From f5cc9deadea4d07f79e6bc46572229124f05bfc0 Mon Sep 17 00:00:00 2001 From: research-bot Date: Fri, 17 Jan 2025 15:31:56 -0800 Subject: [PATCH] stock values for deprecation --- ...bited_processes_to_enterprise_security.yml | 0 .../baseline_of_api_calls_per_user_arn.yml | 0 ..._aws_instances_launched_by_user___mltk.yml | 0 ...ws_instances_terminated_by_user___mltk.yml | 0 .../baselines}/monitor_successful_backups.yml | 0 .../monitor_unsuccessful_backups.yml | 0 ..._api_call_per_user_roles_in_cloudtrail.yml | 0 ...seen_aws_provisioning_activity_sources.yml | 0 .../previously_seen_aws_regions.yml | 0 .../baselines}/previously_seen_ec2_amis.yml | 0 .../previously_seen_ec2_instance_types.yml | 0 .../previously_seen_ec2_launches_by_user.yml | 0 ...viously_seen_ec2_modifications_by_user.yml | 0 .../previously_seen_users_in_cloudtrail.yml | 0 ...ady_for_spectre_meltdown_windows_patch.yml | 0 ...te_previously_seen_users_in_cloudtrail.yml | 0 ...ly_high_aws_instances_launched_by_user.yml | 7 ++ ..._aws_instances_launched_by_user___mltk.yml | 7 ++ ..._high_aws_instances_terminated_by_user.yml | 7 ++ ...ws_instances_terminated_by_user___mltk.yml | 7 ++ .../detections/asl_aws_createaccesskey.yml | 97 +++++++++++++++ .../asl_aws_excessive_security_scanning.yml | 25 ++-- .../asl_aws_password_policy_changes.yml | 43 ++++--- ...ovisioning_from_previously_unseen_city.yml | 31 +++-- ...sioning_from_previously_unseen_country.yml | 25 ++-- ...ning_from_previously_unseen_ip_address.yml | 29 +++-- ...isioning_from_previously_unseen_region.yml | 27 +++-- ...rnetes_cluster_sensitive_object_access.yml | 7 ++ ...nts_connecting_to_multiple_dns_servers.yml | 9 +- ...ud_network_access_control_list_deleted.yml | 7 ++ .../correlation_by_repository_and_risk.yml | 60 +++++++++ .../correlation_by_user_and_risk.yml | 56 +++++++++ ...ivity_related_to_pass_the_hash_attacks.yml | 22 +++- ...ct_api_activity_from_users_without_mfa.yml | 20 ++- ...pi_activities_from_unapproved_accounts.yml | 9 +- ...to_phishing_sites_leveraging_evilginx2.yml | 29 +++-- .../detect_long_dns_txt_record_response.yml | 7 ++ .../detect_mimikatz_using_loaded_images.yml | 14 ++- ...katz_via_powershell_and_eventcode_4703.yml | 7 ++ .../detect_new_api_calls_from_user_roles.yml | 7 ++ .../detect_new_user_aws_console_login.yml | 7 ++ .../detect_spike_in_aws_api_activity.yml | 13 +- .../detect_spike_in_network_acl_activity.yml | 7 ++ ...etect_spike_in_security_group_activity.yml | 7 ++ .../detect_usb_device_insertion.yml | 7 ++ ...eb_traffic_to_dynamic_domain_providers.yml | 9 +- .../detections}/detection_of_dns_tunnels.yml | 7 ++ ...s_resolved_by_unauthorized_dns_servers.yml | 7 ++ .../detections}/dns_record_changed.yml | 28 +++-- .../dump_lsass_via_procdump_rename.yml | 14 ++- ...e_modified_with_previously_unseen_user.yml | 7 ++ ...ce_started_in_previously_unseen_region.yml | 7 ++ ...nce_started_with_previously_unseen_ami.yml | 7 ++ ...d_with_previously_unseen_instance_type.yml | 7 ++ ...ce_started_with_previously_unseen_user.yml | 7 ++ ...n_of_file_with_spaces_before_extension.yml | 7 ++ ...d_without_successful_netbackup_backups.yml | 7 ++ .../first_time_seen_command_line_argument.yml | 7 ++ ...counts_with_high_risk_roles_by_project.yml | 7 ++ ...sk_permissions_by_resource_and_account.yml | 7 ++ .../gcp_detect_oauth_token_abuse.yml | 7 ++ .../gcp_kubernetes_cluster_scan_detection.yml | 7 ++ .../identify_new_user_accounts.yml | 7 ++ ...ct_most_active_service_accounts_by_pod.yml | 7 ++ ...s_detect_rbac_authorization_by_account.yml | 9 +- ...netes_aws_detect_sensitive_role_access.yml | 11 +- ...vice_accounts_forbidden_failure_access.yml | 7 ++ ...tive_service_accounts_by_pod_namespace.yml | 7 ++ ...e_detect_rbac_authorization_by_account.yml | 7 ++ ...s_azure_detect_sensitive_object_access.yml | 7 ++ ...tes_azure_detect_sensitive_role_access.yml | 11 +- ...vice_accounts_forbidden_failure_access.yml | 7 ++ ..._azure_detect_suspicious_kubectl_calls.yml | 7 ++ .../kubernetes_azure_pod_scan_fingerprint.yml | 7 ++ .../kubernetes_azure_scan_fingerprint.yml | 7 ++ ...ct_most_active_service_accounts_by_pod.yml | 7 ++ ..._detect_rbac_authorizations_by_account.yml | 7 ++ ...tes_gcp_detect_sensitive_object_access.yml | 7 ++ ...netes_gcp_detect_sensitive_role_access.yml | 11 +- ...vice_accounts_forbidden_failure_access.yml | 7 ++ ...es_gcp_detect_suspicious_kubectl_calls.yml | 7 ++ .../monitor_dns_for_brand_abuse.yml | 7 ++ ...h_invalid_credentials_from_the_same_ip.yml | 20 +-- ...o365_suspicious_admin_email_forwarding.yml | 14 ++- .../o365_suspicious_rights_delegation.yml | 86 +++++++++++++ .../o365_suspicious_user_email_forwarding.yml | 88 ++++++++++++++ .../detections}/okta_account_locked_out.yml | 23 ++-- .../okta_account_lockout_events.yml | 29 +++-- .../detections}/okta_failed_sso_attempts.yml | 12 +- ..._login_failure_with_high_unknown_users.yml | 60 +++++++++ ...insight_suspected_passwordspray_attack.yml | 59 +++++++++ .../okta_two_or_more_rejected_okta_pushes.yml | 16 ++- .../osquery_pack___coldroot_detection.yml | 7 ++ .../processes_created_by_netsh.yml | 7 ++ .../prohibited_software_on_endpoint.yml | 7 ++ ...de_files_directories_via_registry_keys.yml | 7 ++ .../remote_registry_key_modifications.yml | 7 ++ ...led_tasks_used_in_badrabbit_ransomware.yml | 11 +- ...pectre_and_meltdown_vulnerable_systems.yml | 7 ++ ...uspicious_changes_to_file_associations.yml | 7 ++ .../suspicious_email___uba_anomaly.yml | 7 ++ .../detections}/suspicious_file_write.yml | 7 ++ ...ious_powershell_command_line_arguments.yml | 7 ++ .../suspicious_rundll32_rename.yml | 7 ++ ...us_writes_to_system_volume_information.yml | 11 +- .../uncommon_processes_on_endpoint.yml | 7 ++ .../unsigned_image_loaded_by_lsass.yml | 12 +- .../unsuccessful_netbackup_backups.yml | 7 ++ .../web_fraud___account_harvesting.yml | 7 ++ .../web_fraud___anomalous_user_clickspeed.yml | 7 ++ ...aud___password_sharing_across_accounts.yml | 7 ++ ...indows_connhost_exe_started_forcefully.yml | 15 ++- ...indows_dll_search_order_hijacking_hunt.yml | 10 +- .../windows_hosts_file_modification.yml | 7 ++ .../windows_lateral_tool_transfer_remcom.yml | 114 ++++++++++++++++++ .../all_backup_logs_for_host.yml | 0 ...azon_eks_kubernetes_activity_by_src_ip.yml | 0 ...nvestigate_security_hub_alerts_by_dest.yml | 0 ...stigate_user_activities_by_accesskeyid.yml | 0 ...aws_investigate_user_activities_by_arn.yml | 0 .../aws_network_acl_details_from_id.yml | 0 ...twork_interface_details_via_resourceid.yml | 0 .../aws_s3_bucket_details_via_bucketname.yml | 0 .../gcp_kubernetes_activity_by_src_ip.yml | 0 .../get_all_aws_activity_from_city.yml | 0 .../get_all_aws_activity_from_country.yml | 0 .../get_all_aws_activity_from_ip_address.yml | 0 .../get_all_aws_activity_from_region.yml | 0 .../get_backup_logs_for_endpoint.yml | 0 .../get_certificate_logs_for_a_domain.yml | 0 .../get_dns_server_history_for_a_host.yml | 0 .../investigations}/get_dns_traffic_ratio.yml | 0 ...get_ec2_instance_details_by_instanceid.yml | 0 .../get_ec2_launch_details.yml | 0 .../investigations}/get_email_info.yml | 0 .../get_emails_from_specific_sender.yml | 0 ...e_and_last_occurrence_of_a_mac_address.yml | 0 .../get_history_of_email_sources.yml | 0 ...ogon_rights_modifications_for_endpoint.yml | 0 ...et_logon_rights_modifications_for_user.yml | 0 .../investigations}/get_notable_history.yml | 0 ...d_emails_to_hidden_cobra_threat_actors.yml | 0 .../get_parent_process_info.yml | 0 .../get_process_file_activity.yml | 0 .../investigations}/get_process_info.yml | 0 ..._process_information_for_port_activity.yml | 0 ...rocess_responsible_for_the_dns_traffic.yml | 0 .../get_sysmon_wmi_activity_for_host.yml | 0 ...web_session_information_via_session_id.yml | 0 ...stigate_aws_activities_via_region_name.yml | 0 ...gate_aws_user_activities_by_user_field.yml | 0 ...ailed_logins_for_multiple_destinations.yml | 0 ...nvestigate_network_traffic_from_src_ip.yml | 0 .../investigate_okta_activity_by_app.yml | 0 ...nvestigate_okta_activity_by_ip_address.yml | 0 .../investigate_pass_the_hash_attempts.yml | 0 .../investigate_pass_the_ticket_attempts.yml | 0 .../investigate_previous_unseen_user.yml | 0 ...cessful_remote_desktop_authentications.yml | 0 ...gate_suspicious_strings_in_http_header.yml | 0 .../investigate_user_activities_in_okta.yml | 0 .../investigate_web_posts_from_src.yml | 0 .../lookups}/aws_service_accounts.csv | 0 .../lookups}/aws_service_accounts.yml | 0 .../lookups}/discovered_dns_records.csv | 0 .../lookups}/discovered_dns_records.yml | 0 .../stories}/aws_cryptomining.yml | 0 ...aws_suspicious_provisioning_activities.yml | 0 .../stories}/common_phishing_frameworks.yml | 0 ...lantation_monitoring_and_investigation.yml | 0 .../stories}/host_redirection.yml | 0 .../kubernetes_sensitive_role_activity.yml | 0 .../stories}/lateral_movement.yml | 0 .../stories}/monitor_backup_solution.yml | 0 .../monitor_for_unauthorized_software.yml | 0 .../stories}/office_365_detections.yml | 0 .../spectre_and_meltdown_vulnerabilities.yml | 0 .../suspicious_aws_ec2_activities.yml | 0 .../unusual_aws_ec2_modifications.yml | 0 .../stories}/web_fraud_detection.yml | 0 .../deprecated/asl_aws_createaccesskey.yml | 87 ------------- .../correlation_by_repository_and_risk.yml | 39 ------ .../correlation_by_user_and_risk.yml | 39 ------ .../o365_suspicious_rights_delegation.yml | 55 --------- .../o365_suspicious_user_email_forwarding.yml | 57 --------- ..._login_failure_with_high_unknown_users.yml | 49 -------- ...insight_suspected_passwordspray_attack.yml | 50 -------- .../windows_lateral_tool_transfer_remcom.yml | 78 ------------ .../endpoint/attacker_tools_on_endpoint.yml | 1 - 189 files changed, 1436 insertions(+), 621 deletions(-) rename {baselines/deprecated => deprecated/baselines}/add_prohibited_processes_to_enterprise_security.yml (100%) rename {baselines/deprecated => deprecated/baselines}/baseline_of_api_calls_per_user_arn.yml (100%) rename {baselines/deprecated => deprecated/baselines}/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml (100%) rename {baselines/deprecated => deprecated/baselines}/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml (100%) rename {baselines => deprecated/baselines}/monitor_successful_backups.yml (100%) rename {baselines => deprecated/baselines}/monitor_unsuccessful_backups.yml (100%) rename {baselines/deprecated => deprecated/baselines}/previously_seen_api_call_per_user_roles_in_cloudtrail.yml (100%) rename {baselines/deprecated => deprecated/baselines}/previously_seen_aws_provisioning_activity_sources.yml (100%) rename {baselines => deprecated/baselines}/previously_seen_aws_regions.yml (100%) rename {baselines/deprecated => deprecated/baselines}/previously_seen_ec2_amis.yml (100%) rename {baselines/deprecated => deprecated/baselines}/previously_seen_ec2_instance_types.yml (100%) rename {baselines/deprecated => deprecated/baselines}/previously_seen_ec2_launches_by_user.yml (100%) rename {baselines => deprecated/baselines}/previously_seen_ec2_modifications_by_user.yml (100%) rename {baselines/deprecated => deprecated/baselines}/previously_seen_users_in_cloudtrail.yml (100%) rename {baselines => deprecated/baselines}/systems_ready_for_spectre_meltdown_windows_patch.yml (100%) rename {baselines/deprecated => deprecated/baselines}/update_previously_seen_users_in_cloudtrail.yml (100%) rename {detections/deprecated => deprecated/detections}/abnormally_high_aws_instances_launched_by_user.yml (90%) rename {detections/deprecated => deprecated/detections}/abnormally_high_aws_instances_launched_by_user___mltk.yml (88%) rename {detections/deprecated => deprecated/detections}/abnormally_high_aws_instances_terminated_by_user.yml (90%) rename {detections/deprecated => deprecated/detections}/abnormally_high_aws_instances_terminated_by_user___mltk.yml (88%) create mode 100644 deprecated/detections/asl_aws_createaccesskey.yml rename {detections/deprecated => deprecated/detections}/asl_aws_excessive_security_scanning.yml (60%) rename {detections/deprecated => deprecated/detections}/asl_aws_password_policy_changes.yml (52%) rename {detections/deprecated => deprecated/detections}/aws_cloud_provisioning_from_previously_unseen_city.yml (73%) rename {detections/deprecated => deprecated/detections}/aws_cloud_provisioning_from_previously_unseen_country.yml (77%) rename {detections/deprecated => deprecated/detections}/aws_cloud_provisioning_from_previously_unseen_ip_address.yml (73%) rename {detections/deprecated => deprecated/detections}/aws_cloud_provisioning_from_previously_unseen_region.yml (77%) rename {detections/deprecated => deprecated/detections}/aws_eks_kubernetes_cluster_sensitive_object_access.yml (86%) rename {detections/deprecated => deprecated/detections}/clients_connecting_to_multiple_dns_servers.yml (91%) rename {detections/deprecated => deprecated/detections}/cloud_network_access_control_list_deleted.yml (89%) create mode 100644 deprecated/detections/correlation_by_repository_and_risk.yml create mode 100644 deprecated/detections/correlation_by_user_and_risk.yml rename {detections/deprecated => deprecated/detections}/detect_activity_related_to_pass_the_hash_attacks.yml (70%) rename {detections/deprecated => deprecated/detections}/detect_api_activity_from_users_without_mfa.yml (83%) rename {detections/deprecated => deprecated/detections}/detect_aws_api_activities_from_unapproved_accounts.yml (93%) rename {detections/deprecated => deprecated/detections}/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml (78%) rename {detections/deprecated => deprecated/detections}/detect_long_dns_txt_record_response.yml (92%) rename {detections/deprecated => deprecated/detections}/detect_mimikatz_using_loaded_images.yml (86%) rename {detections/deprecated => deprecated/detections}/detect_mimikatz_via_powershell_and_eventcode_4703.yml (91%) rename {detections/deprecated => deprecated/detections}/detect_new_api_calls_from_user_roles.yml (91%) rename {detections/deprecated => deprecated/detections}/detect_new_user_aws_console_login.yml (91%) rename {detections/deprecated => deprecated/detections}/detect_spike_in_aws_api_activity.yml (93%) rename {detections/deprecated => deprecated/detections}/detect_spike_in_network_acl_activity.yml (93%) rename {detections/deprecated => deprecated/detections}/detect_spike_in_security_group_activity.yml (93%) rename {detections/deprecated => deprecated/detections}/detect_usb_device_insertion.yml (90%) rename {detections/deprecated => deprecated/detections}/detect_web_traffic_to_dynamic_domain_providers.yml (91%) rename {detections/deprecated => deprecated/detections}/detection_of_dns_tunnels.yml (94%) rename {detections/deprecated => deprecated/detections}/dns_query_requests_resolved_by_unauthorized_dns_servers.yml (88%) rename {detections/deprecated => deprecated/detections}/dns_record_changed.yml (77%) rename {detections/deprecated => deprecated/detections}/dump_lsass_via_procdump_rename.yml (82%) rename {detections/deprecated => deprecated/detections}/ec2_instance_modified_with_previously_unseen_user.yml (91%) rename {detections/deprecated => deprecated/detections}/ec2_instance_started_in_previously_unseen_region.yml (90%) rename {detections/deprecated => deprecated/detections}/ec2_instance_started_with_previously_unseen_ami.yml (91%) rename {detections/deprecated => deprecated/detections}/ec2_instance_started_with_previously_unseen_instance_type.yml (91%) rename {detections/deprecated => deprecated/detections}/ec2_instance_started_with_previously_unseen_user.yml (91%) rename {detections/deprecated => deprecated/detections}/execution_of_file_with_spaces_before_extension.yml (91%) rename {detections/deprecated => deprecated/detections}/extended_period_without_successful_netbackup_backups.yml (88%) rename {detections/deprecated => deprecated/detections}/first_time_seen_command_line_argument.yml (93%) rename {detections/deprecated => deprecated/detections}/gcp_detect_accounts_with_high_risk_roles_by_project.yml (91%) rename {detections/deprecated => deprecated/detections}/gcp_detect_high_risk_permissions_by_resource_and_account.yml (90%) rename {detections/deprecated => deprecated/detections}/gcp_detect_oauth_token_abuse.yml (88%) rename {detections/deprecated => deprecated/detections}/gcp_kubernetes_cluster_scan_detection.yml (90%) rename {detections/deprecated => deprecated/detections}/identify_new_user_accounts.yml (87%) rename {detections/deprecated => deprecated/detections}/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml (86%) rename {detections/deprecated => deprecated/detections}/kubernetes_aws_detect_rbac_authorization_by_account.yml (85%) rename {detections/deprecated => deprecated/detections}/kubernetes_aws_detect_sensitive_role_access.yml (79%) rename {detections/deprecated => deprecated/detections}/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml (86%) rename {detections/deprecated => deprecated/detections}/kubernetes_azure_active_service_accounts_by_pod_namespace.yml (87%) rename {detections/deprecated => deprecated/detections}/kubernetes_azure_detect_rbac_authorization_by_account.yml (87%) rename {detections/deprecated => deprecated/detections}/kubernetes_azure_detect_sensitive_object_access.yml (86%) rename {detections/deprecated => deprecated/detections}/kubernetes_azure_detect_sensitive_role_access.yml (79%) rename {detections/deprecated => deprecated/detections}/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml (86%) rename {detections/deprecated => deprecated/detections}/kubernetes_azure_detect_suspicious_kubectl_calls.yml (88%) rename {detections/deprecated => deprecated/detections}/kubernetes_azure_pod_scan_fingerprint.yml (85%) rename {detections/deprecated => deprecated/detections}/kubernetes_azure_scan_fingerprint.yml (85%) rename {detections/deprecated => deprecated/detections}/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml (87%) rename {detections/deprecated => deprecated/detections}/kubernetes_gcp_detect_rbac_authorizations_by_account.yml (86%) rename {detections/deprecated => deprecated/detections}/kubernetes_gcp_detect_sensitive_object_access.yml (86%) rename {detections/deprecated => deprecated/detections}/kubernetes_gcp_detect_sensitive_role_access.yml (80%) rename {detections/deprecated => deprecated/detections}/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml (88%) rename {detections/deprecated => deprecated/detections}/kubernetes_gcp_detect_suspicious_kubectl_calls.yml (87%) rename {detections/deprecated => deprecated/detections}/monitor_dns_for_brand_abuse.yml (88%) rename {detections/deprecated => deprecated/detections}/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml (78%) rename {detections/deprecated => deprecated/detections}/o365_suspicious_admin_email_forwarding.yml (78%) create mode 100644 deprecated/detections/o365_suspicious_rights_delegation.yml create mode 100644 deprecated/detections/o365_suspicious_user_email_forwarding.yml rename {detections/deprecated => deprecated/detections}/okta_account_locked_out.yml (66%) rename {detections/deprecated => deprecated/detections}/okta_account_lockout_events.yml (65%) rename {detections/deprecated => deprecated/detections}/okta_failed_sso_attempts.yml (77%) create mode 100644 deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml create mode 100644 deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml rename {detections/deprecated => deprecated/detections}/okta_two_or_more_rejected_okta_pushes.yml (79%) rename {detections/deprecated => deprecated/detections}/osquery_pack___coldroot_detection.yml (87%) rename {detections/deprecated => deprecated/detections}/processes_created_by_netsh.yml (92%) rename {detections/deprecated => deprecated/detections}/prohibited_software_on_endpoint.yml (90%) rename {detections/deprecated => deprecated/detections}/reg_exe_used_to_hide_files_directories_via_registry_keys.yml (91%) rename {detections/deprecated => deprecated/detections}/remote_registry_key_modifications.yml (89%) rename {detections/deprecated => deprecated/detections}/scheduled_tasks_used_in_badrabbit_ransomware.yml (85%) rename {detections/deprecated => deprecated/detections}/spectre_and_meltdown_vulnerable_systems.yml (87%) rename {detections/deprecated => deprecated/detections}/suspicious_changes_to_file_associations.yml (92%) rename {detections/deprecated => deprecated/detections}/suspicious_email___uba_anomaly.yml (90%) rename {detections/deprecated => deprecated/detections}/suspicious_file_write.yml (90%) rename {detections/deprecated => deprecated/detections}/suspicious_powershell_command_line_arguments.yml (92%) rename {detections/deprecated => deprecated/detections}/suspicious_rundll32_rename.yml (93%) rename {detections/deprecated => deprecated/detections}/suspicious_writes_to_system_volume_information.yml (78%) rename {detections/deprecated => deprecated/detections}/uncommon_processes_on_endpoint.yml (89%) rename {detections/deprecated => deprecated/detections}/unsigned_image_loaded_by_lsass.yml (82%) rename {detections/deprecated => deprecated/detections}/unsuccessful_netbackup_backups.yml (85%) rename {detections/deprecated => deprecated/detections}/web_fraud___account_harvesting.yml (92%) rename {detections/deprecated => deprecated/detections}/web_fraud___anomalous_user_clickspeed.yml (91%) rename {detections/deprecated => deprecated/detections}/web_fraud___password_sharing_across_accounts.yml (90%) rename {detections/deprecated => deprecated/detections}/windows_connhost_exe_started_forcefully.yml (80%) rename {detections/deprecated => deprecated/detections}/windows_dll_search_order_hijacking_hunt.yml (92%) rename {detections/deprecated => deprecated/detections}/windows_hosts_file_modification.yml (88%) create mode 100644 deprecated/detections/windows_lateral_tool_transfer_remcom.yml rename {investigations => deprecated/investigations}/all_backup_logs_for_host.yml (100%) rename {investigations => deprecated/investigations}/amazon_eks_kubernetes_activity_by_src_ip.yml (100%) rename {investigations => deprecated/investigations}/aws_investigate_security_hub_alerts_by_dest.yml (100%) rename {investigations => deprecated/investigations}/aws_investigate_user_activities_by_accesskeyid.yml (100%) rename {investigations => deprecated/investigations}/aws_investigate_user_activities_by_arn.yml (100%) rename {investigations => deprecated/investigations}/aws_network_acl_details_from_id.yml (100%) rename {investigations => deprecated/investigations}/aws_network_interface_details_via_resourceid.yml (100%) rename {investigations => deprecated/investigations}/aws_s3_bucket_details_via_bucketname.yml (100%) rename {investigations => deprecated/investigations}/gcp_kubernetes_activity_by_src_ip.yml (100%) rename {investigations => deprecated/investigations}/get_all_aws_activity_from_city.yml (100%) rename {investigations => deprecated/investigations}/get_all_aws_activity_from_country.yml (100%) rename {investigations => deprecated/investigations}/get_all_aws_activity_from_ip_address.yml (100%) rename {investigations => deprecated/investigations}/get_all_aws_activity_from_region.yml (100%) rename {investigations => deprecated/investigations}/get_backup_logs_for_endpoint.yml (100%) rename {investigations => deprecated/investigations}/get_certificate_logs_for_a_domain.yml (100%) rename {investigations => deprecated/investigations}/get_dns_server_history_for_a_host.yml (100%) rename {investigations => deprecated/investigations}/get_dns_traffic_ratio.yml (100%) rename {investigations => deprecated/investigations}/get_ec2_instance_details_by_instanceid.yml (100%) rename {investigations => deprecated/investigations}/get_ec2_launch_details.yml (100%) rename {investigations => deprecated/investigations}/get_email_info.yml (100%) rename {investigations => deprecated/investigations}/get_emails_from_specific_sender.yml (100%) rename {investigations => deprecated/investigations}/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml (100%) rename {investigations => deprecated/investigations}/get_history_of_email_sources.yml (100%) rename {investigations => deprecated/investigations}/get_logon_rights_modifications_for_endpoint.yml (100%) rename {investigations => deprecated/investigations}/get_logon_rights_modifications_for_user.yml (100%) rename {investigations => deprecated/investigations}/get_notable_history.yml (100%) rename {investigations => deprecated/investigations}/get_outbound_emails_to_hidden_cobra_threat_actors.yml (100%) rename {investigations => deprecated/investigations}/get_parent_process_info.yml (100%) rename {investigations => deprecated/investigations}/get_process_file_activity.yml (100%) rename {investigations => deprecated/investigations}/get_process_info.yml (100%) rename {investigations => deprecated/investigations}/get_process_information_for_port_activity.yml (100%) rename {investigations => deprecated/investigations}/get_process_responsible_for_the_dns_traffic.yml (100%) rename {investigations => deprecated/investigations}/get_sysmon_wmi_activity_for_host.yml (100%) rename {investigations => deprecated/investigations}/get_web_session_information_via_session_id.yml (100%) rename {investigations => deprecated/investigations}/investigate_aws_activities_via_region_name.yml (100%) rename {investigations => deprecated/investigations}/investigate_aws_user_activities_by_user_field.yml (100%) rename {investigations => deprecated/investigations}/investigate_failed_logins_for_multiple_destinations.yml (100%) rename {investigations => deprecated/investigations}/investigate_network_traffic_from_src_ip.yml (100%) rename {investigations => deprecated/investigations}/investigate_okta_activity_by_app.yml (100%) rename {investigations => deprecated/investigations}/investigate_okta_activity_by_ip_address.yml (100%) rename {investigations => deprecated/investigations}/investigate_pass_the_hash_attempts.yml (100%) rename {investigations => deprecated/investigations}/investigate_pass_the_ticket_attempts.yml (100%) rename {investigations => deprecated/investigations}/investigate_previous_unseen_user.yml (100%) rename {investigations => deprecated/investigations}/investigate_successful_remote_desktop_authentications.yml (100%) rename {investigations => deprecated/investigations}/investigate_suspicious_strings_in_http_header.yml (100%) rename {investigations => deprecated/investigations}/investigate_user_activities_in_okta.yml (100%) rename {investigations => deprecated/investigations}/investigate_web_posts_from_src.yml (100%) rename {lookups => deprecated/lookups}/aws_service_accounts.csv (100%) rename {lookups => deprecated/lookups}/aws_service_accounts.yml (100%) rename {lookups => deprecated/lookups}/discovered_dns_records.csv (100%) rename {lookups => deprecated/lookups}/discovered_dns_records.yml (100%) rename {stories/deprecated => deprecated/stories}/aws_cryptomining.yml (100%) rename {stories/deprecated => deprecated/stories}/aws_suspicious_provisioning_activities.yml (100%) rename {stories/deprecated => deprecated/stories}/common_phishing_frameworks.yml (100%) rename {stories/deprecated => deprecated/stories}/container_implantation_monitoring_and_investigation.yml (100%) rename {stories/deprecated => deprecated/stories}/host_redirection.yml (100%) rename {stories/deprecated => deprecated/stories}/kubernetes_sensitive_role_activity.yml (100%) rename {stories/deprecated => deprecated/stories}/lateral_movement.yml (100%) rename {stories/deprecated => deprecated/stories}/monitor_backup_solution.yml (100%) rename {stories/deprecated => deprecated/stories}/monitor_for_unauthorized_software.yml (100%) rename {stories/deprecated => deprecated/stories}/office_365_detections.yml (100%) rename {stories/deprecated => deprecated/stories}/spectre_and_meltdown_vulnerabilities.yml (100%) rename {stories/deprecated => deprecated/stories}/suspicious_aws_ec2_activities.yml (100%) rename {stories/deprecated => deprecated/stories}/unusual_aws_ec2_modifications.yml (100%) rename {stories/deprecated => deprecated/stories}/web_fraud_detection.yml (100%) delete mode 100644 detections/deprecated/asl_aws_createaccesskey.yml delete mode 100644 detections/deprecated/correlation_by_repository_and_risk.yml delete mode 100644 detections/deprecated/correlation_by_user_and_risk.yml delete mode 100644 detections/deprecated/o365_suspicious_rights_delegation.yml delete mode 100644 detections/deprecated/o365_suspicious_user_email_forwarding.yml delete mode 100644 detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml delete mode 100644 detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml delete mode 100644 detections/deprecated/windows_lateral_tool_transfer_remcom.yml diff --git a/baselines/deprecated/add_prohibited_processes_to_enterprise_security.yml b/deprecated/baselines/add_prohibited_processes_to_enterprise_security.yml similarity index 100% rename from baselines/deprecated/add_prohibited_processes_to_enterprise_security.yml rename to deprecated/baselines/add_prohibited_processes_to_enterprise_security.yml diff --git a/baselines/deprecated/baseline_of_api_calls_per_user_arn.yml b/deprecated/baselines/baseline_of_api_calls_per_user_arn.yml similarity index 100% rename from baselines/deprecated/baseline_of_api_calls_per_user_arn.yml rename to deprecated/baselines/baseline_of_api_calls_per_user_arn.yml diff --git a/baselines/deprecated/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml b/deprecated/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml similarity index 100% rename from baselines/deprecated/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml rename to deprecated/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml diff --git a/baselines/deprecated/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml b/deprecated/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml similarity index 100% rename from baselines/deprecated/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml rename to deprecated/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml diff --git a/baselines/monitor_successful_backups.yml b/deprecated/baselines/monitor_successful_backups.yml similarity index 100% rename from baselines/monitor_successful_backups.yml rename to deprecated/baselines/monitor_successful_backups.yml diff --git a/baselines/monitor_unsuccessful_backups.yml b/deprecated/baselines/monitor_unsuccessful_backups.yml similarity index 100% rename from baselines/monitor_unsuccessful_backups.yml rename to deprecated/baselines/monitor_unsuccessful_backups.yml diff --git a/baselines/deprecated/previously_seen_api_call_per_user_roles_in_cloudtrail.yml b/deprecated/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml similarity index 100% