant as it indicates potential reconnaissance efforts by adversaries to enumerate local or domain groups, which is a common step in Active Directory or privileged accounts discovery. If confirmed malicious, this behavior could allow attackers to gain insights into the domain structure, aiding in further attacks such as privilege escalation or lateral movement. +description: The following analytic identifies the execution of `net.exe` with command-line + arguments used to query global, local and domain groups. It leverages data from + Endpoint Detection and Response (EDR) agents, focusing on process names and command-line + arguments. This activity is significant as it indicates potential reconnaissance + efforts by adversaries to enumerate local or domain groups, which is a common step + in Active Directory or privileged accounts discovery. If confirmed malicious, this + behavior could allow attackers to gain insights into the domain structure, aiding + in further attacks such as privilege escalation or lateral movement. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` Processes.process="*group*" AND NOT (Processes.process="*/add" OR Processes.process="*/delete") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_group_discovery_via_net_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_net` Processes.process="*group*" + AND NOT (Processes.process="*/add" OR Processes.process="*/delete") by Processes.dest + Processes.user Processes.parent_process Processes.process_name Processes.process + Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_group_discovery_via_net_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. known_false_positives: Administrators or power users may use this command for troubleshooting. references: - https://attack.mitre.org/techniques/T1069/002/ @@ -33,7 +53,6 @@ tags: - Azorult asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.001 - T1069.002 product: @@ -44,11 +63,13 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog \ No newline at end of file + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_group_policy_object_created.yml b/detections/endpoint/windows_group_policy_object_created.yml index f3a08ffa82..bd4406e610 100644 --- a/detections/endpoint/windows_group_policy_object_created.yml +++ b/detections/endpoint/windows_group_policy_object_created.yml @@ -1,7 +1,7 @@ name: Windows Group Policy Object Created id: 23add2a8-ea22-4fd4-8bc0-8c0b822373a1 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco status: production type: TTP @@ -61,9 +61,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1484.001 - T1078.002 + - T1484.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_hijack_execution_flow_version_dll_side_load.yml b/detections/endpoint/windows_hijack_execution_flow_version_dll_side_load.yml index 392783e8d3..20958cf465 100644 --- a/detections/endpoint/windows_hijack_execution_flow_version_dll_side_load.yml +++ b/detections/endpoint/windows_hijack_execution_flow_version_dll_side_load.yml @@ -1,7 +1,7 @@ name: Windows Hijack Execution Flow Version Dll Side Load id: 8351340b-ac0e-41ec-8b07-dd01bf32d6ea -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -53,7 +53,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.001 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_http_network_communication_from_msiexec.yml b/detections/endpoint/windows_http_network_communication_from_msiexec.yml index 46426413d7..d312721aa7 100644 --- a/detections/endpoint/windows_http_network_communication_from_msiexec.yml +++ b/detections/endpoint/windows_http_network_communication_from_msiexec.yml @@ -1,6 +1,6 @@ name: Windows HTTP Network Communication From MSIExec id: b0fd38c7-f71a-43a2-870e-f3ca06bcdd99 -version: 1 +version: 2 date: '2025-01-17' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_hunting_system_account_targeting_lsass.yml b/detections/endpoint/windows_hunting_system_account_targeting_lsass.yml index 8dd3e10940..f839a81cb1 100644 --- a/detections/endpoint/windows_hunting_system_account_targeting_lsass.yml +++ b/detections/endpoint/windows_hunting_system_account_targeting_lsass.yml @@ -1,7 +1,7 @@ name: Windows Hunting System Account Targeting Lsass id: 1c6abb08-73d1-11ec-9ca0-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -38,7 +38,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_iis_components_add_new_module.yml b/detections/endpoint/windows_iis_components_add_new_module.yml index bd66a0d8fb..b8e4617559 100644 --- a/detections/endpoint/windows_iis_components_add_new_module.yml +++ b/detections/endpoint/windows_iis_components_add_new_module.yml @@ -1,7 +1,7 @@ name: Windows IIS Components Add New Module id: 38fe731c-1f13-43d4-b878-a5bbe44807e3 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -76,7 +76,6 @@ tags: - IIS Components asset_type: Endpoint mitre_attack_id: - - T1505 - T1505.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_iis_components_get_webglobalmodule_module_query.yml b/detections/endpoint/windows_iis_components_get_webglobalmodule_module_query.yml index 25f6016ba5..67cbd0e5c9 100644 --- a/detections/endpoint/windows_iis_components_get_webglobalmodule_module_query.yml +++ b/detections/endpoint/windows_iis_components_get_webglobalmodule_module_query.yml @@ -1,7 +1,7 @@ name: Windows IIS Components Get-WebGlobalModule Module Query id: 20db5f70-34b4-4e83-8926-fa26119de173 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -33,7 +33,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1505.004 - - T1505 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_iis_components_module_failed_to_load.yml b/detections/endpoint/windows_iis_components_module_failed_to_load.yml index cf09db6fe1..292c33dcc8 100644 --- a/detections/endpoint/windows_iis_components_module_failed_to_load.yml +++ b/detections/endpoint/windows_iis_components_module_failed_to_load.yml @@ -1,7 +1,7 @@ name: Windows IIS Components Module Failed to Load id: 40c2ba5b-dd6a-496b-9e6e-c9524d0be167 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: - IIS Components asset_type: Endpoint mitre_attack_id: - - T1505 - T1505.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_iis_components_new_module_added.yml b/detections/endpoint/windows_iis_components_new_module_added.yml index 6b24987b30..3042160dcc 100644 --- a/detections/endpoint/windows_iis_components_new_module_added.yml +++ b/detections/endpoint/windows_iis_components_new_module_added.yml @@ -1,7 +1,7 @@ name: Windows IIS Components New Module Added id: 55f22929-cfd3-4388-ba5c-4d01fac7ee7e -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: - IIS Components asset_type: Endpoint mitre_attack_id: - - T1505 - T1505.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml b/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml index 2bc0b705bb..9b97d2d1cf 100644 --- a/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml +++ b/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Add Xml Applocker Rules id: 467ed9d9-8035-470e-ad5e-ae5189283033 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -43,7 +43,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_change_win_defender_health_check_intervals.yml b/detections/endpoint/windows_impair_defense_change_win_defender_health_check_intervals.yml index 5ce4ca602b..01111a8dfa 100644 --- a/detections/endpoint/windows_impair_defense_change_win_defender_health_check_intervals.yml +++ b/detections/endpoint/windows_impair_defense_change_win_defender_health_check_intervals.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Change Win Defender Health Check Intervals id: 5211c260-820e-4366-b983-84bbfb5c263a -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_change_win_defender_quick_scan_interval.yml b/detections/endpoint/windows_impair_defense_change_win_defender_quick_scan_interval.yml index a04ac54542..9bd8d4dcd9 100644 --- a/detections/endpoint/windows_impair_defense_change_win_defender_quick_scan_interval.yml +++ b/detections/endpoint/windows_impair_defense_change_win_defender_quick_scan_interval.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Change Win Defender Quick Scan Interval id: 783f0798-f679-4c17-b3b3-187febf0b9b8 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_change_win_defender_throttle_rate.yml b/detections/endpoint/windows_impair_defense_change_win_defender_throttle_rate.yml index 0be8d9fe47..56fe8964d2 100644 --- a/detections/endpoint/windows_impair_defense_change_win_defender_throttle_rate.yml +++ b/detections/endpoint/windows_impair_defense_change_win_defender_throttle_rate.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Change Win Defender Throttle Rate id: f7da5fca-9261-43de-a4d0-130dad1e4f4d -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_change_win_defender_tracing_level.yml b/detections/endpoint/windows_impair_defense_change_win_defender_tracing_level.yml index a4a8c000b8..6f1170901c 100644 --- a/detections/endpoint/windows_impair_defense_change_win_defender_tracing_level.yml +++ b/detections/endpoint/windows_impair_defense_change_win_defender_tracing_level.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Change Win Defender Tracing Level id: fe9391cd-952a-4c64-8f56-727cb0d4f2d4 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_configure_app_install_control.yml b/detections/endpoint/windows_impair_defense_configure_app_install_control.yml index 4e1f435595..c8924b0876 100644 --- a/detections/endpoint/windows_impair_defense_configure_app_install_control.yml +++ b/detections/endpoint/windows_impair_defense_configure_app_install_control.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Configure App Install Control id: c54b7439-cfb1-44c3-bb35-b0409553077c -version: 5 -date: '2025-01-21' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_define_win_defender_threat_action.yml b/detections/endpoint/windows_impair_defense_define_win_defender_threat_action.yml index 29afaf77bb..997dcd5e85 100644 --- a/detections/endpoint/windows_impair_defense_define_win_defender_threat_action.yml +++ b/detections/endpoint/windows_impair_defense_define_win_defender_threat_action.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Define Win Defender Threat Action id: 7215831c-8252-4ae3-8d43-db588e82f952 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml b/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml index d8200b4cfd..a259c74bc3 100644 --- a/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml +++ b/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Delete Win Defender Context Menu id: 395ed5fe-ad13-4366-9405-a228427bdd91 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -39,7 +39,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml b/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml index e431440431..c47f826bdd 100644 --- a/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml +++ b/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Delete Win Defender Profile Registry id: 65d4b105-ec52-48ec-ac46-289d0fbf7d96 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml b/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml index 47a77e773c..a6c48f740b 100644 --- a/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml +++ b/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Deny Security Software With Applocker id: e0b6ca60-9e29-4450-b51a-bba0abae2313 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_controlled_folder_access.yml b/detections/endpoint/windows_impair_defense_disable_controlled_folder_access.yml index d6b1155f4e..8f40b00e62 100644 --- a/detections/endpoint/windows_impair_defense_disable_controlled_folder_access.yml +++ b/detections/endpoint/windows_impair_defense_disable_controlled_folder_access.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Controlled Folder Access id: 3032741c-d6fc-4c69-8988-be8043d6478c -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_defender_firewall_and_network.yml b/detections/endpoint/windows_impair_defense_disable_defender_firewall_and_network.yml index 17bd6686b7..9c02486387 100644 --- a/detections/endpoint/windows_impair_defense_disable_defender_firewall_and_network.yml +++ b/detections/endpoint/windows_impair_defense_disable_defender_firewall_and_network.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Defender Firewall And Network id: 8467d8cd-b0f9-46fa-ac84-a30ad138983e -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_defender_protocol_recognition.yml b/detections/endpoint/windows_impair_defense_disable_defender_protocol_recognition.yml index c9c51d2ebb..ae01a2aeff 100644 --- a/detections/endpoint/windows_impair_defense_disable_defender_protocol_recognition.yml +++ b/detections/endpoint/windows_impair_defense_disable_defender_protocol_recognition.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Defender Protocol Recognition id: b2215bfb-6171-4137-af17-1a02fdd8d043 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_pua_protection.yml b/detections/endpoint/windows_impair_defense_disable_pua_protection.yml index 0ec711df2b..9727759c6f 100644 --- a/detections/endpoint/windows_impair_defense_disable_pua_protection.yml +++ b/detections/endpoint/windows_impair_defense_disable_pua_protection.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable PUA Protection id: fbfef407-cfee-4866-88c1-f8de1c16147c -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_realtime_signature_delivery.yml b/detections/endpoint/windows_impair_defense_disable_realtime_signature_delivery.yml index 0516b79f28..a609983158 100644 --- a/detections/endpoint/windows_impair_defense_disable_realtime_signature_delivery.yml +++ b/detections/endpoint/windows_impair_defense_disable_realtime_signature_delivery.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Realtime Signature Delivery id: ffd99aea-542f-448e-b737-091c1b417274 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_web_evaluation.yml b/detections/endpoint/windows_impair_defense_disable_web_evaluation.yml index 14fe3afff2..ca7527eacf 100644 --- a/detections/endpoint/windows_impair_defense_disable_web_evaluation.yml +++ b/detections/endpoint/windows_impair_defense_disable_web_evaluation.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Web Evaluation id: e234970c-dcf5-4f80-b6a9-3a562544ca5b -version: 5 -date: '2025-01-21' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_app_guard.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_app_guard.yml index a9396eab83..4113418ced 100644 --- a/detections/endpoint/windows_impair_defense_disable_win_defender_app_guard.yml +++ b/detections/endpoint/windows_impair_defense_disable_win_defender_app_guard.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Win Defender App Guard id: 8b700d7e-54ad-4d7d-81cc-1456c4703306 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_compute_file_hashes.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_compute_file_hashes.yml index d8d1c3e1dd..0e827549ac 100644 --- a/detections/endpoint/windows_impair_defense_disable_win_defender_compute_file_hashes.yml +++ b/detections/endpoint/windows_impair_defense_disable_win_defender_compute_file_hashes.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Win Defender Compute File Hashes id: fe52c280-98bd-4596-b6f6-a13bbf8ac7c6 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_gen_reports.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_gen_reports.yml index 0b07829d29..508ebf0f28 100644 --- a/detections/endpoint/windows_impair_defense_disable_win_defender_gen_reports.yml +++ b/detections/endpoint/windows_impair_defense_disable_win_defender_gen_reports.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Win Defender Gen reports id: 93f114f6-cb1e-419b-ac3f-9e11a3045e70 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_network_protection.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_network_protection.yml index 2fd33fce86..f97411180b 100644 --- a/detections/endpoint/windows_impair_defense_disable_win_defender_network_protection.yml +++ b/detections/endpoint/windows_impair_defense_disable_win_defender_network_protection.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Win Defender Network Protection id: 8b6c15c7-5556-463d-83c7-986326c21f12 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_report_infection.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_report_infection.yml index 3311e301c4..118feb49cd 100644 --- a/detections/endpoint/windows_impair_defense_disable_win_defender_report_infection.yml +++ b/detections/endpoint/windows_impair_defense_disable_win_defender_report_infection.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Win Defender Report Infection id: 201946c6-b1d5-42bb-a7e0-5f7123f47fc4 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_scan_on_update.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_scan_on_update.yml index 9f723c9a7a..4d35f7fcf8 100644 --- a/detections/endpoint/windows_impair_defense_disable_win_defender_scan_on_update.yml +++ b/detections/endpoint/windows_impair_defense_disable_win_defender_scan_on_update.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Win Defender Scan On Update id: 0418e72f-e710-4867-b656-0688e1523e09 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_signature_retirement.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_signature_retirement.yml index 1f812f4b95..828bc431c3 100644 --- a/detections/endpoint/windows_impair_defense_disable_win_defender_signature_retirement.yml +++ b/detections/endpoint/windows_impair_defense_disable_win_defender_signature_retirement.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Win Defender Signature Retirement id: 7567a72f-bada-489d-aef1-59743fb64a66 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_overide_win_defender_phishing_filter.yml b/detections/endpoint/windows_impair_defense_overide_win_defender_phishing_filter.yml index 89ec865e6b..fa8a6726f1 100644 --- a/detections/endpoint/windows_impair_defense_overide_win_defender_phishing_filter.yml +++ b/detections/endpoint/windows_impair_defense_overide_win_defender_phishing_filter.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Overide Win Defender Phishing Filter id: 10ca081c-57b1-4a78-ba56-14a40a7e116a -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_override_smartscreen_prompt.yml b/detections/endpoint/windows_impair_defense_override_smartscreen_prompt.yml index 89c4b37a2d..25e00f2f42 100644 --- a/detections/endpoint/windows_impair_defense_override_smartscreen_prompt.yml +++ b/detections/endpoint/windows_impair_defense_override_smartscreen_prompt.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Override SmartScreen Prompt id: 08058866-7987-486f-b042-275715ef6e9d -version: 5 -date: '2025-01-21' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_set_win_defender_smart_screen_level_to_warn.yml b/detections/endpoint/windows_impair_defense_set_win_defender_smart_screen_level_to_warn.yml index 119a81d84b..c5e32b8b14 100644 --- a/detections/endpoint/windows_impair_defense_set_win_defender_smart_screen_level_to_warn.yml +++ b/detections/endpoint/windows_impair_defense_set_win_defender_smart_screen_level_to_warn.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Set Win Defender Smart Screen Level To Warn id: cc2a3425-2703-47e7-818f-3dca1b0bc56f -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defenses_disable_auto_logger_session.yml b/detections/endpoint/windows_impair_defenses_disable_auto_logger_session.yml index 5a904d707d..1220aac4a3 100644 --- a/detections/endpoint/windows_impair_defenses_disable_auto_logger_session.yml +++ b/detections/endpoint/windows_impair_defenses_disable_auto_logger_session.yml @@ -1,7 +1,7 @@ name: Windows Impair Defenses Disable Auto Logger Session id: dc6a5613-d024-47e7-9997-ab6477a483d3 -version: 2 -date: '2025-01-07' +version: 3 +date: '2025-02-10' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -50,7 +50,8 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: Windows Auto Logger Session or Provider registry value set to 'disabled' on $dest$ + message: Windows Auto Logger Session or Provider registry value set to 'disabled' + on $dest$ risk_objects: - field: dest type: system @@ -63,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defenses_disable_av_autostart_via_registry.yml b/detections/endpoint/windows_impair_defenses_disable_av_autostart_via_registry.yml index 9d3ed5adac..0499d7e3de 100644 --- a/detections/endpoint/windows_impair_defenses_disable_av_autostart_via_registry.yml +++ b/detections/endpoint/windows_impair_defenses_disable_av_autostart_via_registry.yml @@ -1,6 +1,6 @@ name: Windows Impair Defenses Disable AV AutoStart via Registry id: 31a13f43-812e-4752-a6ca-c6c87bf03e83 -version: 4 +version: 5 date: '2024-11-13' author: Teoderick Contreras, Splunk data_source: diff --git a/detections/endpoint/windows_impair_defenses_disable_hvci.yml b/detections/endpoint/windows_impair_defenses_disable_hvci.yml index 761a7e1811..cbcc2f8739 100644 --- a/detections/endpoint/windows_impair_defenses_disable_hvci.yml +++ b/detections/endpoint/windows_impair_defenses_disable_hvci.yml @@ -1,7 +1,7 @@ name: Windows Impair Defenses Disable HVCI id: b061dfcc-f0aa-42cc-a6d4-a87f172acb79 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - 70bd71e6-eba4-4e00-92f7-617911dbe020 mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml b/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml index 26e0268183..4faf3a1895 100644 --- a/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml +++ b/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml @@ -1,7 +1,7 @@ name: Windows Impair Defenses Disable Win Defender Auto Logging id: 76406a0f-f5e0-4167-8e1f-337fdc0f1b0c -version: 5 -date: '2024-12-16' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml b/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml index 8bfb3df253..75fd3bf93a 100644 --- a/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml +++ b/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml @@ -1,6 +1,6 @@ name: Windows Ingress Tool Transfer Using Explorer id: 76753bab-f116-4ea3-8fb9-89b638be58a9 -version: 6 +version: 7 date: '2024-11-13' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/windows_input_capture_using_credential_ui_dll.yml b/detections/endpoint/windows_input_capture_using_credential_ui_dll.yml index 2f551ec808..6778cf87fd 100644 --- a/detections/endpoint/windows_input_capture_using_credential_ui_dll.yml +++ b/detections/endpoint/windows_input_capture_using_credential_ui_dll.yml @@ -1,7 +1,7 @@ name: Windows Input Capture Using Credential UI Dll id: 406c21d6-6c75-4e9f-9ca9-48049a1dd90e -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -34,7 +34,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1056.002 - - T1056 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_installutil_credential_theft.yml b/detections/endpoint/windows_installutil_credential_theft.yml index 715a74abb6..647e38256d 100644 --- a/detections/endpoint/windows_installutil_credential_theft.yml +++ b/detections/endpoint/windows_installutil_credential_theft.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil Credential Theft id: ccfeddec-43ec-11ec-b494-acde48001122 -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Mauricio Velazo, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.004 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_installutil_in_non_standard_path.yml b/detections/endpoint/windows_installutil_in_non_standard_path.yml index 3f0452bd4f..139e8140d7 100644 --- a/detections/endpoint/windows_installutil_in_non_standard_path.yml +++ b/detections/endpoint/windows_installutil_in_non_standard_path.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil in Non Standard Path id: dcf74b22-7933-11ec-857c-acde48001122 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -81,9 +81,7 @@ tags: - WhisperGate asset_type: Endpoint mitre_attack_id: - - T1036 - T1036.003 - - T1218 - T1218.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_installutil_remote_network_connection.yml b/detections/endpoint/windows_installutil_remote_network_connection.yml index 7058757a08..3c11ba94f9 100644 --- a/detections/endpoint/windows_installutil_remote_network_connection.yml +++ b/detections/endpoint/windows_installutil_remote_network_connection.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil Remote Network Connection id: 4fbf9270-43da-11ec-9486-acde48001122 -version: 8 -date: '2024-12-10' +version: 10 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -76,7 +76,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.004 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_installutil_uninstall_option.yml b/detections/endpoint/windows_installutil_uninstall_option.yml index 97ee5f6a58..014a79d1e8 100644 --- a/detections/endpoint/windows_installutil_uninstall_option.yml +++ b/detections/endpoint/windows_installutil_uninstall_option.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil Uninstall Option id: cfa7b9ac-43f0-11ec-9b48-acde48001122 -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -77,7 +77,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.004 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_installutil_uninstall_option_with_network.yml b/detections/endpoint/windows_installutil_uninstall_option_with_network.yml index fb760e80bd..0b7b0f9896 100644 --- a/detections/endpoint/windows_installutil_uninstall_option_with_network.yml +++ b/detections/endpoint/windows_installutil_uninstall_option_with_network.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil Uninstall Option with Network id: 1a52c836-43ef-11ec-a36c-acde48001122 -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -78,7 +78,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.004 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_installutil_url_in_command_line.yml b/detections/endpoint/windows_installutil_url_in_command_line.yml index bfae587299..3374400f25 100644 --- a/detections/endpoint/windows_installutil_url_in_command_line.yml +++ b/detections/endpoint/windows_installutil_url_in_command_line.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil URL in Command Line id: 28e06670-43df-11ec-a569-acde48001122 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -75,7 +75,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.004 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_iso_lnk_file_creation.yml b/detections/endpoint/windows_iso_lnk_file_creation.yml index fcbbbebeea..06ff0f1426 100644 --- a/detections/endpoint/windows_iso_lnk_file_creation.yml +++ b/detections/endpoint/windows_iso_lnk_file_creation.yml @@ -1,7 +1,7 @@ name: Windows ISO LNK File Creation id: d7c2c09b-9569-4a9e-a8b6-6a39a99c1d32 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Teoderick Contreras, Splunk status: production type: Hunting @@ -47,10 +47,8 @@ tags: - Gozi Malware asset_type: Endpoint mitre_attack_id: - - T1566.001 - - T1566 - T1204.001 - - T1204 + - T1566.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_java_spawning_shells.yml b/detections/endpoint/windows_java_spawning_shells.yml index 8ed67cb7ab..19a3260fbf 100644 --- a/detections/endpoint/windows_java_spawning_shells.yml +++ b/detections/endpoint/windows_java_spawning_shells.yml @@ -1,6 +1,6 @@ name: Windows Java Spawning Shells id: 28c81306-5c47-11ec-bfea-acde48001122 -version: 7 +version: 8 date: '2024-12-16' author: Michael Haag, Splunk status: experimental diff --git a/detections/endpoint/windows_known_abused_dll_created.yml b/detections/endpoint/windows_known_abused_dll_created.yml index 8c1f4b886f..4ab43c381b 100644 --- a/detections/endpoint/windows_known_abused_dll_created.yml +++ b/detections/endpoint/windows_known_abused_dll_created.yml @@ -1,7 +1,7 @@ name: Windows Known Abused DLL Created id: ea91651a-772a-4b02-ac3d-985b364a5f07 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Steven Dick status: production type: Anomaly @@ -87,7 +87,6 @@ tags: mitre_attack_id: - T1574.001 - T1574.002 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml b/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml index 1509baa004..fd906a1af0 100644 --- a/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml +++ b/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml @@ -1,7 +1,7 @@ name: Windows Known Abused DLL Loaded Suspiciously id: dd6d1f16-adc0-4e87-9c34-06189516b803 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -68,7 +68,6 @@ tags: mitre_attack_id: - T1574.001 - T1574.002 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_known_graphicalproton_loaded_modules.yml b/detections/endpoint/windows_known_graphicalproton_loaded_modules.yml index 0aca5b42c9..8d8b1036e8 100644 --- a/detections/endpoint/windows_known_graphicalproton_loaded_modules.yml +++ b/detections/endpoint/windows_known_graphicalproton_loaded_modules.yml @@ -1,7 +1,7 @@ name: Windows Known GraphicalProton Loaded Modules id: bf471c94-0324-4b19-a113-d02749b969bc -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.002 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_ldifde_directory_object_behavior.yml b/detections/endpoint/windows_ldifde_directory_object_behavior.yml index f03a5ff5a1..30ab7ce4b3 100644 --- a/detections/endpoint/windows_ldifde_directory_object_behavior.yml +++ b/detections/endpoint/windows_ldifde_directory_object_behavior.yml @@ -1,6 +1,6 @@ name: Windows Ldifde Directory Object Behavior id: 35cd29ca-f08c-4489-8815-f715c45460d3 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml b/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml index f2b645134e..a18658909b 100644 --- a/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml +++ b/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml @@ -1,7 +1,7 @@ name: Windows Linked Policies In ADSI Discovery id: 510ea428-4731-4d2f-8829-a28293e427aa -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_local_administrator_credential_stuffing.yml b/detections/endpoint/windows_local_administrator_credential_stuffing.yml index 4669dc1fbe..00ae64da90 100644 --- a/detections/endpoint/windows_local_administrator_credential_stuffing.yml +++ b/detections/endpoint/windows_local_administrator_credential_stuffing.yml @@ -1,7 +1,7 @@ name: Windows Local Administrator Credential Stuffing id: 09555511-aca6-484a-b6ab-72cd03d73c34 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk type: TTP status: production @@ -62,7 +62,6 @@ tags: - Active Directory Lateral Movement asset_type: Endpoint mitre_attack_id: - - T1110 - T1110.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml b/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml index 6a79741770..571055f6e9 100644 --- a/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml +++ b/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml @@ -1,7 +1,7 @@ name: Windows LOLBAS Executed As Renamed File id: fd496996-7d9e-4894-8d40-bb85b6192dc6 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -74,7 +74,6 @@ tags: - Windows Defense Evasion Tactics asset_type: Endpoint mitre_attack_id: - - T1036 - T1036.003 - T1218.011 product: diff --git a/detections/endpoint/windows_lolbas_executed_outside_expected_path.yml b/detections/endpoint/windows_lolbas_executed_outside_expected_path.yml index a11c57c45e..3c51c0705d 100644 --- a/detections/endpoint/windows_lolbas_executed_outside_expected_path.yml +++ b/detections/endpoint/windows_lolbas_executed_outside_expected_path.yml @@ -1,7 +1,7 @@ name: Windows LOLBAS Executed Outside Expected Path id: 326fdf44-b90c-4d2e-adca-1fd140b10536 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -65,7 +65,6 @@ tags: - Windows Defense Evasion Tactics asset_type: Endpoint mitre_attack_id: - - T1036 - T1036.005 - T1218.011 product: diff --git a/detections/endpoint/windows_mail_protocol_in_non_common_process_path.yml b/detections/endpoint/windows_mail_protocol_in_non_common_process_path.yml index f3b8b38435..6661897452 100644 --- a/detections/endpoint/windows_mail_protocol_in_non_common_process_path.yml +++ b/detections/endpoint/windows_mail_protocol_in_non_common_process_path.yml @@ -1,7 +1,7 @@ name: Windows Mail Protocol In Non-Common Process Path id: ac3311f5-661d-4e99-bd1f-3ec665b05441 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1071.003 - - T1071 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_masquerading_explorer_as_child_process.yml b/detections/endpoint/windows_masquerading_explorer_as_child_process.yml index eba3eda086..ff9d52c49c 100644 --- a/detections/endpoint/windows_masquerading_explorer_as_child_process.yml +++ b/detections/endpoint/windows_masquerading_explorer_as_child_process.yml @@ -1,7 +1,7 @@ name: Windows Masquerading Explorer As Child Process id: 61490da9-52a1-4855-a0c5-28233c88c481 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.002 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_mimikatz_binary_execution.yml b/detections/endpoint/windows_mimikatz_binary_execution.yml index b33a7416d4..8578d406d4 100644 --- a/detections/endpoint/windows_mimikatz_binary_execution.yml +++ b/detections/endpoint/windows_mimikatz_binary_execution.yml @@ -1,6 +1,6 @@ name: Windows Mimikatz Binary Execution id: a9e0d6d3-9676-4e26-994d-4e0406bb4467 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_modify_registry_valleyrat_c2_config.yml b/detections/endpoint/windows_modify_registry_valleyrat_c2_config.yml index 6d180da12f..f83503b284 100644 --- a/detections/endpoint/windows_modify_registry_valleyrat_c2_config.yml +++ b/detections/endpoint/windows_modify_registry_valleyrat_c2_config.yml @@ -1,6 +1,6 @@ name: Windows Modify Registry ValleyRAT C2 Config id: ac59298a-8d81-4c02-8c9b-ffdac993891f -version: 4 +version: 5 date: '2024-11-13' author: Teoderick Contreras, Splunk data_source: diff --git a/detections/endpoint/windows_modify_registry_valleyrat_pwn_reg_entry.yml b/detections/endpoint/windows_modify_registry_valleyrat_pwn_reg_entry.yml index cc16e59756..1f0d757c88 100644 --- a/detections/endpoint/windows_modify_registry_valleyrat_pwn_reg_entry.yml +++ b/detections/endpoint/windows_modify_registry_valleyrat_pwn_reg_entry.yml @@ -1,6 +1,6 @@ name: Windows Modify Registry ValleyRat PWN Reg Entry id: 6947c44e-be1f-4dd9-b198-bc42be5be196 -version: 5 +version: 6 date: '2024-12-16' author: Teoderick Contreras, Splunk data_source: diff --git a/detections/endpoint/windows_modify_system_firewall_with_notable_process_path.yml b/detections/endpoint/windows_modify_system_firewall_with_notable_process_path.yml index 3ace7c862d..97cd11c575 100644 --- a/detections/endpoint/windows_modify_system_firewall_with_notable_process_path.yml +++ b/detections/endpoint/windows_modify_system_firewall_with_notable_process_path.yml @@ -1,7 +1,7 @@ name: Windows Modify System Firewall with Notable Process Path id: cd6d7410-9146-4471-a418-49edba6dadc4 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Will Metcalf, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.004 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_mof_event_triggered_execution_via_wmi.yml b/detections/endpoint/windows_mof_event_triggered_execution_via_wmi.yml index 273ecf6bf3..5906eedfab 100644 --- a/detections/endpoint/windows_mof_event_triggered_execution_via_wmi.yml +++ b/detections/endpoint/windows_mof_event_triggered_execution_via_wmi.yml @@ -1,6 +1,6 @@ name: Windows MOF Event Triggered Execution via WMI id: e59b5a73-32bf-4467-a585-452c36ae10c1 -version: 7 +version: 8 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_msexchange_management_mailbox_cmdlet_usage.yml b/detections/endpoint/windows_msexchange_management_mailbox_cmdlet_usage.yml index 5e1bac285c..8cc18bc69f 100644 --- a/detections/endpoint/windows_msexchange_management_mailbox_cmdlet_usage.yml +++ b/detections/endpoint/windows_msexchange_management_mailbox_cmdlet_usage.yml @@ -1,7 +1,7 @@ name: Windows MSExchange Management Mailbox Cmdlet Usage id: 396de86f-25e7-4b0e-be09-a330be35249d -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: - ProxyNotShell asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_msiexec_dllregisterserver.yml b/detections/endpoint/windows_msiexec_dllregisterserver.yml index fab94a6582..862e6c9f89 100644 --- a/detections/endpoint/windows_msiexec_dllregisterserver.yml +++ b/detections/endpoint/windows_msiexec_dllregisterserver.yml @@ -1,6 +1,6 @@ name: Windows MSIExec DLLRegisterServer id: fdb59aef-d88f-4909-8369-ec2afbd2c398 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_msiexec_hidewindow_rundll32_execution.yml b/detections/endpoint/windows_msiexec_hidewindow_rundll32_execution.yml index 92c0e1c8b6..c5d9918949 100644 --- a/detections/endpoint/windows_msiexec_hidewindow_rundll32_execution.yml +++ b/detections/endpoint/windows_msiexec_hidewindow_rundll32_execution.yml @@ -1,7 +1,7 @@ name: Windows MsiExec HideWindow Rundll32 Execution id: 9683271d-92e4-43b5-a907-1983bfb9f7fd -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.007 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_msiexec_remote_download.yml b/detections/endpoint/windows_msiexec_remote_download.yml index 1d89715d94..ea822dfe4d 100644 --- a/detections/endpoint/windows_msiexec_remote_download.yml +++ b/detections/endpoint/windows_msiexec_remote_download.yml @@ -1,6 +1,6 @@ name: Windows MSIExec Remote Download id: 6aa49ff2-3c92-4586-83e0-d83eb693dfda -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_msiexec_spawn_discovery_command.yml b/detections/endpoint/windows_msiexec_spawn_discovery_command.yml index dde48d4cb7..a604c6a7d5 100644 --- a/detections/endpoint/windows_msiexec_spawn_discovery_command.yml +++ b/detections/endpoint/windows_msiexec_spawn_discovery_command.yml @@ -1,6 +1,6 @@ name: Windows MSIExec Spawn Discovery Command id: e9d05aa2-32f0-411b-930c-5b8ca5c4fcee -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_msiexec_spawn_windbg.yml b/detections/endpoint/windows_msiexec_spawn_windbg.yml index 4e4121a5d0..c80059d8d6 100644 --- a/detections/endpoint/windows_msiexec_spawn_windbg.yml +++ b/detections/endpoint/windows_msiexec_spawn_windbg.yml @@ -1,6 +1,6 @@ name: Windows MSIExec Spawn WinDBG id: 9a18f7c2-1fe3-47b8-9467-8b3976770a30 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml b/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml index b7255c3665..697c254586 100644 --- a/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml +++ b/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml @@ -1,6 +1,6 @@ name: Windows MSIExec Unregister DLLRegisterServer id: a27db3c5-1a9a-46df-a577-765d3f1a3c24 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_multi_hop_proxy_tor_website_query.yml b/detections/endpoint/windows_multi_hop_proxy_tor_website_query.yml index 382204bb18..f223d20020 100644 --- a/detections/endpoint/windows_multi_hop_proxy_tor_website_query.yml +++ b/detections/endpoint/windows_multi_hop_proxy_tor_website_query.yml @@ -1,7 +1,7 @@ name: Windows Multi hop Proxy TOR Website Query id: 4c2d198b-da58-48d7-ba27-9368732d0054 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -55,7 +55,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1071.003 - - T1071 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml b/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml index 730fe3867d..cc48eeadc3 100644 --- a/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml +++ b/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml @@ -1,7 +1,7 @@ name: Windows Multiple Disabled Users Failed To Authenticate Wth Kerberos id: 98f22d82-9d62-11eb-9fcf-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk type: TTP status: production @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml b/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml index 7696c03e9d..993132ddda 100644 --- a/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml +++ b/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml @@ -1,7 +1,7 @@ name: Windows Multiple Invalid Users Fail To Authenticate Using Kerberos id: 001266a6-9d5b-11eb-829b-acde48001122 -date: '2024-11-13' -version: 5 +date: '2025-02-10' +version: 6 type: TTP status: production author: Mauricio Velazco, Splunk @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml b/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml index c8db8b309f..88dc4a2ca2 100644 --- a/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml +++ b/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml @@ -1,12 +1,12 @@ name: Windows Multiple Invalid Users Failed To Authenticate Using NTLM id: 57ad5a64-9df7-11eb-a290-acde48001122 type: TTP -version: 6 +version: 7 author: Mauricio Velazco, Splunk status: production data_source: - Windows Event Log Security 4776 -date: '2024-11-13' +date: '2025-02-10' description: The following analytic detects a single source endpoint failing to authenticate with 30 unique invalid users using the NTLM protocol. It leverages EventCode 4776 from Domain Controller logs, focusing on error code 0xC0000064, which indicates @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_multiple_ntlm_null_domain_authentications.yml b/detections/endpoint/windows_multiple_ntlm_null_domain_authentications.yml index cda160cc85..e9ffe53973 100644 --- a/detections/endpoint/windows_multiple_ntlm_null_domain_authentications.yml +++ b/detections/endpoint/windows_multiple_ntlm_null_domain_authentications.yml @@ -1,7 +1,7 @@ name: Windows Multiple NTLM Null Domain Authentications id: c187ce2c-c88e-4cec-8a1c-607ca0dedd78 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -64,7 +64,6 @@ tags: - Active Directory Password Spraying asset_type: Endpoint mitre_attack_id: - - T1110 - T1110.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml b/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml index c57c7baf7e..7d72b1462b 100644 --- a/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml +++ b/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml @@ -1,12 +1,12 @@ name: Windows Multiple Users Fail To Authenticate Wth ExplicitCredentials id: e61918fa-9ca4-11eb-836c-acde48001122 type: TTP -version: 6 +version: 7 status: production author: Mauricio Velazco, Splunk data_source: - Windows Event Log Security 4648 -date: '2024-11-13' +date: '2025-02-10' description: The following analytic identifies a source user failing to authenticate with 30 unique users using explicit credentials on a host. It leverages Windows Event 4648, which is generated when a process attempts an account logon by explicitly @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml index 4791ed5824..d3c8a07eb4 100644 --- a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml +++ b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml @@ -3,10 +3,10 @@ id: 7ed272a4-9c77-11eb-af22-acde48001122 author: Mauricio Velazco, Splunk type: TTP status: production -version: 6 +version: 7 data_source: - Windows Event Log Security 4776 -date: '2024-11-13' +date: '2025-02-10' description: The following analytic identifies a single source endpoint failing to authenticate with 30 unique valid users using the NTLM protocol. It leverages EventCode 4776 from Domain Controller logs, focusing on error code 0xC000006A, which indicates @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml index b4e4eb9ae2..8d8df90f05 100644 --- a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml +++ b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml @@ -1,12 +1,12 @@ name: Windows Multiple Users Failed To Authenticate From Process id: 9015385a-9c84-11eb-bef2-acde48001122 type: TTP -version: 6 +version: 7 status: production author: Mauricio Velazco, Splunk data_source: - Windows Event Log Security 4625 -date: '2024-11-13' +date: '2025-02-10' description: The following analytic detects a source process failing to authenticate with 30 unique users, indicating a potential Password Spraying attack. It leverages Windows Event 4625 with Logon Type 2, collected from domain controllers, member @@ -59,7 +59,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml b/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml index 15df1ec8be..2a4325b756 100644 --- a/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml +++ b/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml @@ -1,8 +1,8 @@ name: Windows Multiple Users Failed To Authenticate Using Kerberos id: 3a91a212-98a9-11eb-b86a-acde48001122 type: TTP -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' status: production author: Mauricio Velazco, Splunk data_source: @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml b/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml index 3c72e172b9..8e5c99c808 100644 --- a/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml +++ b/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml @@ -3,8 +3,8 @@ id: 80f9d53e-9ca1-11eb-b0d6-acde48001122 author: Mauricio Velazco, Splunk type: TTP status: production -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' data_source: - Windows Event Log Security 4625 description: The following analytic identifies a source host failing to authenticate @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_new_custom_security_descriptor_set_on_eventlog_channel.yml b/detections/endpoint/windows_new_custom_security_descriptor_set_on_eventlog_channel.yml index bfeca92a28..4703844127 100644 --- a/detections/endpoint/windows_new_custom_security_descriptor_set_on_eventlog_channel.yml +++ b/detections/endpoint/windows_new_custom_security_descriptor_set_on_eventlog_channel.yml @@ -16,22 +16,9 @@ description: The following analytic detects suspicious modifications to the Even viewing, ingesting and interacting event logs. data_source: - Sysmon EventID 13 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime FROM datamodel=Endpoint.Registry WHERE Registry.registry_path= "*\\Services\\Eventlog\\*" - AND Registry.registry_value_name=CustomSD BY Registry.dest Registry.registry_value_data - Registry.action Registry.process_guid Registry.process_id Registry.registry_key_name - Registry.user Registry.registry_value_name Registry.registry_path | `drop_dm_object_name(Registry)` | where - isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | `windows_new_custom_security_descriptor_set_on_eventlog_channel_filter`' -how_to_implement: To successfully implement this search, you must be ingesting data - that records registry activity from your hosts to populate the endpoint data model - in the registry node. This is typically populated via endpoint detection-and-response - product, such as Carbon Black or endpoint data sources, such as Sysmon. The data - used for this search is typically generated via logs that report reads and writes - to the registry. If you are using Sysmon, you must have at least version 2.0 of - the official Sysmon TA. https://splunkbase.splunk.com/app/5709 -known_false_positives: None identified, setting up the "CustomSD" value is considered - a legacy option and shouldn't be a common activity. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry WHERE Registry.registry_path= "*\\Services\\Eventlog\\*" AND Registry.registry_value_name=CustomSD BY Registry.dest Registry.registry_value_data Registry.action Registry.process_guid Registry.process_id Registry.registry_key_name Registry.user Registry.registry_value_name Registry.registry_path | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_new_custom_security_descriptor_set_on_eventlog_channel_filter`' +how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. If you are using Sysmon, you must have at least version 2.0 of the official Sysmon TA. https://splunkbase.splunk.com/app/5709 +known_false_positives: None identified, setting up the "CustomSD" value is considered a legacy option and shouldn't be a common activity. references: - https://learn.microsoft.com/en-us/troubleshoot/windows-server/group-policy/set-event-log-security-locally-or-via-group-policy - https://attack.mitre.org/techniques/T1562/002/ diff --git a/detections/endpoint/windows_new_default_file_association_value_set.yml b/detections/endpoint/windows_new_default_file_association_value_set.yml index ad44980ccf..74809b6e75 100644 --- a/detections/endpoint/windows_new_default_file_association_value_set.yml +++ b/detections/endpoint/windows_new_default_file_association_value_set.yml @@ -1,16 +1,35 @@ name: Windows New Default File Association Value Set id: 7d1f031f-f1c9-43be-8b0b-c4e3e8a8928a -version: 1 -date: '2025-01-15' +version: 2 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting -description: The following analytic detects registry changes to the default file association value. It leverages data from the Endpoint data model, specifically monitoring registry paths under "HKCR\\*\\shell\\open\\command\\*". This activity can be significant because, attackers might alter the default file associations in order to execute arbitrary scripts or payloads when a user opens a file, leading to potential code execution. If confirmed malicious, this technique can enable attackers to persist on the compromised host and execute further malicious commands, posing a severe threat to the environment. +description: The following analytic detects registry changes to the default file association + value. It leverages data from the Endpoint data model, specifically monitoring registry + paths under "HKCR\\*\\shell\\open\\command\\*". This activity can be significant + because, attackers might alter the default file associations in order to execute + arbitrary scripts or payloads when a user opens a file, leading to potential code + execution. If confirmed malicious, this technique can enable attackers to persist + on the compromised host and execute further malicious commands, posing a severe + threat to the environment. data_source: - Sysmon EventID 13 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\shell\\open\\command\\*" Registry.registry_path IN ("*HKCR\\*", "*HKEY_CLASSES_ROOT\\*") by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `windows_new_default_file_association_value_set_filter`' -how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. -known_false_positives: Windows and third party software will create and modify these file associations during installation or upgrades. Additional filters needs to be applied to tune environment specific false positives. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime + max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\shell\\open\\command\\*" + Registry.registry_path IN ("*HKCR\\*", "*HKEY_CLASSES_ROOT\\*") by Registry.dest Registry.user + Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data + | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` + | `windows_new_default_file_association_value_set_filter`' +how_to_implement: To successfully implement this search, you must be ingesting data + that records registry activity from your hosts to populate the endpoint data model + in the registry node. This is typically populated via endpoint detection-and-response + product, such as Carbon Black or endpoint data sources, such as Sysmon. The data + used for this search is typically generated via logs that report reads and writes + to the registry. +known_false_positives: Windows and third party software will create and modify these + file associations during installation or upgrades. Additional filters needs to be + applied to tune environment specific false positives. references: - https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/accessibility-features drilldown_searches: @@ -19,7 +38,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" and "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", + "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) + as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk + Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ tags: @@ -33,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.001 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security @@ -42,6 +65,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.001/txtfile_reg/sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.001/txtfile_reg/sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_ngrok_reverse_proxy_usage.yml b/detections/endpoint/windows_ngrok_reverse_proxy_usage.yml index 9d6caf3abd..aae826157a 100644 --- a/detections/endpoint/windows_ngrok_reverse_proxy_usage.yml +++ b/detections/endpoint/windows_ngrok_reverse_proxy_usage.yml @@ -1,6 +1,6 @@ name: Windows Ngrok Reverse Proxy Usage id: e2549f2c-0aef-408a-b0c1-e0f270623436 -version: 6 +version: 7 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_nirsoft_advancedrun.yml b/detections/endpoint/windows_nirsoft_advancedrun.yml index 62b05e5300..4a5461615e 100644 --- a/detections/endpoint/windows_nirsoft_advancedrun.yml +++ b/detections/endpoint/windows_nirsoft_advancedrun.yml @@ -1,6 +1,6 @@ name: Windows NirSoft AdvancedRun id: bb4f3090-7ae4-11ec-897f-acde48001122 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_njrat_fileless_storage_via_registry.yml b/detections/endpoint/windows_njrat_fileless_storage_via_registry.yml index b152d8f05a..22f73f858f 100644 --- a/detections/endpoint/windows_njrat_fileless_storage_via_registry.yml +++ b/detections/endpoint/windows_njrat_fileless_storage_via_registry.yml @@ -1,7 +1,7 @@ name: Windows Njrat Fileless Storage via Registry id: a5fffbbd-271f-4980-94ed-4fbf17f0af1c -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1027.011 - - T1027 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_non_system_account_targeting_lsass.yml b/detections/endpoint/windows_non_system_account_targeting_lsass.yml index 0a6c933bc2..b6588d58e9 100644 --- a/detections/endpoint/windows_non_system_account_targeting_lsass.yml +++ b/detections/endpoint/windows_non_system_account_targeting_lsass.yml @@ -1,7 +1,7 @@ name: Windows Non-System Account Targeting Lsass id: b1ce9a72-73cf-11ec-981b-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_odbcconf_load_dll.yml b/detections/endpoint/windows_odbcconf_load_dll.yml index 815aa3b02f..f7a52f0e6a 100644 --- a/detections/endpoint/windows_odbcconf_load_dll.yml +++ b/detections/endpoint/windows_odbcconf_load_dll.yml @@ -1,6 +1,6 @@ name: Windows Odbcconf Load DLL id: 141e7fca-a9f0-40fd-a539-9aac8be41f1b -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_odbcconf_load_response_file.yml b/detections/endpoint/windows_odbcconf_load_response_file.yml index 0fa23e5e03..7d234fd114 100644 --- a/detections/endpoint/windows_odbcconf_load_response_file.yml +++ b/detections/endpoint/windows_odbcconf_load_response_file.yml @@ -1,6 +1,6 @@ name: Windows Odbcconf Load Response File id: 1acafff9-1347-4b40-abae-f35aa4ba85c1 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml b/detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml index 52313880e5..f6134c4079 100644 --- a/detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml +++ b/detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml @@ -1,17 +1,36 @@ name: Windows Office Product Dropped Cab or Inf File id: dbdd251e-dd45-4ec9-a555-f5e151391746 -version: 1 -date: '2025-01-20' +version: 2 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP -description: The following analytic detects Office products writing .cab or .inf files, indicative of CVE-2021-40444 exploitation. It leverages the Endpoint.Processes and Endpoint.Filesystem data models to identify Office applications creating these file types. This activity is significant as it may signal an attempt to load malicious ActiveX controls and download remote payloads, a known attack vector. If confirmed malicious, this could lead to remote code execution, allowing attackers to gain control over the affected system and potentially compromise sensitive data. +description: The following analytic detects Office products writing .cab or .inf files, + indicative of CVE-2021-40444 exploitation. It leverages the Endpoint.Processes and + Endpoint.Filesystem data models to identify Office applications creating these file + types. This activity is significant as it may signal an attempt to load malicious + ActiveX controls and download remote payloads, a known attack vector. If confirmed + malicious, this could lead to remote code execution, allowing attackers to gain + control over the affected system and potentially compromise sensitive data. data_source: - Sysmon EventID 1 AND Sysmon EventID 11 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_office_products` by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | join proc_guid, _time [ | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.cab", "*.inf") by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid | `drop_dm_object_name(Filesystem)` |rename process_guid as proc_guid | fields _time dest file_create_time file_name file_path process_name process_path process proc_guid] | dedup file_create_time | table dest, process_name, process, file_create_time, file_name, file_path, proc_guid | `windows_office_product_dropped_cab_or_inf_file_filter`' -how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` node. +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + where `process_office_products` by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.process_guid | `drop_dm_object_name(Processes)` + |rename process_guid as proc_guid | join proc_guid, _time [ | tstats `security_content_summariesonly` + count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem + where Filesystem.file_name IN ("*.cab", "*.inf") by _time span=1h Filesystem.dest + Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid + | `drop_dm_object_name(Filesystem)` |rename process_guid as proc_guid | fields _time + dest file_create_time file_name file_path process_name process_path process proc_guid] + | dedup file_create_time | table dest, process_name, process, file_create_time, + file_name, file_path, proc_guid | `windows_office_product_dropped_cab_or_inf_file_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` + node. known_false_positives: The query is structured in a way that `action` (read, create) is not defined. Review the results of this query, filter, and tune as necessary. It may be necessary to generate this query specific to your endpoint product. @@ -54,7 +73,6 @@ tags: cve: - CVE-2021-40444 mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -64,6 +82,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_cabinf.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_cabinf.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_office_product_dropped_uncommon_file.yml b/detections/endpoint/windows_office_product_dropped_uncommon_file.yml index bf3090d832..fad1a08049 100644 --- a/detections/endpoint/windows_office_product_dropped_uncommon_file.yml +++ b/detections/endpoint/windows_office_product_dropped_uncommon_file.yml @@ -1,15 +1,35 @@ name: Windows Office Product Dropped Uncommon File id: 7ac0fced-9eae-4381-a748-90dcd1aa9393 -version: 1 -date: '2025-01-20' +version: 2 +date: '2025-02-10' author: Teoderick Contreras, Michael Haag, Splunk, TheLawsOfChaos, Github status: production type: Anomaly -description: The following analytic detects Microsoft Office applications dropping or creating executables or scripts on a Windows OS. It leverages process creation and file system events from the Endpoint data model to identify Office applications like Word or Excel generating files with extensions such as ".exe", ".dll", or ".ps1". This behavior is significant as it is often associated with spear-phishing attacks where malicious files are dropped to compromise the host. If confirmed malicious, this activity could lead to code execution, privilege escalation, or persistent access, posing a severe threat to the environment. +description: The following analytic detects Microsoft Office applications dropping + or creating executables or scripts on a Windows OS. It leverages process creation + and file system events from the Endpoint data model to identify Office applications + like Word or Excel generating files with extensions such as ".exe", ".dll", or ".ps1". + This behavior is significant as it is often associated with spear-phishing attacks + where malicious files are dropped to compromise the host. If confirmed malicious, + this activity could lead to code execution, privilege escalation, or persistent + access, posing a severe threat to the environment. data_source: - Sysmon EventID 1 AND Sysmon EventID 11 -search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_office_products` by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.process_guid | `drop_dm_object_name(Processes)` | join process_guid, _time [| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.dll", "*.exe", "*.js", "*.pif", "*.ps1", "*.scr", "*.vbe", "*.vbs") by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.process_guid Filesystem.file_path | `drop_dm_object_name(Filesystem)` | fields _time dest file_create_time file_name file_path process_name process_path process process_guid] | dedup file_create_time | table dest, process_name, process, file_create_time, file_name, file_path, process_guid | `windows_office_product_dropped_uncommon_file_filter`' -how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + where `process_office_products` by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.process_guid | `drop_dm_object_name(Processes)` + | join process_guid, _time [| tstats `security_content_summariesonly` count min(_time) + as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name + IN ("*.dll", "*.exe", "*.js", "*.pif", "*.ps1", "*.scr", "*.vbe", "*.vbs") by _time + span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.process_guid + Filesystem.file_path | `drop_dm_object_name(Filesystem)` | fields _time dest file_create_time + file_name file_path process_name process_path process process_guid] | dedup file_create_time + | table dest, process_name, process, file_create_time, file_name, file_path, process_guid + | `windows_office_product_dropped_uncommon_file_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. known_false_positives: office macro for automation may do this behavior references: - https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation @@ -49,7 +69,6 @@ tags: - PlugX asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -59,6 +78,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_macro_js_1/sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_macro_js_1/sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_office_product_loaded_mshtml_module.yml b/detections/endpoint/windows_office_product_loaded_mshtml_module.yml index 2d546a5b2b..cb6ba413cc 100644 --- a/detections/endpoint/windows_office_product_loaded_mshtml_module.yml +++ b/detections/endpoint/windows_office_product_loaded_mshtml_module.yml @@ -1,16 +1,31 @@ name: Windows Office Product Loaded MSHTML Module id: 4cc015c9-687c-40d2-adcc-46350f66e10c -version: 1 -date: '2025-01-20' +version: 2 +date: '2025-02-10' author: Michael Haag, Mauricio Velazco, Splunk status: production type: Anomaly -description: The following analytic detects the loading of the mshtml.dll module into an Office product, which is indicative of CVE-2021-40444 exploitation. It leverages Sysmon EventID 7 to monitor image loads by specific Office processes. This activity is significant because it can indicate an attempt to exploit a vulnerability in the MSHTML component via a malicious document. If confirmed malicious, this could allow an attacker to execute arbitrary code, potentially leading to system compromise, data exfiltration, or further network penetration. +description: The following analytic detects the loading of the mshtml.dll module into + an Office product, which is indicative of CVE-2021-40444 exploitation. It leverages + Sysmon EventID 7 to monitor image loads by specific Office processes. This activity + is significant because it can indicate an attempt to exploit a vulnerability in + the MSHTML component via a malicious document. If confirmed malicious, this could + allow an attacker to execute arbitrary code, potentially leading to system compromise, + data exfiltration, or further network penetration. data_source: - Sysmon EventID 7 -search: '`sysmon` EventID=7 process_name IN ("EQNEDT32.exe", "excel.exe", "Graph.exe", "msaccess.exe", "mspub.exe", "onenote.exe", "onenoteim.exe", "onenotem.exe", "outlook.exe", "powerpnt.exe", "visio.exe", "winproj.exe", "winword.exe", "wordpad.exe", "wordview.exe") loaded_file_path IN ("*\\mshtml.dll", "*\\Microsoft.mshtml.dll","*\\IE.Interop.MSHTML.dll","*\\MshtmlDac.dll","*\\MshtmlDed.dll","*\\MshtmlDer.dll") | stats count min(_time) as firstTime max(_time) as lastTime by user_id, dest, process_name, loaded_file, loaded_file_path, original_file_name, process_guid | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_office_product_loaded_mshtml_module_filter`' -how_to_implement: To successfully implement this search, you need to be ingesting logs with the process names and image loads from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. -known_false_positives: Limited false positives will be present, however, tune as necessary. Some applications may legitimately load mshtml.dll. +search: '`sysmon` EventID=7 process_name IN ("EQNEDT32.exe", "excel.exe", "Graph.exe", + "msaccess.exe", "mspub.exe", "onenote.exe", "onenoteim.exe", "onenotem.exe", "outlook.exe", + "powerpnt.exe", "visio.exe", "winproj.exe", "winword.exe", "wordpad.exe", "wordview.exe") + loaded_file_path IN ("*\\mshtml.dll", "*\\Microsoft.mshtml.dll","*\\IE.Interop.MSHTML.dll","*\\MshtmlDac.dll","*\\MshtmlDed.dll","*\\MshtmlDer.dll") + | stats count min(_time) as firstTime max(_time) as lastTime by user_id, dest, process_name, + loaded_file, loaded_file_path, original_file_name, process_guid | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `windows_office_product_loaded_mshtml_module_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process names and image loads from your endpoints. If you are using + Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +known_false_positives: Limited false positives will be present, however, tune as necessary. + Some applications may legitimately load mshtml.dll. references: - https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/ - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444 @@ -22,7 +37,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -44,7 +64,6 @@ tags: cve: - CVE-2021-40444 mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -54,6 +73,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_mshtml.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_mshtml.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_office_product_loading_taskschd_dll.yml b/detections/endpoint/windows_office_product_loading_taskschd_dll.yml index b16c25faa3..a7ba40103b 100644 --- a/detections/endpoint/windows_office_product_loading_taskschd_dll.yml +++ b/detections/endpoint/windows_office_product_loading_taskschd_dll.yml @@ -1,16 +1,33 @@ name: Windows Office Product Loading Taskschd DLL id: d7297cfa-1f04-4714-bfbe-3679e0666959 -version: 1 -date: '2025-01-20' +version: 2 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly -description: The following analytic detects an Office document creating a scheduled task, either through a macro VBA API or by loading `taskschd.dll`. This detection leverages Sysmon EventCode 7 to identify when Office applications load the `taskschd.dll` file. This activity is significant as it is a common technique used by malicious macro malware to establish persistence or initiate beaconing. If confirmed malicious, this could allow an attacker to maintain persistence, execute arbitrary commands, or schedule future malicious activities, posing a significant threat to the environment. +description: The following analytic detects an Office document creating a scheduled + task, either through a macro VBA API or by loading `taskschd.dll`. This detection + leverages Sysmon EventCode 7 to identify when Office applications load the `taskschd.dll` + file. This activity is significant as it is a common technique used by malicious + macro malware to establish persistence or initiate beaconing. If confirmed malicious, + this could allow an attacker to maintain persistence, execute arbitrary commands, + or schedule future malicious activities, posing a significant threat to the environment. data_source: - Sysmon EventID 7 -search: '`sysmon` EventCode=7 process_name IN ("EQNEDT32.exe", "excel.exe", "Graph.exe", "msaccess.exe", "mspub.exe", "onenote.exe", "onenoteim.exe", "onenotem.exe", "outlook.exe", "powerpnt.exe", "visio.exe", "winproj.exe", "winword.exe") loaded_file_path = "*\\taskschd.dll" | stats min(_time) as firstTime max(_time) as lastTime count by user_id, dest, process_name,loaded_file, loaded_file_path, original_file_name, process_guid | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_office_product_loading_taskschd_dll_filter`' -how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name and ImageLoaded (Like sysmon EventCode 7) from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Also be sure to include those monitored dll to your own sysmon config. -known_false_positives: False positives may occur if legitimate office documents are creating scheduled tasks. Ensure to investigate the scheduled task and the command to be executed. If the task is benign, add the task name to the exclusion list. Some applications may legitimately load taskschd.dll. +search: '`sysmon` EventCode=7 process_name IN ("EQNEDT32.exe", "excel.exe", "Graph.exe", + "msaccess.exe", "mspub.exe", "onenote.exe", "onenoteim.exe", "onenotem.exe", "outlook.exe", + "powerpnt.exe", "visio.exe", "winproj.exe", "winword.exe") loaded_file_path = "*\\taskschd.dll" + | stats min(_time) as firstTime max(_time) as lastTime count by user_id, dest, process_name,loaded_file, + loaded_file_path, original_file_name, process_guid | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `windows_office_product_loading_taskschd_dll_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name and ImageLoaded (Like sysmon EventCode 7) from your endpoints. + If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + Also be sure to include those monitored dll to your own sysmon config. +known_false_positives: False positives may occur if legitimate office documents are + creating scheduled tasks. Ensure to investigate the scheduled task and the command + to be executed. If the task is benign, add the task name to the exclusion list. + Some applications may legitimately load taskschd.dll. references: - https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/ - https://redcanary.com/threat-detection-report/techniques/scheduled-task-job/ @@ -21,7 +38,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -37,7 +59,6 @@ tags: - Spearphishing Attachments asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -47,6 +68,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_office_product_loading_vbe7_dll.yml b/detections/endpoint/windows_office_product_loading_vbe7_dll.yml index d4aa93a79a..e68293a575 100644 --- a/detections/endpoint/windows_office_product_loading_vbe7_dll.yml +++ b/detections/endpoint/windows_office_product_loading_vbe7_dll.yml @@ -1,16 +1,33 @@ name: Windows Office Product Loading VBE7 DLL id: 7cfec906-2697-43f7-898b-83634a051d9a -version: 1 -date: '2025-01-20' +version: 2 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly -description: The following analytic identifies office documents executing macro code. It leverages Sysmon EventCode 7 to detect when processes like WINWORD.EXE or EXCEL.EXE load specific DLLs associated with macros (e.g., VBE7.DLL). This activity is significant because macros are a common attack vector for delivering malicious payloads, such as malware. If confirmed malicious, this could lead to unauthorized code execution, data exfiltration, or further compromise of the system. Disabling macros by default is recommended to mitigate this risk. +description: The following analytic identifies office documents executing macro code. + It leverages Sysmon EventCode 7 to detect when processes like WINWORD.EXE or EXCEL.EXE + load specific DLLs associated with macros (e.g., VBE7.DLL). This activity is significant + because macros are a common attack vector for delivering malicious payloads, such + as malware. If confirmed malicious, this could lead to unauthorized code execution, + data exfiltration, or further compromise of the system. Disabling macros by default + is recommended to mitigate this risk. data_source: - Sysmon EventID 7 -search: '`sysmon` EventCode=7 process_name IN ("EQNEDT32.exe", "excel.exe", "Graph.exe", "msaccess.exe", "mspub.exe", "onenote.exe", "onenoteim.exe", "onenotem.exe", "outlook.exe", "powerpnt.exe", "visio.exe", "winproj.exe", "winword.exe") loaded_file_path IN ("*\\VBE7INTL.DLL", "*\\VBE7.DLL", "*\\VBEUI.DLL") | stats min(_time) as firstTime max(_time) as lastTime values(loaded_file) as loaded_file count by dest EventCode process_name process_guid | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_office_product_loading_vbe7_dll_filter`' -how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name and ImageLoaded (Like sysmon EventCode 7) from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Also be sure to include those monitored dll to your own sysmon config. -known_false_positives: False positives may occur if legitimate office documents are executing macro code. Ensure to investigate the macro code and the command to be executed. If the macro code is benign, add the document name to the exclusion list. Some applications may legitimately load VBE7INTL.DLL, VBE7.DLL, or VBEUI.DLL. +search: '`sysmon` EventCode=7 process_name IN ("EQNEDT32.exe", "excel.exe", "Graph.exe", + "msaccess.exe", "mspub.exe", "onenote.exe", "onenoteim.exe", "onenotem.exe", "outlook.exe", + "powerpnt.exe", "visio.exe", "winproj.exe", "winword.exe") loaded_file_path IN ("*\\VBE7INTL.DLL", + "*\\VBE7.DLL", "*\\VBEUI.DLL") | stats min(_time) as firstTime max(_time) as lastTime + values(loaded_file) as loaded_file count by dest EventCode process_name process_guid + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_office_product_loading_vbe7_dll_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name and ImageLoaded (Like sysmon EventCode 7) from your endpoints. + If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + Also be sure to include those monitored dll to your own sysmon config. +known_false_positives: False positives may occur if legitimate office documents are + executing macro code. Ensure to investigate the macro code and the command to be + executed. If the macro code is benign, add the document name to the exclusion list. + Some applications may legitimately load VBE7INTL.DLL, VBE7.DLL, or VBEUI.DLL. references: - https://www.joesandbox.com/analysis/386500/0/html - https://www.joesandbox.com/analysis/702680/0/html @@ -24,7 +41,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -48,7 +70,6 @@ tags: - NjRAT asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -58,6 +79,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml b/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml index 0b215898be..60bbc6b349 100644 --- a/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml +++ b/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml @@ -1,17 +1,38 @@ name: Windows Office Product Spawned Child Process For Download id: f02b64b8-cbea-4f75-bf77-7a05111566b1 -version: 1 -date: '2025-01-14' +version: 2 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP -description: The following analytic identifies Office applications spawning child processes to download content via HTTP/HTTPS. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process creation events where Office applications like Word or Excel initiate network connections, excluding common browsers. This activity is significant as it often indicates the use of malicious documents to execute living-off-the-land binaries (LOLBins) for payload delivery. If confirmed malicious, this behavior could lead to unauthorized code execution, data exfiltration, or further malware deployment, posing a severe threat to the organization's security. +description: The following analytic identifies Office applications spawning child + processes to download content via HTTP/HTTPS. It leverages data from Endpoint Detection + and Response (EDR) agents, focusing on process creation events where Office applications + like Word or Excel initiate network connections, excluding common browsers. This + activity is significant as it often indicates the use of malicious documents to + execute living-off-the-land binaries (LOLBins) for payload delivery. If confirmed + malicious, this behavior could lead to unauthorized code execution, data exfiltration, + or further malware deployment, posing a severe threat to the organization's security. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` Processes.process IN ("*http:*","*https:*") NOT (Processes.original_file_name IN ("firefox.exe", "chrome.exe","iexplore.exe","msedge.exe")) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_office_product_spawned_child_process_for_download_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` + Processes.process IN ("*http:*","*https:*") NOT (Processes.original_file_name IN + ("firefox.exe", "chrome.exe","iexplore.exe","msedge.exe")) by Processes.dest Processes.user + Processes.parent_process_name Processes.process_name Processes.process Processes.process_id + Processes.parent_process_id Processes.original_file_name | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_office_product_spawned_child_process_for_download_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. known_false_positives: Default browser not in the filter list. references: - https://app.any.run/tasks/92d7ef61-bfd7-4c92-bc15-322172b4ebec/ @@ -22,7 +43,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -40,7 +66,6 @@ tags: - NjRAT asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -50,6 +75,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets2/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets2/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_office_product_spawned_control.yml b/detections/endpoint/windows_office_product_spawned_control.yml index 5590c761b9..12ffb28a63 100644 --- a/detections/endpoint/windows_office_product_spawned_control.yml +++ b/detections/endpoint/windows_office_product_spawned_control.yml @@ -1,7 +1,7 @@ name: Windows Office Product Spawned Control id: 081c485d-ac8d-4bee-ad4c-525772fead4d -version: 1 -date: '2025-01-14' +version: 3 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -17,7 +17,12 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` Processes.process_name=control.exe by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `windows_office_product_spawned_control_filter`' +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` + Processes.process_name=control.exe by Processes.dest Processes.user Processes.parent_process_name + Processes.parent_process Processes.process_name Processes.process Processes.process_id + Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| + `security_content_ctime(lastTime)`| `windows_office_product_spawned_control_filter`' how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, @@ -71,7 +76,6 @@ tags: cve: - CVE-2021-40444 mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -81,6 +85,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_control.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_control.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_office_product_spawned_msdt.yml b/detections/endpoint/windows_office_product_spawned_msdt.yml index 3a79e47208..9f855ec660 100644 --- a/detections/endpoint/windows_office_product_spawned_msdt.yml +++ b/detections/endpoint/windows_office_product_spawned_msdt.yml @@ -1,7 +1,7 @@ name: Windows Office Product Spawned MSDT id: a3148fad-3734-4b7f-9a71-62f08d39fab1 -version: 1 -date: '2025-01-14' +version: 3 +date: '2025-02-10' author: Michael Haag, Teoderick Contreras, Splunk status: production type: TTP @@ -17,7 +17,12 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` Processes.process_name=msdt.exe by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_office_product_spawned_msdt_filter`' +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` + Processes.process_name=msdt.exe by Processes.dest Processes.user Processes.parent_process_name + Processes.parent_process Processes.process_name Processes.original_file_name Processes.process + Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_office_product_spawned_msdt_filter`' how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, @@ -74,7 +79,6 @@ tags: cve: - CVE-2022-30190 mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -84,6 +88,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/msdt.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/msdt.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_office_product_spawned_rundll32_with_no_dll.yml b/detections/endpoint/windows_office_product_spawned_rundll32_with_no_dll.yml index 21813278bb..f44212470f 100644 --- a/detections/endpoint/windows_office_product_spawned_rundll32_with_no_dll.yml +++ b/detections/endpoint/windows_office_product_spawned_rundll32_with_no_dll.yml @@ -1,7 +1,7 @@ name: Windows Office Product Spawned Rundll32 With No DLL id: f28e787e-69ca-480e-9f98-ab970e6d4bcc -version: 1 -date: '2025-01-14' +version: 2 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -17,7 +17,12 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` `process_rundll32` (Processes.process!=*.dll*) by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_office_product_spawned_rundll32_with_no_dll_filter`' +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` + `process_rundll32` (Processes.process!=*.dll*) by Processes.dest Processes.user + Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process + Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_office_product_spawned_rundll32_with_no_dll_filter`' how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, @@ -68,7 +73,6 @@ tags: - Crypto Stealer asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -78,6 +82,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_icedid.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_icedid.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_office_product_spawned_uncommon_process.yml b/detections/endpoint/windows_office_product_spawned_uncommon_process.yml index 5dc516ea3d..be1ba871e9 100644 --- a/detections/endpoint/windows_office_product_spawned_uncommon_process.yml +++ b/detections/endpoint/windows_office_product_spawned_uncommon_process.yml @@ -1,17 +1,39 @@ name: Windows Office Product Spawned Uncommon Process id: 55d8741c-fa32-4692-8109-410304961eb8 -version: 1 -date: '2025-01-13' +version: 2 +date: '2025-02-10' author: Michael Haag, Teoderick Contreras, Splunk status: production type: TTP -description: The following analytic detects a Microsoft Office product spawning uncommon processes. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process creation events where Office applications are the parent process. This activity is significant as it may indicate an attempt of a malicious macro execution or exploitation of an unknown vulnerability in an office product, in order to bypass security controls. If confirmed malicious, this behavior could allow an attacker to execute arbitrary code, potentially leading to system compromise, data exfiltration, or further lateral movement within the network. +description: The following analytic detects a Microsoft Office product spawning uncommon + processes. This detection leverages data from Endpoint Detection and Response (EDR) + agents, focusing on process creation events where Office applications are the parent + process. This activity is significant as it may indicate an attempt of a malicious + macro execution or exploitation of an unknown vulnerability in an office product, + in order to bypass security controls. If confirmed malicious, this behavior could + allow an attacker to execute arbitrary code, potentially leading to system compromise, + data exfiltration, or further lateral movement within the network. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` AND (`process_bitsadmin` OR `process_certutil` OR `process_cmd` OR `process_cscript` OR `process_mshta` OR `process_powershell` OR `process_regsvr32` OR `process_rundll32` OR `process_wmic` OR `process_wscript`) by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_office_product_spawned_uncommon_process_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` + AND (`process_bitsadmin` OR `process_certutil` OR `process_cmd` OR `process_cscript` + OR `process_mshta` OR `process_powershell` OR `process_regsvr32` OR `process_rundll32` + OR `process_wmic` OR `process_wscript`) by Processes.dest Processes.user Processes.parent_process_name + Processes.parent_process Processes.process_name Processes.original_file_name Processes.process + Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_office_product_spawned_uncommon_process_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. known_false_positives: False positives should be limited, however filter as needed. references: - https://any.run/malware-trends/trickbot @@ -74,7 +96,6 @@ tags: - Warzone RAT asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -84,26 +105,31 @@ tags: tests: - name: True Positive Test - Macro attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog - name: True Positive Test - IcedId attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/phish_icedid/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/phish_icedid/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog -- name: True Positive Test +- name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.002/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.002/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog - name: True Positive Test - TrickBot attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/spear_phish/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/spear_phish/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_papercut_ng_spawn_shell.yml b/detections/endpoint/windows_papercut_ng_spawn_shell.yml index 31198dc5a3..d647e50311 100644 --- a/detections/endpoint/windows_papercut_ng_spawn_shell.yml +++ b/detections/endpoint/windows_papercut_ng_spawn_shell.yml @@ -1,6 +1,6 @@ name: Windows PaperCut NG Spawn Shell id: a602d9a2-aaea-45f8-bf0f-d851168d61ca -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_parent_pid_spoofing_with_explorer.yml b/detections/endpoint/windows_parent_pid_spoofing_with_explorer.yml index 11cc9f084e..1fb1a5fb88 100644 --- a/detections/endpoint/windows_parent_pid_spoofing_with_explorer.yml +++ b/detections/endpoint/windows_parent_pid_spoofing_with_explorer.yml @@ -1,7 +1,7 @@ name: Windows Parent PID Spoofing with Explorer id: 17f8f69c-5d00-4c88-9c6f-493bbdef20a1 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1134.004 - - T1134 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_phishing_pdf_file_executes_url_link.yml b/detections/endpoint/windows_phishing_pdf_file_executes_url_link.yml index 18c5531a67..13103b18d8 100644 --- a/detections/endpoint/windows_phishing_pdf_file_executes_url_link.yml +++ b/detections/endpoint/windows_phishing_pdf_file_executes_url_link.yml @@ -1,7 +1,7 @@ name: Windows Phishing PDF File Executes URL Link id: 2fa9dec8-9d8e-46d3-96c1-202c06f0e6e1 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1566.001 - - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml b/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml index 2b4bed4e9f..bc0b87b903 100644 --- a/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml +++ b/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml @@ -1,7 +1,7 @@ name: Windows Phishing Recent ISO Exec Registry id: cb38ee66-8ae5-47de-bd66-231c7bbc0b2c -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -48,7 +48,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1566.001 - - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_possible_credential_dumping.yml b/detections/endpoint/windows_possible_credential_dumping.yml index 470fcafb77..2d20510beb 100644 --- a/detections/endpoint/windows_possible_credential_dumping.yml +++ b/detections/endpoint/windows_possible_credential_dumping.yml @@ -1,7 +1,7 @@ name: Windows Possible Credential Dumping id: e4723b92-7266-11ec-af45-acde48001122 -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -74,7 +74,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_powershell_add_module_to_global_assembly_cache.yml b/detections/endpoint/windows_powershell_add_module_to_global_assembly_cache.yml index be0d947169..e74b775e06 100644 --- a/detections/endpoint/windows_powershell_add_module_to_global_assembly_cache.yml +++ b/detections/endpoint/windows_powershell_add_module_to_global_assembly_cache.yml @@ -1,7 +1,7 @@ name: Windows PowerShell Add Module to Global Assembly Cache id: 3fc16961-97e5-4a5b-a079-e4ab0d9763eb -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -54,7 +54,6 @@ tags: - IIS Components asset_type: Endpoint mitre_attack_id: - - T1505 - T1505.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_powershell_cryptography_namespace.yml b/detections/endpoint/windows_powershell_cryptography_namespace.yml index bf088f301f..cdcc825296 100644 --- a/detections/endpoint/windows_powershell_cryptography_namespace.yml +++ b/detections/endpoint/windows_powershell_cryptography_namespace.yml @@ -1,7 +1,7 @@ name: Windows Powershell Cryptography Namespace id: f8b482f4-6d62-49fa-a905-dfa15698317b -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.001 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_powershell_disable_http_logging.yml b/detections/endpoint/windows_powershell_disable_http_logging.yml index 4c3060bb6a..b770a22794 100644 --- a/detections/endpoint/windows_powershell_disable_http_logging.yml +++ b/detections/endpoint/windows_powershell_disable_http_logging.yml @@ -1,7 +1,7 @@ name: Windows PowerShell Disable HTTP Logging id: 27958de0-2857-43ca-9d4c-b255cf59dcab -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -58,10 +58,8 @@ tags: - Windows Defense Evasion Tactics asset_type: Endpoint mitre_attack_id: - - T1562 - - T1562.002 - - T1505 - T1505.004 + - T1562.002 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_powershell_export_certificate.yml b/detections/endpoint/windows_powershell_export_certificate.yml index bbe40a4adc..acbed42b34 100644 --- a/detections/endpoint/windows_powershell_export_certificate.yml +++ b/detections/endpoint/windows_powershell_export_certificate.yml @@ -1,7 +1,7 @@ name: Windows PowerShell Export Certificate id: 5e38ded4-c964-41f4-8cb6-4a1a53c6929f -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -55,7 +55,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.004 - - T1552 - T1649 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_powershell_export_pfxcertificate.yml b/detections/endpoint/windows_powershell_export_pfxcertificate.yml index 7f493a22c9..8a44eca228 100644 --- a/detections/endpoint/windows_powershell_export_pfxcertificate.yml +++ b/detections/endpoint/windows_powershell_export_pfxcertificate.yml @@ -1,7 +1,7 @@ name: Windows PowerShell Export PfxCertificate id: ed06725f-6da6-439f-9dcc-ab30e891297c -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -54,7 +54,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.004 - - T1552 - T1649 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_powershell_iis_components_webglobalmodule_usage.yml b/detections/endpoint/windows_powershell_iis_components_webglobalmodule_usage.yml index ae73b3a6e6..3a9bdc8cc3 100644 --- a/detections/endpoint/windows_powershell_iis_components_webglobalmodule_usage.yml +++ b/detections/endpoint/windows_powershell_iis_components_webglobalmodule_usage.yml @@ -1,7 +1,7 @@ name: Windows PowerShell IIS Components WebGlobalModule Usage id: 33fc9f6f-0ce7-4696-924e-a69ec61a3d57 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: - IIS Components asset_type: Endpoint mitre_attack_id: - - T1505 - T1505.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_powershell_import_applocker_policy.yml b/detections/endpoint/windows_powershell_import_applocker_policy.yml index a2cfb60449..b7e2a44f69 100644 --- a/detections/endpoint/windows_powershell_import_applocker_policy.yml +++ b/detections/endpoint/windows_powershell_import_applocker_policy.yml @@ -1,7 +1,7 @@ name: Windows Powershell Import Applocker Policy id: 102af98d-0ca3-4aa4-98d6-7ab2b98b955a -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -58,9 +58,7 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.001 - - T1059 - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_powershell_logoff_user_via_quser.yml b/detections/endpoint/windows_powershell_logoff_user_via_quser.yml index c22dd241a4..1e2d7ad33b 100644 --- a/detections/endpoint/windows_powershell_logoff_user_via_quser.yml +++ b/detections/endpoint/windows_powershell_logoff_user_via_quser.yml @@ -1,20 +1,26 @@ name: Windows Powershell Logoff User via Quser id: 6d70780d-4cfe-4820-bafd-1b43941986b5 -version: 1 -date: '2024-12-12' +version: 2 +date: '2025-02-10' author: Teoderick Contreras, Splunk data_source: - Powershell Script Block Logging 4104 type: Anomaly status: production -description: The following analytic detects the process of logging off a user through the use of the quser and logoff commands. By monitoring for these commands, the analytic identifies actions where a user session is forcibly terminated, which could be part of an administrative task or a potentially unauthorized access attempt. This detection helps identify potential misuse or malicious activity where a user’s access is revoked without proper authorization, providing insight into potential security incidents involving account management or session manipulation. -search: '`powershell` EventCode=4104 ScriptBlockText = "*quser*logoff*" - | stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText UserID Computer - | rename Computer as dest, UserID as user - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `windows_powershell_logoff_user_via_quser_filter`' -how_to_implement: The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. +description: The following analytic detects the process of logging off a user through + the use of the quser and logoff commands. By monitoring for these commands, the + analytic identifies actions where a user session is forcibly terminated, which could + be part of an administrative task or a potentially unauthorized access attempt. + This detection helps identify potential misuse or malicious activity where a user’s + access is revoked without proper authorization, providing insight into potential + security incidents involving account management or session manipulation. +search: '`powershell` EventCode=4104 ScriptBlockText = "*quser*logoff*" | stats count + min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText UserID + Computer | rename Computer as dest, UserID as user | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `windows_powershell_logoff_user_via_quser_filter`' +how_to_implement: The following Hunting analytic requires PowerShell operational logs + to be imported. Modify the powershell macro as needed to match the sourcetype or + add index. This analytic is specific to 4104, or PowerShell Script Block Logging. known_false_positives: Administrators or power users may use this command. references: - https://devblogs.microsoft.com/scripting/automating-quser-through-powershell/ @@ -24,11 +30,17 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: Powershell process having commandline [$ScriptBlockText$] used to logoff user on [$dest$]. + message: Powershell process having commandline [$ScriptBlockText$] used to logoff + user on [$dest$]. risk_objects: - field: dest type: system @@ -39,9 +51,8 @@ tags: - Crypto Stealer asset_type: Endpoint mitre_attack_id: - - T1531 - T1059.001 - - T1059 + - T1531 product: - Splunk Enterprise - Splunk Enterprise Security @@ -50,6 +61,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/log_off_user/pwh_quser_logoff.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/log_off_user/pwh_quser_logoff.log source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_powershell_remotesigned_file.yml b/detections/endpoint/windows_powershell_remotesigned_file.yml index 64bd011024..63df593e37 100644 --- a/detections/endpoint/windows_powershell_remotesigned_file.yml +++ b/detections/endpoint/windows_powershell_remotesigned_file.yml @@ -1,7 +1,7 @@ name: Windows Powershell RemoteSigned File id: f7f7456b-470d-4a95-9703-698250645ff4 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.001 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_powershell_scheduletask.yml b/detections/endpoint/windows_powershell_scheduletask.yml index 2cb840930a..0aaa0d5614 100644 --- a/detections/endpoint/windows_powershell_scheduletask.yml +++ b/detections/endpoint/windows_powershell_scheduletask.yml @@ -1,7 +1,7 @@ name: Windows PowerShell ScheduleTask id: ddf82fcb-e9ee-40e3-8712-a50b5bf323fc -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -65,7 +65,6 @@ tags: mitre_attack_id: - T1053.005 - T1059.001 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_powershell_wmi_win32_scheduledjob.yml b/detections/endpoint/windows_powershell_wmi_win32_scheduledjob.yml index 358d2f9f2c..4ec8982c98 100644 --- a/detections/endpoint/windows_powershell_wmi_win32_scheduledjob.yml +++ b/detections/endpoint/windows_powershell_wmi_win32_scheduledjob.yml @@ -1,7 +1,7 @@ name: Windows PowerShell WMI Win32 ScheduledJob id: 47c69803-2c09-408b-b40a-063c064cbb16 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk type: TTP status: production @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.001 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_powersploit_gpp_discovery.yml b/detections/endpoint/windows_powersploit_gpp_discovery.yml index c0bc3bffb3..cdd8803bc9 100644 --- a/detections/endpoint/windows_powersploit_gpp_discovery.yml +++ b/detections/endpoint/windows_powersploit_gpp_discovery.yml @@ -1,7 +1,7 @@ name: Windows PowerSploit GPP Discovery id: 0130a0df-83a1-4647-9011-841e950ff302 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: - Active Directory Privilege Escalation asset_type: Endpoint mitre_attack_id: - - T1552 - T1552.006 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_powerview_kerberos_service_ticket_request.yml b/detections/endpoint/windows_powerview_kerberos_service_ticket_request.yml index 77bff74777..0fa3ee8fe5 100644 --- a/detections/endpoint/windows_powerview_kerberos_service_ticket_request.yml +++ b/detections/endpoint/windows_powerview_kerberos_service_ticket_request.yml @@ -1,7 +1,7 @@ name: Windows PowerView Kerberos Service Ticket Request id: 970455a1-4ac2-47e1-a9a5-9e75443ddcb9 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Rhysida Ransomware asset_type: Endpoint mitre_attack_id: - - T1558 - T1558.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_powerview_spn_discovery.yml b/detections/endpoint/windows_powerview_spn_discovery.yml index a3184c2941..8abe7becab 100644 --- a/detections/endpoint/windows_powerview_spn_discovery.yml +++ b/detections/endpoint/windows_powerview_spn_discovery.yml @@ -1,7 +1,7 @@ name: Windows PowerView SPN Discovery id: a7093c28-796c-4ebb-9997-e2c18b870837 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Active Directory Kerberos Attacks asset_type: Endpoint mitre_attack_id: - - T1558 - T1558.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_private_keys_discovery.yml b/detections/endpoint/windows_private_keys_discovery.yml index 27fffec337..74c47622aa 100644 --- a/detections/endpoint/windows_private_keys_discovery.yml +++ b/detections/endpoint/windows_private_keys_discovery.yml @@ -1,7 +1,7 @@ name: Windows Private Keys Discovery id: 5c1c2877-06c0-40ee-a1a2-db71f1372b5b -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -70,7 +70,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.004 - - T1552 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_privilege_escalation_suspicious_process_elevation.yml b/detections/endpoint/windows_privilege_escalation_suspicious_process_elevation.yml index 6b4490c90e..c94417e9e5 100644 --- a/detections/endpoint/windows_privilege_escalation_suspicious_process_elevation.yml +++ b/detections/endpoint/windows_privilege_escalation_suspicious_process_elevation.yml @@ -1,6 +1,6 @@ name: Windows Privilege Escalation Suspicious Process Elevation id: 6a80300a-9f8a-4f22-bd3e-09ca577cfdfc -version: 4 +version: 5 date: '2024-11-13' author: Steven Dick status: production diff --git a/detections/endpoint/windows_process_executed_from_removable_media.yml b/detections/endpoint/windows_process_executed_from_removable_media.yml new file mode 100644 index 0000000000..6e3b66300b --- /dev/null +++ b/detections/endpoint/windows_process_executed_from_removable_media.yml @@ -0,0 +1,81 @@ +name: Windows Process Executed From Removable Media +id: b483804a-4cc0-49a4-9f00-ac29ba844d08 +version: 1 +date: '2025-01-17' +author: Steven Dick +status: production +type: Anomaly +description: This analytic is used to identify when a removable media device is attached to a machine and then a process is executed from the same drive letter assigned to the removable media device. Adversaries and Insider Threats may use removable media devices for several malicious activities, including initial access, execution, and exfiltration. +data_source: +- Windows Security Event ID 4688 +- Sysmon Event ID 1 +- Sysmon Event ID 12 +- Sysmon Event ID 13 +- CrowdStrike ProcessRollup2 +search: |- + | tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_current_directory=* AND NOT Processes.process_current_directory IN ("C:\\*","*\\sysvol\\*") by Processes.dest Processes.user Processes.process_name Processes.parent_process_name Processes.process_current_directory + | `drop_dm_object_name(Processes)` + | rex field=process_current_directory "^(?[^\\\]+\\\)" + | where isnotnull(object_handle) + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | join dest,object_handle + [| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_value_data="*:\\*" AND Registry.registry_path="*USBSTOR*" AND Registry.registry_path IN ("HKLM\\SOFTWARE\\Microsoft\\Windows Portable Devices\\Devices\\*","HKLM\\System\\CurrentControlSet\\Enum\\SWD\\WPDBUSENUM\\*") by Registry.dest,Registry.registry_value_data,Registry.registry_path + | `drop_dm_object_name(Registry)` + | eval object_handle = registry_value_data, object_name = replace(mvindex(split(mvindex(split(registry_path, "??"),1),"&"),2),"PROD_","") + ] + | `windows_process_executed_from_removable_media_filter` +how_to_implement: To successfully implement this search, you must ingest endpoint logging that tracks changes to the HKLM\SOFTWARE\Microsoft\Windows Portable Devices\Devices\ or HKLM\System\CurrentControlSet\Enum\SWD\WPDBUSENUM\ registry keys as well as Process Execution commands. Ensure that the field from the event logs is being mapped to the proper fields in the Endpoint.Registry data model. This analytic joins the Process and Registry datamodels together based on the drive letter extract to the "object_handle" field from both datasets. +known_false_positives: Legitimate USB activity will also be detected. Please verify and investigate as appropriate. +references: +- https://attack.mitre.org/techniques/T1200/ +- https://www.cisa.gov/news-events/news/using-caution-usb-drives +- https://www.bleepingcomputer.com/news/security/fbi-hackers-use-badusb-to-target-defense-firms-with-ransomware/ +drilldown_searches: +- name: View the detection results for - "$dest$" and "$user$" + search: '%original_detection_search% | search dest = "$dest$" and user= "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" and "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$" , "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: Investigate USB events on $dest$ + search: '| from datamodel:Endpoint.Processes | search dest=$dest$ process_current_directory=$object_handle$*' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The process [$process_name$] was launched using files on a removable storage device named [$object_name$] by [$user$] on $dest$ + risk_objects: + - field: user + type: user + score: 35 + - field: dest + type: system + score: 35 + threat_objects: + - field: process_name + type: process_name + - field: object_name + type: registry_value_name + - field: object_handle + type: registry_value_text +tags: + analytic_story: + - Data Protection + asset_type: Endpoint + mitre_attack_id: + - T1200 + - T1025 + - T1091 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1200/sysmon_usb_use_execution/sysmon_usb_use_execution.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_process_execution_in_temp_dir.yml b/detections/endpoint/windows_process_execution_in_temp_dir.yml new file mode 100644 index 0000000000..c8909b0013 --- /dev/null +++ b/detections/endpoint/windows_process_execution_in_temp_dir.yml @@ -0,0 +1,87 @@ +name: Windows Process Execution in Temp Dir +id: f6fbe929-4187-4ba4-901e-8a34be838443 +version: 1 +date: '2025-01-27' +author: Teoderick Contreras, Splunk +status: production +type: Anomaly +description: The following analytic identifies processes running from %temp% directory file paths. + It leverages data from Endpoint Detection and Response (EDR) agents, focusing on specific process paths within the Endpoint + data model. This activity is significant because adversaries often use unconventional file paths to execute malicious code without requiring administrative privileges. If confirmed malicious, this behavior could indicate an attempt to bypass security controls, leading to unauthorized software execution, potential system compromise, and further malicious activities within the environment. +data_source: +- Sysmon EventID 1 +- Windows Event Log Security 4688 +- CrowdStrike ProcessRollup2 +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where Processes.process_path IN("*\\temp\\*") + by Processes.parent_process_name Processes.parent_process Processes.process_path Processes.dest Processes.user + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_process_execution_in_temp_dir_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. +known_false_positives: Administrators may allow execution of specific binaries in + non-standard paths. Filter as needed. +references: +- https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/ +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ +- https://twitter.com/pr0xylife/status/1590394227758104576 +- https://malpedia.caad.fkie.fraunhofer.de/details/win.asyncrat +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ +drilldown_searches: +- name: View the detection results for - "$dest$" + search: '%original_detection_search% | search dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: Suspicious process $process_name$ running from temp directory- + $process_path$ on host- $dest$ + risk_objects: + - field: dest + type: system + score: 30 + threat_objects: + - field: process_path + type: process_name +tags: + analytic_story: + - Ryuk Ransomware + - Trickbot + - Qakbot + - AgentTesla + - Remcos + - NjRAT + - Ransomware + asset_type: Endpoint + mitre_attack_id: + - T1543 + - T1036.005 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/process_temp_path/process_temp_path.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_process_injection_into_notepad.yml b/detections/endpoint/windows_process_injection_into_notepad.yml index 6e1e86e9f8..8a4a772575 100644 --- a/detections/endpoint/windows_process_injection_into_notepad.yml +++ b/detections/endpoint/windows_process_injection_into_notepad.yml @@ -1,7 +1,7 @@ name: Windows Process Injection into Notepad id: b8340d0f-ba48-4391-bea7-9e793c5aae36 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk type: Anomaly status: production @@ -61,7 +61,6 @@ tags: - BishopFox Sliver Adversary Emulation Framework asset_type: Endpoint mitre_attack_id: - - T1055 - T1055.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml b/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml index 7ca8139ceb..4c35239780 100644 --- a/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml +++ b/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml @@ -1,7 +1,7 @@ name: Windows Process Injection Of Wermgr to Known Browser id: aec755a5-3a2c-4be0-ab34-6540e68644e9 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1055.001 - - T1055 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_process_injection_remote_thread.yml b/detections/endpoint/windows_process_injection_remote_thread.yml index acb2c928e0..48d56aec9f 100644 --- a/detections/endpoint/windows_process_injection_remote_thread.yml +++ b/detections/endpoint/windows_process_injection_remote_thread.yml @@ -1,7 +1,7 @@ name: Windows Process Injection Remote Thread id: 8a618ade-ca8f-4d04-b972-2d526ba59924 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - Warzone RAT asset_type: Endpoint mitre_attack_id: - - T1055 - T1055.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_process_injection_with_public_source_path.yml b/detections/endpoint/windows_process_injection_with_public_source_path.yml index 6ff6638edb..3034d4db52 100644 --- a/detections/endpoint/windows_process_injection_with_public_source_path.yml +++ b/detections/endpoint/windows_process_injection_with_public_source_path.yml @@ -1,7 +1,7 @@ name: Windows Process Injection With Public Source Path id: 492f09cf-5d60-4d87-99dd-0bc325532dda -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -33,7 +33,6 @@ tags: - Brute Ratel C4 asset_type: Endpoint mitre_attack_id: - - T1055 - T1055.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_process_with_netexec_command_line_parameters.yml b/detections/endpoint/windows_process_with_netexec_command_line_parameters.yml index 578832eea3..82eb5c76bd 100644 --- a/detections/endpoint/windows_process_with_netexec_command_line_parameters.yml +++ b/detections/endpoint/windows_process_with_netexec_command_line_parameters.yml @@ -1,70 +1,68 @@ -name: Windows Process With NetExec Command Line Parameters -id: adbff89c-c1f2-4a2e-88a4-b5e645856510 -version: 2 -date: '2025-01-09' -author: Steven Dick, Github Community -status: production -type: TTP -description: The following analytic detects the use of NetExec (formally CrackmapExec) a toolset used for post-exploitation enumeration and attack within Active Directory environments through command line parameters. It leverages Endpoint Detection and Response (EDR) data to identify specific command-line arguments associated with actions like ticket manipulation, kerberoasting, and password spraying. This activity is significant as NetExec is used by adversaries to exploit Kerberos for privilege escalation and lateral movement. If confirmed malicious, this could lead to unauthorized access, persistence, and potential compromise of sensitive information within the network. -data_source: -- Windows Security Event ID 4688 -- Sysmon Event ID 1 -- CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` values(Processes.parent_process) as Processes.parent_process, values(Processes.process) as Processes.process values(Processes.process_current_directory) AS process_current_directory, values(Processes.process_id) as Processes.process_id, values(Processes.process_guid) as Processes.process_guid, count min(_time) AS firstTime, max(_time) AS lastTime FROM datamodel=Endpoint.Processes where Processes.process_name IN ("nxc.exe") OR Processes.original_file_name IN ("nxc.exe") OR (Processes.process IN ("* smb *","* ssh *","* ldap *","* ftp *","* wmi *","* winrm *","* rdp *","* vnc *","* mssql *","* nfs *") AND ((Processes.process = "* -p *" AND Processes.process = "* -u *") OR Processes.process IN ("* -x *","* -M *","* --*"))) BY _time span=1h Processes.user Processes.dest Processes.process_name Processes.parent_process_name -|`drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_process_with_netexec_command_line_parameters_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: Although unlikely, legitimate applications may use the same command line parameters as NetExec. Filter as needed. -references: -- https://www.netexec.wiki/ -- https://www.johnvictorwolfe.com/2024/07/21/the-successor-to-crackmapexec/ -- https://attack.mitre.org/software/S0488/ -drilldown_searches: -- name: View the detection results for - "$dest$" and "$user$" - search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' - earliest_offset: $info_min_time$ - latest_offset: $info_max_time$ -- name: View risk events for the last 7 days for - "$dest$" and "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$","$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' - earliest_offset: $info_min_time$ - latest_offset: $info_max_time$ -- name: Investigate processes on $dest$ - search: '| from datamodel:Endpoint.Processes | search dest=$dest$ process_name = $process_name$' - earliest_offset: $info_min_time$ - latest_offset: $info_max_time$ -rba: - message: NetExec command line parameters were used on $dest$ by $user$ - risk_objects: - - field: user - type: user - score: 64 - - field: dest - type: system - score: 64 - threat_objects: - - field: parent_process_name - type: parent_process_name -tags: - analytic_story: - - Active Directory Kerberos Attacks - - Active Directory Privilege Escalation - asset_type: Endpoint - mitre_attack_id: - - T1550 - - T1550.003 - - T1558 - - T1558.003 - - T1558.004 - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - security_domain: endpoint -tests: -- name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550/netexec_toolkit_usage/netexec_toolkit_usage.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog +name: Windows Process With NetExec Command Line Parameters +id: adbff89c-c1f2-4a2e-88a4-b5e645856510 +version: 3 +date: '2025-02-11' +author: Steven Dick, Github Community +status: production +type: TTP +description: The following analytic detects the use of NetExec (formally CrackmapExec) a toolset used for post-exploitation enumeration and attack within Active Directory environments through command line parameters. It leverages Endpoint Detection and Response (EDR) data to identify specific command-line arguments associated with actions like ticket manipulation, kerberoasting, and password spraying. This activity is significant as NetExec is used by adversaries to exploit Kerberos for privilege escalation and lateral movement. If confirmed malicious, this could lead to unauthorized access, persistence, and potential compromise of sensitive information within the network. +data_source: +- Windows Security Event ID 4688 +- Sysmon EventID 1 +- CrowdStrike ProcessRollup2 +search: '| tstats `security_content_summariesonly` values(Processes.parent_process) as Processes.parent_process, values(Processes.process) as Processes.process values(Processes.process_current_directory) AS process_current_directory, values(Processes.process_id) as Processes.process_id, values(Processes.process_guid) as Processes.process_guid, count min(_time) AS firstTime, max(_time) AS lastTime FROM datamodel=Endpoint.Processes where Processes.process_name IN ("nxc.exe") OR Processes.original_file_name IN ("nxc.exe") OR (Processes.process IN ("* smb *","* ssh *","* ldap *","* ftp *","* wmi *","* winrm *","* rdp *","* vnc *","* mssql *","* nfs *") AND ((Processes.process = "* -p *" AND Processes.process = "* -u *") OR Processes.process IN ("* -x *","* -M *","* --*"))) BY _time span=1h Processes.user Processes.dest Processes.process_name Processes.parent_process_name +|`drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `windows_process_with_netexec_command_line_parameters_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +known_false_positives: Although unlikely, legitimate applications may use the same command line parameters as NetExec. Filter as needed. +references: +- https://www.netexec.wiki/ +- https://www.johnvictorwolfe.com/2024/07/21/the-successor-to-crackmapexec/ +- https://attack.mitre.org/software/S0488/ +drilldown_searches: +- name: View the detection results for - "$dest$" and "$user$" + search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" and "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$","$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: Investigate processes on $dest$ + search: '| from datamodel:Endpoint.Processes | search dest=$dest$ process_name = $process_name$' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: NetExec command line parameters were used on $dest$ by $user$ + risk_objects: + - field: user + type: user + score: 64 + - field: dest + type: system + score: 64 + threat_objects: + - field: parent_process_name + type: parent_process_name +tags: + analytic_story: + - Active Directory Kerberos Attacks + - Active Directory Privilege Escalation + asset_type: Endpoint + mitre_attack_id: + - T1550.003 + - T1558.003 + - T1558.004 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550/netexec_toolkit_usage/netexec_toolkit_usage.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_protocol_tunneling_with_plink.yml b/detections/endpoint/windows_protocol_tunneling_with_plink.yml index 3a6481da48..b55caf7791 100644 --- a/detections/endpoint/windows_protocol_tunneling_with_plink.yml +++ b/detections/endpoint/windows_protocol_tunneling_with_plink.yml @@ -1,6 +1,6 @@ name: Windows Protocol Tunneling with Plink id: 8aac5e1e-0fab-4437-af0b-c6e60af23eed -version: 6 +version: 7 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_proxy_via_netsh.yml b/detections/endpoint/windows_proxy_via_netsh.yml index 66dcbfa6da..639a557efe 100644 --- a/detections/endpoint/windows_proxy_via_netsh.yml +++ b/detections/endpoint/windows_proxy_via_netsh.yml @@ -1,7 +1,7 @@ name: Windows Proxy Via Netsh id: c137bfe8-6036-4cff-b77b-4e327dd0a1cf -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -71,7 +71,6 @@ tags: - b8223ea9-4be2-44a6-b50a-9657a3d4e72a mitre_attack_id: - T1090.001 - - T1090 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_proxy_via_registry.yml b/detections/endpoint/windows_proxy_via_registry.yml index df29fba982..ab99e0cb4e 100644 --- a/detections/endpoint/windows_proxy_via_registry.yml +++ b/detections/endpoint/windows_proxy_via_registry.yml @@ -1,7 +1,7 @@ name: Windows Proxy Via Registry id: 0270455b-1385-4579-9ac5-e77046c508ae -version: 5 -date: '2024-12-16' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: - b8223ea9-4be2-44a6-b50a-9657a3d4e72a mitre_attack_id: - T1090.001 - - T1090 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_raccine_scheduled_task_deletion.yml b/detections/endpoint/windows_raccine_scheduled_task_deletion.yml index 4c61efa0c7..9e419ace18 100644 --- a/detections/endpoint/windows_raccine_scheduled_task_deletion.yml +++ b/detections/endpoint/windows_raccine_scheduled_task_deletion.yml @@ -1,6 +1,6 @@ name: Windows Raccine Scheduled Task Deletion id: c9f010da-57ab-11ec-82bd-acde48001122 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_rasautou_dll_execution.yml b/detections/endpoint/windows_rasautou_dll_execution.yml index f04f743ef0..8e15a67174 100644 --- a/detections/endpoint/windows_rasautou_dll_execution.yml +++ b/detections/endpoint/windows_rasautou_dll_execution.yml @@ -1,7 +1,7 @@ name: Windows Rasautou DLL Execution id: 6f42b8be-8e96-11ec-ad5a-acde48001122 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: mitre_attack_id: - T1055.001 - T1218 - - T1055 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml b/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml index d6193ca528..b12079e3c2 100644 --- a/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml +++ b/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml @@ -1,7 +1,7 @@ name: Windows Raw Access To Disk Volume Partition id: a85aa37e-9647-11ec-90c5-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -23,8 +23,9 @@ how_to_implement: To successfully implement this search, you need to be ingestin logs with the raw access read event (like sysmon eventcode 9), process name and process guid from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. -known_false_positives: There are som minimal number of normal applications from system32 folder like svchost.exe accessing the MBR. In this - case we used 'system32' and 'syswow64' path as a filter for this detection. +known_false_positives: There are som minimal number of normal applications from system32 + folder like svchost.exe accessing the MBR. In this case we used 'system32' and 'syswow64' + path as a filter for this detection. references: - https://blog.talosintelligence.com/2022/02/threat-advisory-hermeticwiper.html drilldown_searches: @@ -60,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1561.002 - - T1561 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml b/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml index 3692033d81..a689fa523f 100644 --- a/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml +++ b/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml @@ -1,7 +1,7 @@ name: Windows Raw Access To Master Boot Record Drive id: 7b83f666-900c-11ec-a2d9-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -23,8 +23,9 @@ how_to_implement: To successfully implement this search, you need to be ingestin logs with the raw access read event (like sysmon eventcode 9), process name and process guid from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. -known_false_positives: There are som minimal number of normal applications from system32 folder like svchost.exe accessing the MBR. In this - case we used 'system32' and 'syswow64' path as a filter for this detection. +known_false_positives: There are som minimal number of normal applications from system32 + folder like svchost.exe accessing the MBR. In this case we used 'system32' and 'syswow64' + path as a filter for this detection. references: - https://www.splunk.com/en_us/blog/security/threat-advisory-strt-ta02-destructive-software.html - https://www.crowdstrike.com/blog/technical-analysis-of-whispergate-malware/ @@ -63,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1561.002 - - T1561 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_registry_certificate_added.yml b/detections/endpoint/windows_registry_certificate_added.yml index 2781d73827..f8c97ce6b7 100644 --- a/detections/endpoint/windows_registry_certificate_added.yml +++ b/detections/endpoint/windows_registry_certificate_added.yml @@ -1,7 +1,7 @@ name: Windows Registry Certificate Added id: 5ee98b2f-8b9e-457a-8bdc-dd41aaba9e87 -version: 6 -date: '2025-01-21' +version: 7 +date: '2025-02-10' author: Michael Haag, Teodeerick Contreras, Splunk status: production type: Anomaly @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1553.004 - - T1553 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_registry_dotnet_etw_disabled_via_env_variable.yml b/detections/endpoint/windows_registry_dotnet_etw_disabled_via_env_variable.yml index d938db4eac..5e2ddf9fce 100644 --- a/detections/endpoint/windows_registry_dotnet_etw_disabled_via_env_variable.yml +++ b/detections/endpoint/windows_registry_dotnet_etw_disabled_via_env_variable.yml @@ -1,7 +1,7 @@ name: Windows Registry Dotnet ETW Disabled Via ENV Variable id: 55502381-5cce-491b-9277-7cb1d10bc0df -version: 2 -date: '2025-01-07' +version: 4 +date: '2025-02-10' author: Nasreddine Bencherchali, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.006 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_registry_modification_for_safe_mode_persistence.yml b/detections/endpoint/windows_registry_modification_for_safe_mode_persistence.yml index fbd1a12913..7a88c95d54 100644 --- a/detections/endpoint/windows_registry_modification_for_safe_mode_persistence.yml +++ b/detections/endpoint/windows_registry_modification_for_safe_mode_persistence.yml @@ -1,7 +1,7 @@ name: Windows Registry Modification for Safe Mode Persistence id: c6149154-c9d8-11eb-9da7-acde48001122 -version: 8 -date: '2025-01-21' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Michael Haag, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.001 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_registry_payload_injection.yml b/detections/endpoint/windows_registry_payload_injection.yml index 9a2dcd0047..e798fc114f 100644 --- a/detections/endpoint/windows_registry_payload_injection.yml +++ b/detections/endpoint/windows_registry_payload_injection.yml @@ -1,7 +1,7 @@ name: Windows Registry Payload Injection id: c6b2d80f-179a-41a1-b95e-ce5601d7427a -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -77,7 +77,6 @@ tags: - Unusual Processes asset_type: Endpoint mitre_attack_id: - - T1027 - T1027.011 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_regsvr32_renamed_binary.yml b/detections/endpoint/windows_regsvr32_renamed_binary.yml index 64e9e406e3..53b64d87dd 100644 --- a/detections/endpoint/windows_regsvr32_renamed_binary.yml +++ b/detections/endpoint/windows_regsvr32_renamed_binary.yml @@ -1,7 +1,7 @@ name: Windows Regsvr32 Renamed Binary id: 7349a9e9-3cf6-4171-bb0c-75607a8dcd1a -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.010 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_remote_assistance_spawning_process.yml b/detections/endpoint/windows_remote_assistance_spawning_process.yml index 90cb689064..e6810e6c34 100644 --- a/detections/endpoint/windows_remote_assistance_spawning_process.yml +++ b/detections/endpoint/windows_remote_assistance_spawning_process.yml @@ -1,6 +1,6 @@ name: Windows Remote Assistance Spawning Process id: ced50492-8849-11ec-9f68-acde48001122 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_remote_create_service.yml b/detections/endpoint/windows_remote_create_service.yml index 93c28d5380..ffa6ead077 100644 --- a/detections/endpoint/windows_remote_create_service.yml +++ b/detections/endpoint/windows_remote_create_service.yml @@ -1,7 +1,7 @@ name: Windows Remote Create Service id: 0dc44d03-8c00-482d-ba7c-796ba7ab18c9 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -72,7 +72,6 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1543 - T1543.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml b/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml index 73d240c71e..780c0b7854 100644 --- a/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml +++ b/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml @@ -1,7 +1,7 @@ name: Windows Remote Service Rdpwinst Tool Execution id: c8127f87-c7c9-4036-89ed-8fe4b30e678c -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.001 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml b/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml index 01e73f560f..52c5aed5a0 100644 --- a/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml +++ b/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml @@ -1,7 +1,7 @@ name: Windows Remote Services Allow Rdp In Firewall id: 9170cb54-ea15-41e1-9dfc-9f3363ce9b02 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.001 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_remote_services_allow_remote_assistance.yml b/detections/endpoint/windows_remote_services_allow_remote_assistance.yml index 39dfcd8333..4f5028aa36 100644 --- a/detections/endpoint/windows_remote_services_allow_remote_assistance.yml +++ b/detections/endpoint/windows_remote_services_allow_remote_assistance.yml @@ -1,7 +1,7 @@ name: Windows Remote Services Allow Remote Assistance id: 9bce3a97-bc97-4e89-a1aa-ead151c82fbb -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.001 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_remote_services_rdp_enable.yml b/detections/endpoint/windows_remote_services_rdp_enable.yml index db44d18d43..16dc4dcfb1 100644 --- a/detections/endpoint/windows_remote_services_rdp_enable.yml +++ b/detections/endpoint/windows_remote_services_rdp_enable.yml @@ -1,7 +1,7 @@ name: Windows Remote Services Rdp Enable id: 8fbd2e88-4ea5-40b9-9217-fd0855e08cc0 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.001 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_root_domain_linked_policies_discovery.yml b/detections/endpoint/windows_root_domain_linked_policies_discovery.yml index f006024e2d..b4b40d775a 100644 --- a/detections/endpoint/windows_root_domain_linked_policies_discovery.yml +++ b/detections/endpoint/windows_root_domain_linked_policies_discovery.yml @@ -1,7 +1,7 @@ name: Windows Root Domain linked policies Discovery id: 80ffaede-1f12-49d5-a86e-b4b599b68b3c -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_rundll32_apply_user_settings_changes.yml b/detections/endpoint/windows_rundll32_apply_user_settings_changes.yml index 711d2c152e..f1c867ecd3 100644 --- a/detections/endpoint/windows_rundll32_apply_user_settings_changes.yml +++ b/detections/endpoint/windows_rundll32_apply_user_settings_changes.yml @@ -1,7 +1,7 @@ name: Windows Rundll32 Apply User Settings Changes id: b9fb8d97-dbc9-4a09-804c-ff0e3862bb2d -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: - Rhysida Ransomware asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_rundll32_webdav_request.yml b/detections/endpoint/windows_rundll32_webdav_request.yml index ce111cff26..68ccb04ab4 100644 --- a/detections/endpoint/windows_rundll32_webdav_request.yml +++ b/detections/endpoint/windows_rundll32_webdav_request.yml @@ -1,6 +1,6 @@ name: Windows Rundll32 WebDAV Request id: 320099b7-7eb1-4153-a2b4-decb53267de2 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk type: TTP diff --git a/detections/endpoint/windows_rundll32_webdav_with_network_connection.yml b/detections/endpoint/windows_rundll32_webdav_with_network_connection.yml index de78c6f02b..8ef7992823 100644 --- a/detections/endpoint/windows_rundll32_webdav_with_network_connection.yml +++ b/detections/endpoint/windows_rundll32_webdav_with_network_connection.yml @@ -1,6 +1,6 @@ name: Windows Rundll32 WebDav With Network Connection id: f03355e0-28b5-4e9b-815a-6adffc63b38c -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk type: TTP diff --git a/detections/endpoint/windows_scheduled_task_created_via_xml.yml b/detections/endpoint/windows_scheduled_task_created_via_xml.yml index b29963f952..0a239e80fc 100644 --- a/detections/endpoint/windows_scheduled_task_created_via_xml.yml +++ b/detections/endpoint/windows_scheduled_task_created_via_xml.yml @@ -1,7 +1,7 @@ name: Windows Scheduled Task Created Via XML id: 7e03b682-3965-4598-8e91-a60a40a3f7e4 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.005 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_scheduled_task_with_highest_privileges.yml b/detections/endpoint/windows_scheduled_task_with_highest_privileges.yml index 2111e93ad4..0cb70faff7 100644 --- a/detections/endpoint/windows_scheduled_task_with_highest_privileges.yml +++ b/detections/endpoint/windows_scheduled_task_with_highest_privileges.yml @@ -1,7 +1,7 @@ name: Windows Scheduled Task with Highest Privileges id: 2f15e1a4-0fc2-49dd-919e-cbbe60699218 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -68,7 +68,6 @@ tags: - RedLine Stealer asset_type: Endpoint mitre_attack_id: - - T1053 - T1053.005 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_schtasks_create_run_as_system.yml b/detections/endpoint/windows_schtasks_create_run_as_system.yml index 0803309dab..bb349b102f 100644 --- a/detections/endpoint/windows_schtasks_create_run_as_system.yml +++ b/detections/endpoint/windows_schtasks_create_run_as_system.yml @@ -1,7 +1,7 @@ name: Windows Schtasks Create Run As System id: 41a0e58e-884c-11ec-9976-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.005 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_security_and_backup_services_stop.yml b/detections/endpoint/windows_security_and_backup_services_stop.yml new file mode 100644 index 0000000000..47e8f2e8cf --- /dev/null +++ b/detections/endpoint/windows_security_and_backup_services_stop.yml @@ -0,0 +1,78 @@ +name: Windows Security And Backup Services Stop +id: 9c24aef6-cad9-4931-acce-74318aa5663b +version: 1 +date: '2025-02-07' +author: Teoderick Contreras, Splunk +status: production +type: TTP +description: The following analytic detects the suspicious termination of known services + commonly targeted by ransomware before file encryption. It leverages Windows System + Event Logs (EventCode 7036) to identify when critical services such as Volume Shadow + Copy, backup, and antivirus services are stopped. This activity is significant because + ransomware often disables these services to avoid errors and ensure successful file + encryption. If confirmed malicious, this behavior could lead to widespread data + encryption, rendering files inaccessible and potentially causing significant operational + disruption and data loss. +data_source: +- Windows Event Log System 7036 +search: '`wineventlog_system` `normalized_service_binary_field` + | rename param1 as display_name + | where param2="stopped" AND (match(display_name, "(?i)(Volume Shadow Copy|VSS|backup|sophos|sql|memtas|mepocs|veeam|svc\$|DefWatch|ccEvtMgr|ccSetMgr|SavRoam|RTVscan|QBFCService|QBIDPService|Intuit\.QuickBooks\.FCS|QBCFMonitorService|YooBackup|YooIT|Veeam|PDVFSService|BackupExec|WdBoot|WdFilter|WdNisDrv|WdNisSvc|WinDefend|wscsvc|Sense|sppsvc|SecurityHealthService)") + OR match(normalized_service_name, "(?i)(Volume Shadow Copy|VSS|backup|sophos|sql|memtas|mepocs|veeam|svc\$|DefWatch|ccEvtMgr|ccSetMgr|SavRoam|RTVscan|QBFCService|QBIDPService|Intuit\.QuickBooks\.FCS|QBCFMonitorService|YooBackup|YooIT|Veeam|PDVFSService|BackupExec|WdBoot|WdFilter|WdNisDrv|WdNisSvc|WinDefend|wscsvc|Sense|sppsvc|SecurityHealthService)")) + | stats count min(_time) as firstTime max(_time) as lastTime by EventCode display_name dest normalized_service_name + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_security_and_backup_services_stop_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the 7036 EventCode ScManager in System audit Logs from your endpoints. +known_false_positives: Admin activities or installing related updates may do a sudden + stop to list of services we monitor. +references: +- https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/ +- https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/ +- https://news.sophos.com/en-us/2020/04/24/lockbit-ransomware-borrows-tricks-to-keep-up-with-revil-and-maze/ +- https://blogs.vmware.com/security/2022/10/lockbit-3-0-also-known-as-lockbit-black.html +drilldown_searches: +- name: View the detection results for - "$dest$" + search: '%original_detection_search% | search dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: Known services $param1$ terminated by a potential ransomware on $dest$ + risk_objects: + - field: dest + type: system + score: 72 + threat_objects: + - field: display_name + type: service +tags: + analytic_story: + - LockBit Ransomware + - Ransomware + - Compromised Windows Host + - BlackMatter Ransomware + asset_type: Endpoint + mitre_attack_id: + - T1490 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/known_services_killed_by_ransomware/windows-xml.log + source: XmlWinEventLog:System + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_security_support_provider_reg_query.yml b/detections/endpoint/windows_security_support_provider_reg_query.yml index 1ec47ad04d..78ab163dc2 100644 --- a/detections/endpoint/windows_security_support_provider_reg_query.yml +++ b/detections/endpoint/windows_security_support_provider_reg_query.yml @@ -1,7 +1,7 @@ name: Windows Security Support Provider Reg Query id: 31302468-93c9-4eca-9ae3-2d41f53a4e2b -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.005 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_sensitive_group_discovery_with_net.yml b/detections/endpoint/windows_sensitive_group_discovery_with_net.yml index 6a7c924fe9..57b7d6e524 100644 --- a/detections/endpoint/windows_sensitive_group_discovery_with_net.yml +++ b/detections/endpoint/windows_sensitive_group_discovery_with_net.yml @@ -1,17 +1,39 @@ name: Windows Sensitive Group Discovery With Net id: d9eb7cda-5622-4722-bc88-7f2442f4b5af -version: 1 -date: '2025-01-13' +version: 2 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Anomaly -description: The following analytic detects the execution of `net.exe` with command-line arguments used to query elevated domain or sensitive groups. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions. This activity is significant as it indicates potential reconnaissance efforts by adversaries to identify high-privileged users within Active Directory. If confirmed malicious, this behavior could lead to further attacks aimed at compromising privileged accounts, escalating privileges, or gaining unauthorized access to sensitive systems and data. +description: The following analytic detects the execution of `net.exe` with command-line + arguments used to query elevated domain or sensitive groups. It leverages data from + Endpoint Detection and Response (EDR) agents, focusing on process names and command-line + executions. This activity is significant as it indicates potential reconnaissance + efforts by adversaries to identify high-privileged users within Active Directory. + If confirmed malicious, this behavior could lead to further attacks aimed at compromising + privileged accounts, escalating privileges, or gaining unauthorized access to sensitive + systems and data. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` Processes.process="*group*" Processes.process IN ("*Domain Admins*", "*Enterprise Admins*", "*Schema Admins*", "*Account Operators*", "*Server Operators*", "*Protected Users*", "*Dns Admins*", "*Domain Computers*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_sensitive_group_discovery_with_net_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_net` Processes.process="*group*" + Processes.process IN ("*Domain Admins*", "*Enterprise Admins*", "*Schema Admins*", + "*Account Operators*", "*Server Operators*", "*Protected Users*", "*Dns Admins*", + "*Domain Computers*") by Processes.dest Processes.user Processes.parent_process + Processes.process_name Processes.process Processes.process_id Processes.parent_process_id + | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `windows_sensitive_group_discovery_with_net_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. known_false_positives: Administrators or power users may use this command for troubleshooting. references: - https://attack.mitre.org/techniques/T1069/002/ @@ -25,7 +47,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -44,7 +71,6 @@ tags: - IcedID asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise @@ -54,6 +80,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_sensitive_registry_hive_dump_via_commandline.yml b/detections/endpoint/windows_sensitive_registry_hive_dump_via_commandline.yml index d8050741e3..fba9efd879 100644 --- a/detections/endpoint/windows_sensitive_registry_hive_dump_via_commandline.yml +++ b/detections/endpoint/windows_sensitive_registry_hive_dump_via_commandline.yml @@ -1,18 +1,41 @@ name: Windows Sensitive Registry Hive Dump Via CommandLine id: 5aaff29d-0cce-405b-9ee8-5d06b49d045e -version: 1 -date: '2025-01-15' +version: 3 +date: '2025-02-10' author: Michael Haag, Patrick Bareiss, Nasreddine Bencherchali, Splunk status: production type: TTP -description: The following analytic detects the use of `reg.exe` to export Windows Registry hives, which may contain sensitive credentials. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions involving `save` or `export` actions targeting the `sam`, `system`, or `security` hives. This activity is significant as it indicates potential offline credential access attacks, often executed from untrusted processes or scripts. If confirmed malicious, attackers could gain access to credential data, enabling further compromise and lateral movement within the network. +description: The following analytic detects the use of `reg.exe` to export Windows + Registry hives, which may contain sensitive credentials. This detection leverages + data from Endpoint Detection and Response (EDR) agents, focusing on command-line + executions involving `save` or `export` actions targeting the `sam`, `system`, or + `security` hives. This activity is significant as it indicates potential offline + credential access attacks, often executed from untrusted processes or scripts. If + confirmed malicious, attackers could gain access to credential data, enabling further + compromise and lateral movement within the network. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where ((`process_reg` Processes.process IN ("*save*", "*export*")) OR (`process_regedit` Processes.process IN ("*/E *", "*-E *"))) AND Processes.process IN ("*HKEY_LOCAL_MACHINE*", "*HKLM*") AND Processes.process IN ("*SAM*", "*System*", "*Security*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.parent_process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_sensitive_registry_hive_dump_via_commandline_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: It is possible some agent based products will generate false positives. Filter as needed. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where ((`process_reg` Processes.process + IN ("*save*", "*export*")) OR (`process_regedit` Processes.process IN ("*/E *", + "*-E *"))) AND Processes.process IN ("*HKEY_LOCAL_MACHINE*", "*HKLM*") AND Processes.process + IN ("*SAM*", "*System*", "*Security*") by Processes.dest Processes.user Processes.parent_process + Processes.process_name Processes.parent_process_name Processes.process Processes.process_id + Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `windows_sensitive_registry_hive_dump_via_commandline_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. +known_false_positives: It is possible some agent based products will generate false + positives. Filter as needed. references: - https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md @@ -23,7 +46,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$user$" and "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", + "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) + as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk + Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -53,7 +81,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.002 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security @@ -62,6 +89,7 @@ tags: tests: - name: True Positive Test - Sysmon attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_server_software_component_gacutil_install_to_gac.yml b/detections/endpoint/windows_server_software_component_gacutil_install_to_gac.yml index 64c9bcdd4f..f0baa10770 100644 --- a/detections/endpoint/windows_server_software_component_gacutil_install_to_gac.yml +++ b/detections/endpoint/windows_server_software_component_gacutil_install_to_gac.yml @@ -1,7 +1,7 @@ name: Windows Server Software Component GACUtil Install to GAC id: 7c025ef0-9e65-4c57-be39-1c13dbb1613e -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: - IIS Components asset_type: Endpoint mitre_attack_id: - - T1505 - T1505.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_service_create_kernel_mode_driver.yml b/detections/endpoint/windows_service_create_kernel_mode_driver.yml index a183f4a0d9..b9a59dae84 100644 --- a/detections/endpoint/windows_service_create_kernel_mode_driver.yml +++ b/detections/endpoint/windows_service_create_kernel_mode_driver.yml @@ -1,7 +1,7 @@ name: Windows Service Create Kernel Mode Driver id: 0b4e3b06-1b2b-4885-b752-cf06d12a90cb -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -67,9 +67,8 @@ tags: - CISA AA22-320A asset_type: Endpoint mitre_attack_id: - - T1543.003 - - T1543 - T1068 + - T1543.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_service_create_remcomsvc.yml b/detections/endpoint/windows_service_create_remcomsvc.yml index 23e3442fbb..642022aaff 100644 --- a/detections/endpoint/windows_service_create_remcomsvc.yml +++ b/detections/endpoint/windows_service_create_remcomsvc.yml @@ -1,7 +1,7 @@ name: Windows Service Create RemComSvc id: 0be4b5d6-c449-4084-b945-2392b519c33b -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk type: Anomaly status: production @@ -53,7 +53,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1543.003 - - T1543 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_service_create_sliverc2.yml b/detections/endpoint/windows_service_create_sliverc2.yml index 43a0ccd75b..d9279cedf9 100644 --- a/detections/endpoint/windows_service_create_sliverc2.yml +++ b/detections/endpoint/windows_service_create_sliverc2.yml @@ -1,7 +1,7 @@ name: Windows Service Create SliverC2 id: 89dad3ee-57ec-43dc-9044-131c4edd663f -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk type: TTP status: production @@ -53,7 +53,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1569 - T1569.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_service_create_with_tscon.yml b/detections/endpoint/windows_service_create_with_tscon.yml index 150f198cc2..747300e74b 100644 --- a/detections/endpoint/windows_service_create_with_tscon.yml +++ b/detections/endpoint/windows_service_create_with_tscon.yml @@ -1,7 +1,7 @@ name: Windows Service Create with Tscon id: c13b3d74-6b63-4db5-a841-4206f0370077 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk type: TTP status: production @@ -81,9 +81,8 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1563.002 - - T1563 - T1543.003 + - T1563.002 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_service_created_with_suspicious_service_path.yml b/detections/endpoint/windows_service_created_with_suspicious_service_path.yml index 9dfedd34e8..d87ac0bdb8 100644 --- a/detections/endpoint/windows_service_created_with_suspicious_service_path.yml +++ b/detections/endpoint/windows_service_created_with_suspicious_service_path.yml @@ -1,7 +1,7 @@ name: Windows Service Created with Suspicious Service Path id: 429141be-8311-11eb-adb6-acde48001122 -version: 11 -date: '2025-01-27' +version: 12 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -68,7 +68,6 @@ tags: - Earth Estries asset_type: Endpoint mitre_attack_id: - - T1569 - T1569.002 product: - Splunk Enterprise @@ -78,6 +77,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/windows_service_created_with_suspicious_service_path/windows-xml.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/windows_service_created_with_suspicious_service_path/windows-xml.log source: XmlWinEventLog:System sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_service_created_within_public_path.yml b/detections/endpoint/windows_service_created_within_public_path.yml index 6ff175c139..393b3eb567 100644 --- a/detections/endpoint/windows_service_created_within_public_path.yml +++ b/detections/endpoint/windows_service_created_within_public_path.yml @@ -1,7 +1,7 @@ name: Windows Service Created Within Public Path id: 3abb2eda-4bb8-11ec-9ae4-3e22fbd008af -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - Snake Malware asset_type: Endpoint mitre_attack_id: - - T1543 - T1543.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_service_creation_on_remote_endpoint.yml b/detections/endpoint/windows_service_creation_on_remote_endpoint.yml index 19ea16bb63..ec3397951e 100644 --- a/detections/endpoint/windows_service_creation_on_remote_endpoint.yml +++ b/detections/endpoint/windows_service_creation_on_remote_endpoint.yml @@ -1,7 +1,7 @@ name: Windows Service Creation on Remote Endpoint id: e0eea4fa-4274-11ec-882b-3e22fbd008af -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -66,7 +66,6 @@ tags: - CISA AA23-347A asset_type: Endpoint mitre_attack_id: - - T1543 - T1543.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_service_execution_remcom.yml b/detections/endpoint/windows_service_execution_remcom.yml index 01840501c6..43198428c0 100644 --- a/detections/endpoint/windows_service_execution_remcom.yml +++ b/detections/endpoint/windows_service_execution_remcom.yml @@ -1,6 +1,6 @@ name: Windows Service Execution RemCom id: 7e3d68db-ea4d-419b-adbd-e14a525ecf09 -version: 2 +version: 3 date: '2025-01-07' author: Michael Haag, Splunk type: TTP diff --git a/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml b/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml index 2a3c2b3981..0c2963cf1d 100644 --- a/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml +++ b/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml @@ -1,7 +1,7 @@ name: Windows Service Initiation on Remote Endpoint id: 3f519894-4276-11ec-ab02-3e22fbd008af -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - CISA AA23-347A asset_type: Endpoint mitre_attack_id: - - T1543 - T1543.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_soaphound_binary_execution.yml b/detections/endpoint/windows_soaphound_binary_execution.yml index cfe3f8ce09..0629cd8492 100644 --- a/detections/endpoint/windows_soaphound_binary_execution.yml +++ b/detections/endpoint/windows_soaphound_binary_execution.yml @@ -1,7 +1,7 @@ name: Windows SOAPHound Binary Execution id: 8e53f839-e127-4d6d-a54d-a2f67044a57f -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -70,13 +70,11 @@ tags: asset_type: Endpoint atomic_guid: [] mitre_attack_id: - - T1087.002 - T1069.001 - - T1482 - - T1087.001 - - T1087 - T1069.002 - - T1069 + - T1087.001 + - T1087.002 + - T1482 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_spearphishing_attachment_connect_to_none_ms_office_domain.yml b/detections/endpoint/windows_spearphishing_attachment_connect_to_none_ms_office_domain.yml index 9da99670ce..b59cd135c2 100644 --- a/detections/endpoint/windows_spearphishing_attachment_connect_to_none_ms_office_domain.yml +++ b/detections/endpoint/windows_spearphishing_attachment_connect_to_none_ms_office_domain.yml @@ -1,7 +1,7 @@ name: Windows Spearphishing Attachment Connect To None MS Office Domain id: 1cb40e15-cffa-45cc-abbd-e35884a49766 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -36,7 +36,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1566.001 - - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml b/detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml index c11e520d5a..52b946ec39 100644 --- a/detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml +++ b/detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml @@ -1,7 +1,7 @@ name: Windows Spearphishing Attachment Onenote Spawn Mshta id: 35aeb0e7-7de5-444a-ac45-24d6788796ec -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1566.001 - - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_sql_spawning_certutil.yml b/detections/endpoint/windows_sql_spawning_certutil.yml index f2e58cc866..d612a17e7e 100644 --- a/detections/endpoint/windows_sql_spawning_certutil.yml +++ b/detections/endpoint/windows_sql_spawning_certutil.yml @@ -1,6 +1,6 @@ name: Windows SQL Spawning CertUtil id: dfc18a5a-946e-44ee-a373-c0f60d06e676 -version: 6 +version: 7 date: '2024-12-16' author: Michael Haag, Splunk status: experimental diff --git a/detections/endpoint/windows_steal_authentication_certificates___esc1_abuse.yml b/detections/endpoint/windows_steal_authentication_certificates___esc1_abuse.yml index f62cbf81c9..10ca564046 100644 --- a/detections/endpoint/windows_steal_authentication_certificates___esc1_abuse.yml +++ b/detections/endpoint/windows_steal_authentication_certificates___esc1_abuse.yml @@ -1,6 +1,6 @@ name: Windows Steal Authentication Certificates - ESC1 Abuse id: cbe761fc-d945-4c8c-a71d-e26d12255d32 -version: 5 +version: 6 date: '2024-11-13' author: Steven Dick status: production diff --git a/detections/endpoint/windows_steal_authentication_certificates___esc1_authentication.yml b/detections/endpoint/windows_steal_authentication_certificates___esc1_authentication.yml index 725f04e04e..5fcaaba267 100644 --- a/detections/endpoint/windows_steal_authentication_certificates___esc1_authentication.yml +++ b/detections/endpoint/windows_steal_authentication_certificates___esc1_authentication.yml @@ -1,6 +1,6 @@ name: Windows Steal Authentication Certificates - ESC1 Authentication id: f0306acf-a6ab-437a-bbc6-8628f8d5c97e -version: 5 +version: 6 date: '2024-12-10' author: Steven Dick status: production diff --git a/detections/endpoint/windows_steal_authentication_certificates_certutil_backup.yml b/detections/endpoint/windows_steal_authentication_certificates_certutil_backup.yml index bf954e1d52..9e7ceb2759 100644 --- a/detections/endpoint/windows_steal_authentication_certificates_certutil_backup.yml +++ b/detections/endpoint/windows_steal_authentication_certificates_certutil_backup.yml @@ -1,6 +1,6 @@ name: Windows Steal Authentication Certificates CertUtil Backup id: bac85b56-0b65-4ce5-aad5-d94880df0967 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_steal_authentication_certificates_export_certificate.yml b/detections/endpoint/windows_steal_authentication_certificates_export_certificate.yml index d1a5eb3d7b..af44db774c 100644 --- a/detections/endpoint/windows_steal_authentication_certificates_export_certificate.yml +++ b/detections/endpoint/windows_steal_authentication_certificates_export_certificate.yml @@ -1,6 +1,6 @@ name: Windows Steal Authentication Certificates Export Certificate id: e39dc429-c2a5-4f1f-9c3c-6b211af6b332 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_steal_authentication_certificates_export_pfxcertificate.yml b/detections/endpoint/windows_steal_authentication_certificates_export_pfxcertificate.yml index 459417802e..2e01886698 100644 --- a/detections/endpoint/windows_steal_authentication_certificates_export_pfxcertificate.yml +++ b/detections/endpoint/windows_steal_authentication_certificates_export_pfxcertificate.yml @@ -1,6 +1,6 @@ name: Windows Steal Authentication Certificates Export PfxCertificate id: 391329f3-c14b-4b8d-8b37-ac5012637360 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml b/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml index 3b28765cce..b418e2f4d2 100644 --- a/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml +++ b/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml @@ -1,7 +1,7 @@ name: Windows Suspect Process With Authentication Traffic id: 953322db-128a-4ce9-8e89-56e039e33d98 -version: 4 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Steven Dick status: production type: Anomaly @@ -66,9 +66,7 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.002 - - T1204 - T1204.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_suspicious_child_process_spawned_from_webserver.yml b/detections/endpoint/windows_suspicious_child_process_spawned_from_webserver.yml index 57257bec13..00bfe7a17b 100644 --- a/detections/endpoint/windows_suspicious_child_process_spawned_from_webserver.yml +++ b/detections/endpoint/windows_suspicious_child_process_spawned_from_webserver.yml @@ -1,7 +1,7 @@ name: Windows Suspicious Child Process Spawned From WebServer id: 2d4470ef-7158-4b47-b68b-1f7f16382156 -version: 1 -date: '2025-01-13' +version: 2 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -87,7 +87,6 @@ tags: - BlackByte Ransomware asset_type: Endpoint mitre_attack_id: - - T1505 - T1505.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_suspicious_driver_loaded_path.yml b/detections/endpoint/windows_suspicious_driver_loaded_path.yml new file mode 100644 index 0000000000..60383739c7 --- /dev/null +++ b/detections/endpoint/windows_suspicious_driver_loaded_path.yml @@ -0,0 +1,75 @@ +name: Windows Suspicious Driver Loaded Path +id: 2ca1c4a1-8342-4750-9363-905650e0c933 +version: 1 +date: '2025-02-03' +author: Teoderick Contreras, Splunk +status: production +type: TTP +description: The following analytic detects the loading of drivers from suspicious + paths, which is a technique often used by malicious software such as coin miners + (e.g., xmrig). It leverages Sysmon EventCode 6 to identify drivers loaded from non-standard + directories. This activity is significant because legitimate drivers typically reside + in specific system directories, and deviations may indicate malicious activity. + If confirmed malicious, this could allow an attacker to execute code at the kernel + level, potentially leading to privilege escalation, persistence, or further system + compromise. +data_source: +- Sysmon EventID 6 +search: '`sysmon` EventCode=6 ImageLoaded = "*.sys" NOT (ImageLoaded IN("*\\WINDOWS\\inf","*\\WINDOWS\\System32\\drivers\\*", + "*\\WINDOWS\\System32\\DriverStore\\FileRepository\\*","*:\Windows\\WinSxS\\*","*\\ProgramData\\Microsoft\\Windows Defender\\Definition Updates\\*")) | stats min(_time) as + firstTime max(_time) as lastTime count by dest ImageLoaded Hashes IMPHASH Signature + Signed| rename ImageLoaded as file_name | `security_content_ctime(firstTime)` | + `security_content_ctime(lastTime)` | `windows_suspicious_driver_loaded_path_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the driver loaded and Signature from your endpoints. If you are using + Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +known_false_positives: Limited false positives will be present. Some applications + do load drivers +references: +- https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/ +- https://redcanary.com/blog/tracking-driver-inventory-to-expose-rootkits/ +drilldown_searches: +- name: View the detection results for - "$dest$" + search: '%original_detection_search% | search dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: Suspicious driver $file_name$ on $dest$ + risk_objects: + - field: dest + type: system + score: 60 + threat_objects: + - field: file_name + type: file_name +tags: + analytic_story: + - XMRig + - CISA AA22-320A + - AgentTesla + - BlackByte Ransomware + - Snake Keylogger + asset_type: Endpoint + mitre_attack_id: + - T1543.003 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_suspicious_process_file_path.yml b/detections/endpoint/windows_suspicious_process_file_path.yml new file mode 100644 index 0000000000..0675251a94 --- /dev/null +++ b/detections/endpoint/windows_suspicious_process_file_path.yml @@ -0,0 +1,121 @@ +name: Windows Suspicious Process File Path +id: ecddae4e-3d4b-41e2-b3df-e46a88b38521 +version: 7 +date: '2025-02-10' +author: Teoderick Contreras, Splunk +status: production +type: TTP +description: The following analytic identifies processes running from file paths not + typically associated with legitimate software. It leverages data from Endpoint Detection + and Response (EDR) agents, focusing on specific process paths within the Endpoint + data model. This activity is significant because adversaries often use unconventional + file paths to execute malicious code without requiring administrative privileges. + If confirmed malicious, this behavior could indicate an attempt to bypass security + controls, leading to unauthorized software execution, potential system compromise, + and further malicious activities within the environment. +data_source: +- Sysmon EventID 1 +- Windows Event Log Security 4688 +- CrowdStrike ProcessRollup2 +search: '| tstats `security_content_summariesonly` count values(Processes.process_name) + as process_name values(Processes.process) as process min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes + where Processes.process_path IN("*\\windows\\fonts\\*", "*\\users\\public\\*", "*\\windows\\debug\\*", "*\\Users\\Administrator\\Music\\*", "*Recycle.bin*", "*\\Windows\\Media\\*","\\Windows\\repair\\*", "*\\PerfLogs\\*", "*:\\Windows\\Prefetch\\*", "*:\\Windows\\Cursors\\*", "*:\\Windows\\INF\\*") AND NOT(Processes.process_path IN ("*\\temp\\*")) + by Processes.parent_process_name Processes.parent_process Processes.process_path Processes.dest Processes.user + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_suspicious_process_file_path_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. +known_false_positives: Administrators may allow execution of specific binaries in + non-standard paths. Filter as needed. +references: +- https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/ +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ +- https://twitter.com/pr0xylife/status/1590394227758104576 +- https://malpedia.caad.fkie.fraunhofer.de/details/win.asyncrat +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ +drilldown_searches: +- name: View the detection results for - "$dest$" + search: '%original_detection_search% | search dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: Suspicious process $process_name$ running from a suspicious process path- + $process_path$ on host- $dest$ + risk_objects: + - field: dest + type: system + score: 60 + threat_objects: + - field: process_path + type: process_name +tags: + analytic_story: + - Double Zero Destructor + - Graceful Wipe Out Attack + - AsyncRAT + - WhisperGate + - Prestige Ransomware + - DarkGate Malware + - AgentTesla + - Brute Ratel C4 + - RedLine Stealer + - Rhysida Ransomware + - Swift Slicer + - IcedID + - DarkCrystal RAT + - Chaos Ransomware + - PlugX + - Industroyer2 + - Azorult + - Remcos + - XMRig + - Qakbot + - Volt Typhoon + - Hermetic Wiper + - Warzone RAT + - Trickbot + - Amadey + - BlackByte Ransomware + - LockBit Ransomware + - CISA AA23-347A + - Data Destruction + - Phemedrone Stealer + - Handala Wiper + - MoonPeak + - ValleyRAT + - Meduza Stealer + asset_type: Endpoint + mitre_attack_id: + - T1543 + - T1036.005 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/suspicious_process_path/susp_path_sysmon1.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml b/detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml index 115d30093e..54ade9f424 100644 --- a/detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml +++ b/detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml @@ -1,7 +1,7 @@ name: Windows System Binary Proxy Execution Compiled HTML File Decompile id: 2acf0e19-4149-451c-a3f3-39cd3c77e37d -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -72,7 +72,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.001 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_system_remote_discovery_with_query.yml b/detections/endpoint/windows_system_remote_discovery_with_query.yml new file mode 100644 index 0000000000..58b97c3df7 --- /dev/null +++ b/detections/endpoint/windows_system_remote_discovery_with_query.yml @@ -0,0 +1,64 @@ +name: Windows System Remote Discovery With Query +id: 94859172-a521-474f-97ac-4cf4b09634a3 +version: 1 +date: '2025-02-05' +author: Steven Dick +status: production +type: Anomaly +description: The following analytic detects the execution of `query.exe` with command-line arguments aimed at discovering data on remote devices. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions. This activity is significant as adversaries may use `query.exe` to gain situational awareness and perform Active Directory discovery on compromised endpoints. If confirmed malicious, this behavior could allow attackers to identify various details about a system, aiding in further lateral movement and privilege escalation within the network. +data_source: +- Sysmon Event ID 1 +- Windows Security Event ID 4688 +- CrowdStrike ProcessRollup2 +search: |- + | tstats `security_content_summariesonly` values(Processes.process_current_directory) as Processes.process_current_directory values(Processes.process_id) as Processes.process_id values(Processes.process) as Processes.process values(Processes.parent_process_id) as Processes.parent_process_id values(Processes.parent_process) as Processes.parent_process count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="query.exe" OR Processes.original_file_name="query.exe") AND (Processes.process="*/server*") AND NOT Processes.process IN ("*/server:localhost*", "*/server:127.0.0.1*") by Processes.dest Processes.user Processes.process_name Processes.parent_process_name + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_system_remote_discovery_with_query_filter` +how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +known_false_positives: Administrators or power users may use this command for troubleshooting. +references: +- https://attack.mitre.org/techniques/T1033/ +drilldown_searches: +- name: View the detection results for - "$dest$" and "$user$" + search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" and "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$","$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: Investigate processes on $dest$ + search: '| from datamodel:Endpoint.Processes | search dest=$dest$ process_name = $process_name|s$' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The user $user$ ran the Query command to enumerate the remote system $dest$ + risk_objects: + - field: user + type: user + score: 25 + - field: dest + type: system + score: 25 + threat_objects: + - field: process_name + type: process_name +tags: + analytic_story: + - Active Directory Discovery + asset_type: Endpoint + mitre_attack_id: + - T1033 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/query_remote_usage/query_remote_usage.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml b/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml index 40f299551f..151b86c366 100644 --- a/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml +++ b/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml @@ -1,6 +1,6 @@ name: Windows System Script Proxy Execution Syncappvpublishingserver id: 8dd73f89-682d-444c-8b41-8e679966ad3c -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_terminating_lsass_process.yml b/detections/endpoint/windows_terminating_lsass_process.yml index 1010e55878..4ac22b6fea 100644 --- a/detections/endpoint/windows_terminating_lsass_process.yml +++ b/detections/endpoint/windows_terminating_lsass_process.yml @@ -1,7 +1,7 @@ name: Windows Terminating Lsass Process id: 7ab3c319-a4e7-4211-9e8c-40a049d0dba6 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -59,7 +59,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_time_based_evasion.yml b/detections/endpoint/windows_time_based_evasion.yml index a6e2eda7af..a7a30342b6 100644 --- a/detections/endpoint/windows_time_based_evasion.yml +++ b/detections/endpoint/windows_time_based_evasion.yml @@ -1,7 +1,7 @@ name: Windows Time Based Evasion id: 34502357-deb1-499a-8261-ffe144abf561 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - NjRAT asset_type: Endpoint mitre_attack_id: - - T1497 - T1497.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_time_based_evasion_via_choice_exec.yml b/detections/endpoint/windows_time_based_evasion_via_choice_exec.yml index 69fcad7d31..5453cc7fef 100644 --- a/detections/endpoint/windows_time_based_evasion_via_choice_exec.yml +++ b/detections/endpoint/windows_time_based_evasion_via_choice_exec.yml @@ -1,7 +1,7 @@ name: Windows Time Based Evasion via Choice Exec id: d5f54b38-10bf-4b3a-b6fc-85949862ed50 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1497.003 - - T1497 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_uac_bypass_suspicious_child_process.yml b/detections/endpoint/windows_uac_bypass_suspicious_child_process.yml index ffd2829b98..ced7799775 100644 --- a/detections/endpoint/windows_uac_bypass_suspicious_child_process.yml +++ b/detections/endpoint/windows_uac_bypass_suspicious_child_process.yml @@ -1,7 +1,7 @@ name: Windows UAC Bypass Suspicious Child Process id: 453a6b0f-b0ea-48fa-9cf4-20537ffdd22c -version: 4 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -69,7 +69,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1548 - T1548.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_uac_bypass_suspicious_escalation_behavior.yml b/detections/endpoint/windows_uac_bypass_suspicious_escalation_behavior.yml index 29e8eca705..e6c5b3452a 100644 --- a/detections/endpoint/windows_uac_bypass_suspicious_escalation_behavior.yml +++ b/detections/endpoint/windows_uac_bypass_suspicious_escalation_behavior.yml @@ -1,7 +1,7 @@ name: Windows UAC Bypass Suspicious Escalation Behavior id: 00d050d3-a5b4-4565-a6a5-a31f69681dc3 -version: 5 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -86,7 +86,6 @@ tags: - Windows Defense Evasion Tactics asset_type: Endpoint mitre_attack_id: - - T1548 - T1548.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_unsigned_dll_side_loading_in_same_process_path.yml b/detections/endpoint/windows_unsigned_dll_side_loading_in_same_process_path.yml index 08803a7cd9..b064f55c1f 100644 --- a/detections/endpoint/windows_unsigned_dll_side_loading_in_same_process_path.yml +++ b/detections/endpoint/windows_unsigned_dll_side_loading_in_same_process_path.yml @@ -1,7 +1,7 @@ name: Windows Unsigned DLL Side-Loading In Same Process Path id: 3cf85c02-f9d6-4186-bf3c-e70ee99fbc7f -version: 6 -date: '2025-01-27' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk data_source: - Sysmon EventID 7 @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.002 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security @@ -71,6 +70,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.002/unsigned_dll_loaded_same_process_path/unsigned_dll_process_path.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.002/unsigned_dll_loaded_same_process_path/unsigned_dll_process_path.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml b/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml index c2fca2d205..63b6bc6fe8 100644 --- a/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml +++ b/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml @@ -1,8 +1,8 @@ name: Windows Unusual Count Of Disabled Users Failed Auth Using Kerberos id: f65aa026-b811-42ab-b4b9-d9088137648f -date: '2024-11-13' +date: '2025-02-10' type: Anomaly -version: 4 +version: 5 status: production author: Mauricio Velazco, Splunk data_source: @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml b/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml index 99987eef1c..3526b02f99 100644 --- a/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml +++ b/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml @@ -1,8 +1,8 @@ name: Windows Unusual Count Of Invalid Users Fail To Auth Using Kerberos id: f122cb2e-d773-4f11-8399-62a3572d8dd7 type: Anomaly -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' status: production author: Mauricio Velazco, Splunk data_source: @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml b/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml index 423d4f8f23..5dbcdccc4e 100644 --- a/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml +++ b/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml @@ -1,9 +1,9 @@ name: Windows Unusual Count Of Invalid Users Failed To Auth Using NTLM id: 15603165-147d-4a6e-9778-bd0ff39e668f type: Anomaly -version: 5 +version: 6 status: production -date: '2024-11-13' +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: - Windows Event Log Security 4776 @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml b/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml index 44f94c13c8..8d72b7869c 100644 --- a/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml +++ b/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml @@ -1,9 +1,9 @@ name: Windows Unusual Count Of Users Fail To Auth Wth ExplicitCredentials id: 14f414cf-3080-4b9b-aaf6-55a4ce947b93 type: Anomaly -version: 5 +version: 6 status: production -date: '2024-11-13' +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: - Windows Event Log Security 4648 @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml b/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml index 437f332a2f..8d4f21783d 100644 --- a/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml +++ b/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml @@ -1,8 +1,8 @@ name: Windows Unusual Count Of Users Failed To Auth Using Kerberos id: bc9cb715-08ba-40c3-9758-6e2b26e455cb -date: '2024-11-13' +date: '2025-02-10' type: Anomaly -version: 4 +version: 5 status: production author: Mauricio Velazco, Splunk data_source: @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml index e7fa32d047..4390ea59a9 100644 --- a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml +++ b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml @@ -1,9 +1,9 @@ name: Windows Unusual Count Of Users Failed To Authenticate From Process id: 25bdb6cb-2e49-4d34-a93c-d6c567c122fe type: Anomaly -version: 5 +version: 6 status: production -date: '2024-11-13' +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: - Windows Event Log Security 4625 @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml index 51d1787dea..851a0ac391 100644 --- a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml +++ b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml @@ -1,9 +1,9 @@ name: Windows Unusual Count Of Users Failed To Authenticate Using NTLM id: 6f6c8fd7-6a6b-4af9-a0e9-57cfc47a58b4 type: Anomaly -version: 5 +version: 6 status: production -date: '2024-11-13' +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: - Windows Event Log Security 4776 @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml b/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml index f3cb730dff..602d834ebc 100644 --- a/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml +++ b/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml @@ -1,9 +1,9 @@ name: Windows Unusual Count Of Users Remotely Failed To Auth From Host id: cf06a0ee-ffa9-4ed3-be77-0670ed9bab52 type: Anomaly -version: 5 +version: 6 status: production -date: '2024-11-13' +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: - Windows Event Log Security 4625 @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_source.yml b/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_source.yml index 8a5066b1b8..dfe94f5f83 100644 --- a/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_source.yml +++ b/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_source.yml @@ -1,7 +1,7 @@ name: Windows Unusual NTLM Authentication Destinations By Source id: ae9b0df5-5fb0-477f-abc9-47faf42aa91d -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: Anomaly @@ -63,7 +63,6 @@ tags: - Active Directory Password Spraying asset_type: Endpoint mitre_attack_id: - - T1110 - T1110.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_user.yml b/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_user.yml index f9d5c01f64..d58eb04003 100644 --- a/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_user.yml +++ b/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_user.yml @@ -1,7 +1,7 @@ name: Windows Unusual NTLM Authentication Destinations By User id: a4d86702-402b-4a4f-8d06-9d61e6c39cad -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: Anomaly @@ -63,7 +63,6 @@ tags: - Active Directory Password Spraying asset_type: Endpoint mitre_attack_id: - - T1110 - T1110.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_unusual_ntlm_authentication_users_by_destination.yml b/detections/endpoint/windows_unusual_ntlm_authentication_users_by_destination.yml index 7474361923..48f11d9078 100644 --- a/detections/endpoint/windows_unusual_ntlm_authentication_users_by_destination.yml +++ b/detections/endpoint/windows_unusual_ntlm_authentication_users_by_destination.yml @@ -1,7 +1,7 @@ name: Windows Unusual NTLM Authentication Users By Destination id: 1120a204-8444-428b-8657-6ea4e1f3e840 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: Anomaly @@ -65,7 +65,6 @@ tags: - Active Directory Password Spraying asset_type: Endpoint mitre_attack_id: - - T1110 - T1110.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_unusual_ntlm_authentication_users_by_source.yml b/detections/endpoint/windows_unusual_ntlm_authentication_users_by_source.yml index d6a3b2c0de..e55d1b5084 100644 --- a/detections/endpoint/windows_unusual_ntlm_authentication_users_by_source.yml +++ b/detections/endpoint/windows_unusual_ntlm_authentication_users_by_source.yml @@ -1,7 +1,7 @@ name: Windows Unusual NTLM Authentication Users By Source id: 80fcc4d4-fd90-488e-b55a-4e7190ae6ce2 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: Anomaly @@ -63,7 +63,6 @@ tags: - Active Directory Password Spraying asset_type: Endpoint mitre_attack_id: - - T1110 - T1110.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_usbstor_registry_key_modification.yml b/detections/endpoint/windows_usbstor_registry_key_modification.yml new file mode 100644 index 0000000000..4ae1abf576 --- /dev/null +++ b/detections/endpoint/windows_usbstor_registry_key_modification.yml @@ -0,0 +1,67 @@ +name: Windows USBSTOR Registry Key Modification +id: a345980a-417d-4ed3-9fb4-cac30c9405a0 +version: 1 +date: '2025-01-17' +author: Steven Dick +status: production +type: Anomaly +description: This analytic is used to identify when a USB removable media device is attached to a Windows host. In this scenario we are querying the Endpoint Registry data model to look for modifications to the HKLM\System\CurrentControlSet\Enum\USBSTOR\ key. Adversaries and Insider Threats may use removable media devices for several malicious activities, including initial access, execution, and exfiltration. +data_source: +- Sysmon Event ID 12 +- Sysmon Event ID 13 +search: |- + | tstats `security_content_summariesonly` values(Registry.registry_value_data) as registry_value_data, values(Registry.registry_value_name) as registry_value_name, min(_time) as firstTime, max(_time) as lastTime, count from datamodel=Endpoint.Registry where Registry.registry_path IN ("HKLM\\System\\CurrentControlSet\\Enum\\USBSTOR\\*") AND Registry.registry_value_name ="FriendlyName" by Registry.dest,Registry.registry_value_data,Registry.registry_path + | `drop_dm_object_name(Registry)` + | eval object_name = registry_value_data, object_handle = split(mvindex(split(registry_path, "\\"),6),"&"), object_handle = mvindex(mvfilter(NOT len(object_handle)=1),0) + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_usbstor_registry_key_modification_filter` +how_to_implement: To successfully implement this search, you must ingest endpoint logging that tracks changes to the HKLM\System\CurrentControlSet\Enum\USBSTOR\ registry keys. Ensure that the field from the event logs is being mapped to the proper fields in the Endpoint.Registry data model. +known_false_positives: Legitimate USB activity will also be detected. Please verify and investigate as appropriate. +references: +- https://attack.mitre.org/techniques/T1200/ +- https://www.cisa.gov/news-events/news/using-caution-usb-drives +- https://www.bleepingcomputer.com/news/security/fbi-hackers-use-badusb-to-target-defense-firms-with-ransomware/ +drilldown_searches: +- name: View the detection results for - "$dest$" + search: '%original_detection_search% | search dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: Investigate USB events on $dest$ + search: '| from datamodel:Endpoint.Registry | search dest=$dest$ registry_path IN ("HKLM\\System\\CurrentControlSet\\Enum\\USBSTOR\\*")' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: A removable storage device named [$object_name$] with drive letter [$object_handle$] was attached to $dest$ + risk_objects: + - field: dest + type: system + score: 10 + threat_objects: + - field: object_name + type: registry_value_name + - field: object_handle + type: registry_value_text +tags: + analytic_story: + - Data Protection + asset_type: Endpoint + mitre_attack_id: + - T1200 + - T1025 + - T1091 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1200/sysmon_usb_use_execution/sysmon_usb_use_execution.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_user_deletion_via_net.yml b/detections/endpoint/windows_user_deletion_via_net.yml index 33ae19c5ea..32bb43dd91 100644 --- a/detections/endpoint/windows_user_deletion_via_net.yml +++ b/detections/endpoint/windows_user_deletion_via_net.yml @@ -1,6 +1,6 @@ name: Windows User Deletion Via Net id: b0b6fd2c-8953-4d1b-8f7b-56075ea6ab3e -version: 1 +version: 2 date: '2025-01-13' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/windows_user_disabled_via_net.yml b/detections/endpoint/windows_user_disabled_via_net.yml index dd390a4128..547248419e 100644 --- a/detections/endpoint/windows_user_disabled_via_net.yml +++ b/detections/endpoint/windows_user_disabled_via_net.yml @@ -1,6 +1,6 @@ name: Windows User Disabled Via Net id: b0359e05-c87b-4354-83d8-aee0d890243f -version: 1 +version: 2 date: '2025-01-13' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/windows_user_discovery_via_net.yml b/detections/endpoint/windows_user_discovery_via_net.yml index 9f736b6b2d..670b59cbaa 100644 --- a/detections/endpoint/windows_user_discovery_via_net.yml +++ b/detections/endpoint/windows_user_discovery_via_net.yml @@ -1,7 +1,7 @@ name: Windows User Discovery Via Net id: 7742987e-88c1-476b-a626-a869e088ab72 -version: 1 -date: '2025-01-13' +version: 2 +date: '2025-02-10' author: Mauricio Velazco, Teoderick Contreras, Nasreddine Bencherchali, Splunk status: production type: Hunting @@ -17,8 +17,22 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` (Processes.process="*user" OR Processes.process="*users" OR Processes.process="*users *" OR Processes.process="*user *") AND NOT (Processes.process="*/add" OR Processes.process="*/delete") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_user_discovery_via_net_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_net` (Processes.process="*user" + OR Processes.process="*users" OR Processes.process="*users *" OR Processes.process="*user + *") AND NOT (Processes.process="*/add" OR Processes.process="*/delete") by Processes.dest + Processes.user Processes.parent_process Processes.process_name Processes.process + Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_user_discovery_via_net_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. known_false_positives: Administrators or power users may use this command for troubleshooting. references: - https://attack.mitre.org/techniques/T1087/001/ @@ -28,7 +42,6 @@ tags: - Sandworm Tools asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.001 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml b/detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml index 0ee3bb1eaa..a9521c99f0 100644 --- a/detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml +++ b/detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml @@ -1,7 +1,7 @@ name: Windows User Execution Malicious URL Shortcut File id: 5c7ee6ad-baf4-44fb-b2f0-0cfeddf82dbc -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1204.002 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_windbg_spawning_autoit3.yml b/detections/endpoint/windows_windbg_spawning_autoit3.yml index ddf09e5373..323c29de1d 100644 --- a/detections/endpoint/windows_windbg_spawning_autoit3.yml +++ b/detections/endpoint/windows_windbg_spawning_autoit3.yml @@ -1,6 +1,6 @@ name: Windows WinDBG Spawning AutoIt3 id: 7aec015b-cd69-46c3-85ed-dac152056aa4 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_wpdbusenum_registry_key_modification.yml b/detections/endpoint/windows_wpdbusenum_registry_key_modification.yml new file mode 100644 index 0000000000..d87be77ae0 --- /dev/null +++ b/detections/endpoint/windows_wpdbusenum_registry_key_modification.yml @@ -0,0 +1,67 @@ +name: Windows WPDBusEnum Registry Key Modification +id: 52b48e8b-eb6e-48b0-b8f1-73273f6b134e +version: 1 +date: '2025-01-17' +author: Steven Dick +status: production +type: Anomaly +description: This analytic is used to identify when a USB removable media device is attached to a Windows host. In this scenario we are querying the Endpoint Registry data model to look for modifications to the Windows Portable Device keys HKLM\SOFTWARE\Microsoft\Windows Portable Devices\Devices\ or HKLM\System\CurrentControlSet\Enum\SWD\WPDBUSENUM\ . Adversaries and Insider Threats may use removable media devices for several malicious activities, including initial access, execution, and exfiltration. +data_source: +- Sysmon Event ID 12 +- Sysmon Event ID 13 +search: |- + | tstats `security_content_summariesonly` latest(Registry.registry_path) as registry_path, values(Registry.registry_value_name) as registry_value_name, min(_time) as firstTime, max(_time) as lastTime, count from datamodel=Endpoint.Registry where Registry.registry_path IN ("HKLM\\SOFTWARE\\Microsoft\\Windows Portable Devices\\Devices\\*","HKLM\\System\\CurrentControlSet\\Enum\\SWD\\WPDBUSENUM\\*") AND Registry.registry_value_name ="FriendlyName" AND Registry.registry_path="*USBSTOR*" by Registry.dest,Registry.registry_value_data + | `drop_dm_object_name(Registry)` + | eval object_handle = registry_value_data, object_name = replace(mvindex(split(mvindex(split(registry_path, "??"),1),"&"),2),"PROD_","") + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_wpdbusenum_registry_key_modification_filter` +how_to_implement: To successfully implement this search, you must ingest endpoint logging that tracks changes to the HKLM\SOFTWARE\Microsoft\Windows Portable Devices\Devices\ or HKLM\System\CurrentControlSet\Enum\SWD\WPDBUSENUM\ registry keys. Ensure that the field from the event logs is being mapped to the proper fields in the Endpoint.Registry data model. +known_false_positives: Legitimate USB activity will also be detected. Please verify and investigate as appropriate. +references: +- https://attack.mitre.org/techniques/T1200/ +- https://www.cisa.gov/news-events/news/using-caution-usb-drives +- https://www.bleepingcomputer.com/news/security/fbi-hackers-use-badusb-to-target-defense-firms-with-ransomware/ +drilldown_searches: +- name: View the detection results for - "$dest$" + search: '%original_detection_search% | search dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: Investigate USB events on $dest$ + search: '| from datamodel:Endpoint.Registry | search dest=$dest$ registry_path IN ("HKLM\\SOFTWARE\\Microsoft\\Windows Portable Devices\\Devices\\*","HKLM\\System\\CurrentControlSet\\Enum\\SWD\\WPDBUSENUM\\*")' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: A removable storage device named [$object_name$] with drive letter [$object_handle$] was attached to $dest$ + risk_objects: + - field: dest + type: system + score: 10 + threat_objects: + - field: object_name + type: registry_value_name + - field: object_handle + type: registry_value_text +tags: + analytic_story: + - Data Protection + asset_type: Endpoint + mitre_attack_id: + - T1200 + - T1025 + - T1091 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1200/sysmon_usb_use_execution/sysmon_usb_use_execution.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml b/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml index 690c5bffb5..36d6515acc 100644 --- a/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml +++ b/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml @@ -1,7 +1,7 @@ name: WinEvent Scheduled Task Created to Spawn Shell id: 203ef0ea-9bd8-11eb-8201-acde48001122 -version: 8 -date: '2025-01-27' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.005 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security @@ -76,6 +75,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/winevent_scheduled_task_created_to_spawn_shell/windows-xml.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/winevent_scheduled_task_created_to_spawn_shell/windows-xml.log source: XmlWinEventLog:Security sourcetype: XmlWinEventLog diff --git a/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml b/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml index 7c383641be..b7a530c00d 100644 --- a/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml +++ b/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml @@ -1,7 +1,7 @@ name: WinEvent Scheduled Task Created Within Public Path id: 5d9c6eee-988c-11eb-8253-acde48001122 -version: 8 -date: '2025-01-27' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.005 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security @@ -82,6 +81,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/winevent_scheduled_task_created_to_spawn_shell/windows-xml.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/winevent_scheduled_task_created_to_spawn_shell/windows-xml.log source: XmlWinEventLog:Security sourcetype: XmlWinEventLog diff --git a/detections/endpoint/winhlp32_spawning_a_process.yml b/detections/endpoint/winhlp32_spawning_a_process.yml index 97671e24f0..71018871f9 100644 --- a/detections/endpoint/winhlp32_spawning_a_process.yml +++ b/detections/endpoint/winhlp32_spawning_a_process.yml @@ -1,6 +1,6 @@ name: Winhlp32 Spawning a Process id: d17dae9e-2618-11ec-b9f5-acde48001122 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/winrar_spawning_shell_application.yml b/detections/endpoint/winrar_spawning_shell_application.yml index 9ef1be04ff..104bc4f1d3 100644 --- a/detections/endpoint/winrar_spawning_shell_application.yml +++ b/detections/endpoint/winrar_spawning_shell_application.yml @@ -1,6 +1,6 @@ name: WinRAR Spawning Shell Application id: d2f36034-37fa-4bd4-8801-26807c15540f -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml b/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml index e544a4480e..c21bc05de0 100644 --- a/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml +++ b/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml @@ -1,7 +1,7 @@ name: WMI Permanent Event Subscription - Sysmon id: ad05aae6-3b2a-4f73-af97-57bd26cee3b9 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Rico Valdez, Michael Haag, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.003 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/wmic_group_discovery.yml b/detections/endpoint/wmic_group_discovery.yml index 1387e90ee7..3d38511475 100644 --- a/detections/endpoint/wmic_group_discovery.yml +++ b/detections/endpoint/wmic_group_discovery.yml @@ -1,7 +1,7 @@ name: Wmic Group Discovery id: 83317b08-155b-11ec-8e00-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -41,7 +41,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.001 product: - Splunk Enterprise diff --git a/detections/endpoint/wmic_noninteractive_app_uninstallation.yml b/detections/endpoint/wmic_noninteractive_app_uninstallation.yml index a45718c22e..cb48b0dacc 100644 --- a/detections/endpoint/wmic_noninteractive_app_uninstallation.yml +++ b/detections/endpoint/wmic_noninteractive_app_uninstallation.yml @@ -1,7 +1,7 @@ name: Wmic NonInteractive App Uninstallation id: bff0e7a0-317f-11ec-ab4e-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -44,7 +44,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/wmic_xsl_execution_via_url.yml b/detections/endpoint/wmic_xsl_execution_via_url.yml index b8efe7f1fc..a9fa113597 100644 --- a/detections/endpoint/wmic_xsl_execution_via_url.yml +++ b/detections/endpoint/wmic_xsl_execution_via_url.yml @@ -1,6 +1,6 @@ name: WMIC XSL Execution via URL id: 787e9dd0-4328-11ec-a029-acde48001122 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml b/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml index bdff837caf..931de61b80 100644 --- a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml +++ b/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml @@ -1,7 +1,7 @@ name: Wscript Or Cscript Suspicious Child Process id: 1f35e1da-267b-11ec-90a9-acde48001122 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -72,9 +72,8 @@ tags: asset_type: Endpoint mitre_attack_id: - T1055 - - T1543 - T1134.004 - - T1134 + - T1543 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/wsmprovhost_lolbas_execution_process_spawn.yml b/detections/endpoint/wsmprovhost_lolbas_execution_process_spawn.yml index 702bb0a66e..9ae72bafa1 100644 --- a/detections/endpoint/wsmprovhost_lolbas_execution_process_spawn.yml +++ b/detections/endpoint/wsmprovhost_lolbas_execution_process_spawn.yml @@ -1,7 +1,7 @@ name: Wsmprovhost LOLBAS Execution Process Spawn id: 2eed004c-4c0d-11ec-93e8-3e22fbd008af -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -75,7 +75,6 @@ tags: - CISA AA24-241A asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.006 product: - Splunk Enterprise diff --git a/detections/endpoint/wsreset_uac_bypass.yml b/detections/endpoint/wsreset_uac_bypass.yml index 14b7aa39d9..1879fa36d4 100644 --- a/detections/endpoint/wsreset_uac_bypass.yml +++ b/detections/endpoint/wsreset_uac_bypass.yml @@ -1,7 +1,7 @@ name: WSReset UAC Bypass id: 8b5901bc-da63-11eb-be43-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Steven Dick, Teoderick Contreras, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/xmrig_driver_loaded.yml b/detections/endpoint/xmrig_driver_loaded.yml index 475bc420de..2c08457e9e 100644 --- a/detections/endpoint/xmrig_driver_loaded.yml +++ b/detections/endpoint/xmrig_driver_loaded.yml @@ -1,7 +1,7 @@ name: XMRIG Driver Loaded id: 90080fa6-a8df-11eb-91e4-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -54,7 +54,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1543.003 - - T1543 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/xsl_script_execution_with_wmic.yml b/detections/endpoint/xsl_script_execution_with_wmic.yml index 02f24699a2..28584c4d66 100644 --- a/detections/endpoint/xsl_script_execution_with_wmic.yml +++ b/detections/endpoint/xsl_script_execution_with_wmic.yml @@ -1,6 +1,6 @@ name: XSL Script Execution With WMIC id: 004e32e2-146d-11ec-a83f-acde48001122 -version: 5 +version: 6 date: '2024-11-13' author: Teoderick Contreras, Splunk status: production diff --git a/detections/network/detect_arp_poisoning.yml b/detections/network/detect_arp_poisoning.yml index 108276a3d7..1e3b9d8998 100644 --- a/detections/network/detect_arp_poisoning.yml +++ b/detections/network/detect_arp_poisoning.yml @@ -1,7 +1,7 @@ name: Detect ARP Poisoning id: b44bebd6-bd39-467b-9321-73971bcd1aac -version: 5 -date: '2024-11-15' +version: 6 +date: '2025-02-10' author: Mikael Bjerkeland, Splunk status: experimental type: TTP @@ -44,7 +44,6 @@ tags: mitre_attack_id: - T1200 - T1498 - - T1557 - T1557.002 product: - Splunk Enterprise diff --git a/detections/network/detect_ipv6_network_infrastructure_threats.yml b/detections/network/detect_ipv6_network_infrastructure_threats.yml index a45007b944..5be89b972e 100644 --- a/detections/network/detect_ipv6_network_infrastructure_threats.yml +++ b/detections/network/detect_ipv6_network_infrastructure_threats.yml @@ -1,7 +1,7 @@ name: Detect IPv6 Network Infrastructure Threats id: c3be767e-7959-44c5-8976-0e9c12a91ad2 -version: 4 -date: '2024-11-15' +version: 5 +date: '2025-02-10' author: Mikael Bjerkeland, Splunk status: experimental type: TTP @@ -52,7 +52,6 @@ tags: mitre_attack_id: - T1200 - T1498 - - T1557 - T1557.002 product: - Splunk Enterprise diff --git a/detections/network/detect_large_outbound_icmp_packets.yml b/detections/network/detect_large_outbound_icmp_packets.yml index e4bdf54ffc..9fa1a7f4b5 100644 --- a/detections/network/detect_large_outbound_icmp_packets.yml +++ b/detections/network/detect_large_outbound_icmp_packets.yml @@ -1,6 +1,6 @@ name: Detect Large Outbound ICMP Packets id: e9c102de-4d43-42a7-b1c8-8062ea297419 -version: 8 +version: 9 date: '2025-01-27' author: Rico Valdez, Dean Luxton, Splunk status: production diff --git a/detections/network/detect_outbound_smb_traffic.yml b/detections/network/detect_outbound_smb_traffic.yml index 3a2cbf6989..0e0acc3144 100644 --- a/detections/network/detect_outbound_smb_traffic.yml +++ b/detections/network/detect_outbound_smb_traffic.yml @@ -1,7 +1,7 @@ name: Detect Outbound SMB Traffic id: 1bed7774-304a-4e8f-9d72-d80e45ff492b -version: 7 -date: '2024-11-15' +version: 8 +date: '2025-02-10' author: Bhavin Patel, Stuart Hopkins, Patrick Bareiss status: experimental type: TTP @@ -30,10 +30,10 @@ how_to_implement: This search also requires you to be ingesting your network tra known_false_positives: It is likely that the outbound Server Message Block (SMB) traffic is legitimate, if the company's internal networks are not well-defined in the Assets and Identity Framework. Categorize the internal CIDR blocks as `internal` in the - lookup file to avoid creating findings for traffic destined to those CIDR - blocks. Any other network connection that is going out to the Internet should be - investigated and blocked. Best practices suggest preventing external communications - of all SMB versions and related protocols at the network boundary. + lookup file to avoid creating findings for traffic destined to those CIDR blocks. + Any other network connection that is going out to the Internet should be investigated + and blocked. Best practices suggest preventing external communications of all SMB + versions and related protocols at the network boundary. references: [] rba: message: An outbound SMB connection from $src_ip$ in your infrastructure connecting @@ -53,7 +53,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1071.002 - - T1071 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/detect_port_security_violation.yml b/detections/network/detect_port_security_violation.yml index 66a16461fd..0126710dbb 100644 --- a/detections/network/detect_port_security_violation.yml +++ b/detections/network/detect_port_security_violation.yml @@ -1,7 +1,7 @@ name: Detect Port Security Violation id: 2de3d5b8-a4fa-45c5-8540-6d071c194d24 -version: 5 -date: '2024-11-15' +version: 6 +date: '2025-02-10' author: Mikael Bjerkeland, Splunk status: experimental type: TTP @@ -44,7 +44,6 @@ tags: mitre_attack_id: - T1200 - T1498 - - T1557 - T1557.002 product: - Splunk Enterprise diff --git a/detections/network/detect_remote_access_software_usage_dns.yml b/detections/network/detect_remote_access_software_usage_dns.yml index e01bd31544..f7744a4f63 100644 --- a/detections/network/detect_remote_access_software_usage_dns.yml +++ b/detections/network/detect_remote_access_software_usage_dns.yml @@ -1,6 +1,6 @@ name: Detect Remote Access Software Usage DNS id: a16b797d-e309-41bd-8ba0-5067dae2e4be -version: 5 +version: 6 date: '2024-11-15' author: Steven Dick status: production @@ -52,21 +52,28 @@ drilldown_searches: | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ +- name: Investigate traffic to $query$ + search: '| from datamodel:Network_Resolution.DNS | search src=$src$ query=$query$' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ rba: message: A domain for a known remote access software $query$ was contacted by $src$. risk_objects: - field: src type: system - score: 4 + score: 25 threat_objects: - field: query type: domain + - field: signature + type: signature tags: analytic_story: - Insider Threat - Command And Control - Ransomware - CISA AA24-241A + - Remote Monitoring and Management Software asset_type: Endpoint mitre_attack_id: - T1219 diff --git a/detections/network/detect_remote_access_software_usage_traffic.yml b/detections/network/detect_remote_access_software_usage_traffic.yml index aeb0b45f21..526fe6f906 100644 --- a/detections/network/detect_remote_access_software_usage_traffic.yml +++ b/detections/network/detect_remote_access_software_usage_traffic.yml @@ -1,6 +1,6 @@ name: Detect Remote Access Software Usage Traffic id: 885ea672-07ee-475a-879e-60d28aa5dd42 -version: 5 +version: 6 date: '2024-11-15' author: Steven Dick status: production @@ -52,6 +52,10 @@ drilldown_searches: | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ +- name: Investigate application traffic for $app$ + search: '| from datamodel:Network_Traffic.All_Traffic | search src=$src$ app=$app$' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ rba: message: Application traffic for a known remote access software [$signature$] was detected from $src$. @@ -59,12 +63,18 @@ rba: - field: src type: system score: 25 - threat_objects: [] + - field: user + type: user + score: 25 + threat_objects: + - field: signature + type: signature tags: analytic_story: - Insider Threat - Command And Control - Ransomware + - Remote Monitoring and Management Software asset_type: Network mitre_attack_id: - T1219 diff --git a/detections/network/detect_software_download_to_network_device.yml b/detections/network/detect_software_download_to_network_device.yml index d11e5395c6..5f16395c2c 100644 --- a/detections/network/detect_software_download_to_network_device.yml +++ b/detections/network/detect_software_download_to_network_device.yml @@ -1,7 +1,7 @@ name: Detect Software Download To Network Device id: cc590c66-f65f-48f2-986a-4797244762f8 -version: 4 -date: '2024-11-15' +version: 5 +date: '2025-02-10' author: Mikael Bjerkeland, Splunk status: experimental type: TTP @@ -44,7 +44,6 @@ tags: asset_type: Infrastructure mitre_attack_id: - T1542.005 - - T1542 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/detect_traffic_mirroring.yml b/detections/network/detect_traffic_mirroring.yml index a8121dd68b..b9982c9d34 100644 --- a/detections/network/detect_traffic_mirroring.yml +++ b/detections/network/detect_traffic_mirroring.yml @@ -1,7 +1,7 @@ name: Detect Traffic Mirroring id: 42b3b753-5925-49c5-9742-36fa40a73990 -version: 5 -date: '2024-11-15' +version: 6 +date: '2025-02-10' author: Mikael Bjerkeland, Splunk status: experimental type: TTP @@ -41,10 +41,9 @@ tags: - Router and Infrastructure Security asset_type: Infrastructure mitre_attack_id: - - T1200 - - T1020 - - T1498 - T1020.001 + - T1200 + - T1498 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/dns_query_length_outliers___mltk.yml b/detections/network/dns_query_length_outliers___mltk.yml index 629215e272..2c4743e19d 100644 --- a/detections/network/dns_query_length_outliers___mltk.yml +++ b/detections/network/dns_query_length_outliers___mltk.yml @@ -1,7 +1,7 @@ name: DNS Query Length Outliers - MLTK id: 85fbcfe8-9718-4911-adf6-7000d077a3a9 -version: 5 -date: '2024-11-15' +version: 6 +date: '2025-02-10' author: Rico Valdez, Splunk status: experimental type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1071.004 - - T1071 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/dns_query_length_with_high_standard_deviation.yml b/detections/network/dns_query_length_with_high_standard_deviation.yml index 744203b569..686ce2e6d7 100644 --- a/detections/network/dns_query_length_with_high_standard_deviation.yml +++ b/detections/network/dns_query_length_with_high_standard_deviation.yml @@ -1,7 +1,7 @@ name: DNS Query Length With High Standard Deviation id: 1a67f15a-f4ff-4170-84e9-08cf6f75d6f5 -version: 8 -date: '2024-11-15' +version: 9 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1048.003 - - T1048 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/excessive_dns_failures.yml b/detections/network/excessive_dns_failures.yml index 96cd124e74..b809df4dbf 100644 --- a/detections/network/excessive_dns_failures.yml +++ b/detections/network/excessive_dns_failures.yml @@ -1,7 +1,7 @@ name: Excessive DNS Failures id: 104658f4-afdc-499e-9719-17243f9826f1 -version: 6 -date: '2024-11-15' +version: 7 +date: '2025-02-10' author: bowesmana, Bhavin Patel, Splunk status: experimental type: Anomaly @@ -43,7 +43,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1071.004 - - T1071 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml b/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml index 16c268125d..86532055ed 100644 --- a/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml +++ b/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml @@ -1,7 +1,7 @@ name: Hosts receiving high volume of network traffic from email server id: 7f5fb3e1-4209-4914-90db-0ec21b556368 -version: 5 -date: '2024-11-15' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Splunk status: experimental type: Anomaly @@ -51,7 +51,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1114.002 - - T1114 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/large_volume_of_dns_any_queries.yml b/detections/network/large_volume_of_dns_any_queries.yml index b73ca41645..1be208ea08 100644 --- a/detections/network/large_volume_of_dns_any_queries.yml +++ b/detections/network/large_volume_of_dns_any_queries.yml @@ -1,7 +1,7 @@ name: Large Volume of DNS ANY Queries id: 8fa891f7-a533-4b3c-af85-5aa2e7c1f1eb -version: 4 -date: '2024-11-15' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: experimental type: Anomaly @@ -35,7 +35,6 @@ tags: - DNS Amplification Attacks asset_type: DNS Servers mitre_attack_id: - - T1498 - T1498.002 product: - Splunk Enterprise diff --git a/detections/network/protocol_or_port_mismatch.yml b/detections/network/protocol_or_port_mismatch.yml index d935eff540..727748a951 100644 --- a/detections/network/protocol_or_port_mismatch.yml +++ b/detections/network/protocol_or_port_mismatch.yml @@ -1,7 +1,7 @@ name: Protocol or Port Mismatch id: 54dc1265-2f74-4b6d-b30d-49eb506a31b3 -version: 5 -date: '2024-11-15' +version: 6 +date: '2025-02-10' author: Rico Valdez, Splunk status: experimental type: Anomaly @@ -42,7 +42,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1048.003 - - T1048 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/remote_desktop_network_bruteforce.yml b/detections/network/remote_desktop_network_bruteforce.yml deleted file mode 100644 index 35dcd16a5c..0000000000 --- a/detections/network/remote_desktop_network_bruteforce.yml +++ /dev/null @@ -1,51 +0,0 @@ -name: Remote Desktop Network Bruteforce -id: a98727cc-286b-4ff2-b898-41df64695923 -version: 6 -date: '2024-11-15' -author: Jose Hernandez, Splunk -status: experimental -type: TTP -description: The following analytic identifies potential Remote Desktop Protocol (RDP) - brute force attacks by monitoring network traffic for RDP application activity. - It detects anomalies by filtering source and destination pairs that generate traffic - exceeding twice the standard deviation of the average traffic. This method leverages - the Network_Traffic data model to identify unusual patterns indicative of brute - force attempts. This activity is significant as it may indicate an attacker attempting - to gain unauthorized access to systems via RDP. If confirmed malicious, this could - lead to unauthorized access, data exfiltration, or further network compromise. -data_source: [] -search: >- - | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Network_Traffic where (All_Traffic.app=rdp OR All_Traffic.dest_port=3389) - AND All_Traffic.action=allowed by All_Traffic.src All_Traffic.dest All_Traffic.dest_port | - eventstats stdev(count) AS stdev avg(count) AS avg p50(count) AS p50 | where count>(avg - + stdev*2) | rename All_Traffic.src AS src All_Traffic.dest AS dest | table firstTime - lastTime src dest count avg p50 stdev | `remote_desktop_network_bruteforce_filter` -how_to_implement: You must ensure that your network traffic data is populating the - Network_Traffic data model. -known_false_positives: RDP gateways may have unusually high amounts of traffic from - all other hosts' RDP applications in the network. -references: [] -rba: - message: $dest$ may be the target of an RDP Bruteforce - risk_objects: - - field: dest - type: system - score: 25 - - field: src - type: system - score: 25 - threat_objects: [] -tags: - analytic_story: - - SamSam Ransomware - - Ryuk Ransomware - asset_type: Endpoint - mitre_attack_id: - - T1021.001 - - T1021 - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - security_domain: network diff --git a/detections/network/remote_desktop_network_traffic.yml b/detections/network/remote_desktop_network_traffic.yml index dea3884a91..866c4cc5e4 100644 --- a/detections/network/remote_desktop_network_traffic.yml +++ b/detections/network/remote_desktop_network_traffic.yml @@ -1,7 +1,7 @@ name: Remote Desktop Network Traffic id: 272b8407-842d-4b3d-bead-a704584003d3 -version: 8 -date: '2024-11-15' +version: 9 +date: '2025-02-10' author: David Dorsey, Splunk status: production type: Anomaly @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.001 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/smb_traffic_spike.yml b/detections/network/smb_traffic_spike.yml index 7154a35162..122c6cb228 100644 --- a/detections/network/smb_traffic_spike.yml +++ b/detections/network/smb_traffic_spike.yml @@ -1,7 +1,7 @@ name: SMB Traffic Spike id: 7f5fb3e1-4209-4914-90db-0ec21b936378 -version: 6 -date: '2024-11-15' +version: 7 +date: '2025-02-10' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -43,7 +43,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.002 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/smb_traffic_spike___mltk.yml b/detections/network/smb_traffic_spike___mltk.yml index 0ec7d9fe16..38c6b024a6 100644 --- a/detections/network/smb_traffic_spike___mltk.yml +++ b/detections/network/smb_traffic_spike___mltk.yml @@ -1,7 +1,7 @@ name: SMB Traffic Spike - MLTK id: d25773ba-9ad8-48d1-858e-07ad0bbeb828 -version: 6 -date: '2024-11-15' +version: 7 +date: '2025-02-10' author: Rico Valdez, Splunk status: experimental type: Anomaly @@ -31,11 +31,10 @@ how_to_implement: "To successfully implement this search, you will need to ensur should periodically re-run the support search to rebuild the model with the latest data available in your environment.\nThis search produces a field (Number of events,count) that are not yet supported by ES Incident Review and therefore cannot be viewed - when a finding is raised. This field contributes additional context to the - finding. To see the additional metadata, add the following field, if not already - present, to Incident Review - Event Attributes (Configure > Incident Management - > Incident Review Settings > Add New Entry):\n* **Label:** Number of events, **Field:** - count" + when a finding is raised. This field contributes additional context to the finding. + To see the additional metadata, add the following field, if not already present, + to Incident Review - Event Attributes (Configure > Incident Management > Incident + Review Settings > Add New Entry):\n* **Label:** Number of events, **Field:** count" known_false_positives: If you are seeing more results than desired, you may consider reducing the value of the threshold in the search. You should also periodically re-run the support search to re-build the ML model on the latest data. Please update @@ -57,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.002 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/tor_traffic.yml b/detections/network/tor_traffic.yml index 07c2e15ab9..4b1d821c41 100644 --- a/detections/network/tor_traffic.yml +++ b/detections/network/tor_traffic.yml @@ -1,7 +1,7 @@ name: TOR Traffic id: ea688274-9c06-4473-b951-e4cb7a5d7a45 -version: 6 -date: '2024-11-15' +version: 7 +date: '2025-02-10' author: David Dorsey, Bhavin Patel, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: - Command And Control asset_type: Endpoint mitre_attack_id: - - T1090 - T1090.003 product: - Splunk Enterprise diff --git a/detections/network/windows_ad_replication_service_traffic.yml b/detections/network/windows_ad_replication_service_traffic.yml index 17845e1f82..59036dc908 100644 --- a/detections/network/windows_ad_replication_service_traffic.yml +++ b/detections/network/windows_ad_replication_service_traffic.yml @@ -1,7 +1,7 @@ name: Windows AD Replication Service Traffic id: c6e24183-a5f4-4b2a-ad01-2eb456d09b67 -version: 4 -date: '2024-11-15' +version: 5 +date: '2025-02-10' author: Steven Dick type: TTP status: experimental @@ -42,7 +42,6 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1003 - T1003.006 - T1207 product: diff --git a/detections/network/windows_remote_desktop_network_bruteforce_attempt.yml b/detections/network/windows_remote_desktop_network_bruteforce_attempt.yml new file mode 100644 index 0000000000..38f166c9d9 --- /dev/null +++ b/detections/network/windows_remote_desktop_network_bruteforce_attempt.yml @@ -0,0 +1,60 @@ +name: Windows Remote Desktop Network Bruteforce Attempt +id: 908bf0d5-0983-4afd-b6a4-e9eb5d361a7d +version: 2 +date: '2025-02-11' +author: Jose Hernandez, Bhavin Patel, Splunk +status: production +type: Anomaly +description: The following analytic identifies potential Remote Desktop Protocol (RDP) brute force attacks by monitoring network traffic for RDP application activity. This query detects potential RDP brute force attacks by identifying source IPs that have made more than 10 connection attempts to the same RDP port on a host within a one-hour window. The results are presented in a table that includes the source and destination IPs, destination port, number of attempts, and the times of the first and last connection attempts, helping to prioritize IPs based on the intensity of activity. +data_source: +- Sysmon EventID 3 +search: >- + | tstats `security_content_summariesonly` count, min(_time) as firstTime, max(_time) as lastTime values(Al_Traffic.action) as action from datamodel=Network_Traffic where (All_Traffic.app=rdp OR All_Traffic.dest_port=3389) by All_Traffic.src, All_Traffic.dest, All_Traffic.dest_port All_Traffic.user All_Traffic.vendor_product + | `drop_dm_object_name("All_Traffic")` + | eval duration=lastTime-firstTime + | where count > 10 AND duration < 3600 + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_remote_desktop_network_bruteforce_attempt_filter` +how_to_implement: You must ensure that your network traffic data is populating the Network_Traffic data model. Adjust the count and duration thresholds as necessary to tune the sensitivity of your detection. +known_false_positives: RDP gateways may have unusually high amounts of traffic from all other hosts' RDP applications in the network.Any legitimate RDP traffic using wrong/expired credentials will be also detected as a false positive. +references: +- https://www.zscaler.com/blogs/security-research/ransomware-delivered-using-rdp-brute-force-attack +- https://www.reliaquest.com/blog/rdp-brute-force-attacks/ +drilldown_searches: +- name: View the detection results for - "$dest$" + search: '%original_detection_search% | search dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: $dest$ may be the target of an RDP Bruteforce from $src$ + risk_objects: + - field: dest + type: system + score: 25 + threat_objects: + - field: src + type: ip_address +tags: + analytic_story: + - SamSam Ransomware + - Ryuk Ransomware + - Compromised User Account + asset_type: Endpoint + mitre_attack_id: + - T1110.001 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: network +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.001/rdp_brute_sysmon/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/web/detect_remote_access_software_usage_url.yml b/detections/web/detect_remote_access_software_usage_url.yml index d60f2af086..6f186e9379 100644 --- a/detections/web/detect_remote_access_software_usage_url.yml +++ b/detections/web/detect_remote_access_software_usage_url.yml @@ -1,6 +1,6 @@ name: Detect Remote Access Software Usage URL id: 9296f515-073c-43a5-88ec-eda5a4626654 -version: 5 +version: 7 date: '2024-11-15' author: Steven Dick status: production @@ -52,6 +52,10 @@ drilldown_searches: by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ +- name: Investigate traffic to $url_domain$ + search: '| from datamodel:Web | search src=$src$ url_domain=$url_domain$' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ rba: message: A domain for a known remote access software $url_domain$ was contacted by $src$. @@ -65,12 +69,15 @@ rba: threat_objects: - field: url_domain type: domain + - field: signature + type: signature tags: analytic_story: - Insider Threat - Command And Control - Ransomware - CISA AA24-241A + - Remote Monitoring and Management Software asset_type: Network mitre_attack_id: - T1219 diff --git a/detections/web/exploit_public_facing_application_via_apache_commons_text.yml b/detections/web/exploit_public_facing_application_via_apache_commons_text.yml index d9b87dfcf0..162db64b40 100644 --- a/detections/web/exploit_public_facing_application_via_apache_commons_text.yml +++ b/detections/web/exploit_public_facing_application_via_apache_commons_text.yml @@ -1,7 +1,7 @@ name: Exploit Public Facing Application via Apache Commons Text id: 19a481e0-c97c-4d14-b1db-75a708eb592e -version: 5 -date: '2024-11-15' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -72,10 +72,9 @@ tags: cve: - CVE-2022-42889 mitre_attack_id: - - T1505.003 - - T1505 - - T1190 - T1133 + - T1190 + - T1505.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/web/multiple_archive_files_http_post_traffic.yml b/detections/web/multiple_archive_files_http_post_traffic.yml index 725f31561f..7e4978a2c5 100644 --- a/detections/web/multiple_archive_files_http_post_traffic.yml +++ b/detections/web/multiple_archive_files_http_post_traffic.yml @@ -1,7 +1,7 @@ name: Multiple Archive Files Http Post Traffic id: 4477f3ea-a28f-11eb-b762-acde48001122 -version: 5 -date: '2024-11-15' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1048.003 - - T1048 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/web/plain_http_post_exfiltrated_data.yml b/detections/web/plain_http_post_exfiltrated_data.yml index f94dbe9139..1272c755a0 100644 --- a/detections/web/plain_http_post_exfiltrated_data.yml +++ b/detections/web/plain_http_post_exfiltrated_data.yml @@ -1,7 +1,7 @@ name: Plain HTTP POST Exfiltrated Data id: e2b36208-a364-11eb-8909-acde48001122 -version: 5 -date: '2024-11-15' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -55,7 +55,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1048.003 - - T1048 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/web/spring4shell_payload_url_request.yml b/detections/web/spring4shell_payload_url_request.yml index 1ba92e50e9..adec62590e 100644 --- a/detections/web/spring4shell_payload_url_request.yml +++ b/detections/web/spring4shell_payload_url_request.yml @@ -1,7 +1,7 @@ name: Spring4Shell Payload URL Request id: 9d44d649-7d67-4559-95c1-8022ff49420b -version: 4 -date: '2024-11-15' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -57,10 +57,9 @@ tags: cve: - CVE-2022-22965 mitre_attack_id: - - T1505.003 - - T1505 - - T1190 - T1133 + - T1190 + - T1505.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/web/web_jsp_request_via_url.yml b/detections/web/web_jsp_request_via_url.yml index 3aea7b2a94..fbf4f4991c 100644 --- a/detections/web/web_jsp_request_via_url.yml +++ b/detections/web/web_jsp_request_via_url.yml @@ -1,7 +1,7 @@ name: Web JSP Request via URL id: 2850c734-2d44-4431-8139-1a56f6f54c01 -version: 4 -date: '2024-11-15' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -58,10 +58,9 @@ tags: cve: - CVE-2022-22965 mitre_attack_id: - - T1505.003 - - T1505 - - T1190 - T1133 + - T1190 + - T1505.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/web/zscaler_adware_activities_threat_blocked.yml b/detections/web/zscaler_adware_activities_threat_blocked.yml index f662cc0a16..c47abd8740 100644 --- a/detections/web/zscaler_adware_activities_threat_blocked.yml +++ b/detections/web/zscaler_adware_activities_threat_blocked.yml @@ -1,6 +1,6 @@ name: Zscaler Adware Activities Threat Blocked id: 3407b250-345a-4d71-80db-c91e555a3ece -version: 4 +version: 5 date: '2024-11-15' author: Gowthamaraj Rajendran, Splunk status: production diff --git a/detections/web/zscaler_behavior_analysis_threat_blocked.yml b/detections/web/zscaler_behavior_analysis_threat_blocked.yml index 8875d8762b..8a55d3f407 100644 --- a/detections/web/zscaler_behavior_analysis_threat_blocked.yml +++ b/detections/web/zscaler_behavior_analysis_threat_blocked.yml @@ -1,6 +1,6 @@ name: Zscaler Behavior Analysis Threat Blocked id: 289ad59f-8939-4331-b805-f2bd51d36fb8 -version: 4 +version: 5 date: '2024-11-15' author: Rod Soto, Gowthamaraj Rajendran, Splunk status: production diff --git a/detections/web/zscaler_exploit_threat_blocked.yml b/detections/web/zscaler_exploit_threat_blocked.yml index 0da0906592..e88d087743 100644 --- a/detections/web/zscaler_exploit_threat_blocked.yml +++ b/detections/web/zscaler_exploit_threat_blocked.yml @@ -1,6 +1,6 @@ name: Zscaler Exploit Threat Blocked id: 94665d8c-b841-4ff4-acb4-34d613e2cbfe -version: 4 +version: 5 date: '2024-11-15' author: Rod Soto, Gowthamaraj Rajendran, Splunk status: production diff --git a/detections/web/zscaler_malware_activity_threat_blocked.yml b/detections/web/zscaler_malware_activity_threat_blocked.yml index 3494bd9e23..34061dc5be 100644 --- a/detections/web/zscaler_malware_activity_threat_blocked.yml +++ b/detections/web/zscaler_malware_activity_threat_blocked.yml @@ -1,6 +1,6 @@ name: Zscaler Malware Activity Threat Blocked id: ae874ad8-e353-40a7-87d4-420cdfb27d1a -version: 4 +version: 5 date: '2024-11-15' author: Rod Soto, Gowthamaraj Rajendran, Splunk status: production diff --git a/detections/web/zscaler_potentially_abused_file_download.yml b/detections/web/zscaler_potentially_abused_file_download.yml index 040b02ae71..f18bdfe4f0 100644 --- a/detections/web/zscaler_potentially_abused_file_download.yml +++ b/detections/web/zscaler_potentially_abused_file_download.yml @@ -1,6 +1,6 @@ name: Zscaler Potentially Abused File Download id: b0c21379-f4ba-4bac-a958-897e260f964a -version: 4 +version: 5 date: '2024-11-15' author: Gowthamaraj Rajendran, Rod Soto, Splunk status: production diff --git a/detections/web/zscaler_privacy_risk_destinations_threat_blocked.yml b/detections/web/zscaler_privacy_risk_destinations_threat_blocked.yml index cad5f20065..abf94751e3 100644 --- a/detections/web/zscaler_privacy_risk_destinations_threat_blocked.yml +++ b/detections/web/zscaler_privacy_risk_destinations_threat_blocked.yml @@ -1,6 +1,6 @@ name: Zscaler Privacy Risk Destinations Threat Blocked id: 5456bdef-d765-4565-8e1f-61ca027bc50d -version: 4 +version: 5 date: '2024-11-15' author: Gowthamaraj Rajendran, Rod Soto, Splunk status: production diff --git a/detections/web/zscaler_scam_destinations_threat_blocked.yml b/detections/web/zscaler_scam_destinations_threat_blocked.yml index d91cf5e7e9..5c7281924b 100644 --- a/detections/web/zscaler_scam_destinations_threat_blocked.yml +++ b/detections/web/zscaler_scam_destinations_threat_blocked.yml @@ -1,6 +1,6 @@ name: Zscaler Scam Destinations Threat Blocked id: a0c21379-f4ba-4bac-a958-897e260f964a -version: 4 +version: 5 date: '2024-11-15' author: Gowthamaraj Rajendran, Rod Soto, Splunk status: production diff --git a/detections/web/zscaler_virus_download_threat_blocked.yml b/detections/web/zscaler_virus_download_threat_blocked.yml index 656efd2fac..f0c094a07c 100644 --- a/detections/web/zscaler_virus_download_threat_blocked.yml +++ b/detections/web/zscaler_virus_download_threat_blocked.yml @@ -1,6 +1,6 @@ name: Zscaler Virus Download threat blocked id: aa19e627-d448-4a31-85cd-82068dec5691 -version: 4 +version: 5 date: '2024-11-15' author: Gowthamaraj Rajendran, Rod Soto, Splunk status: production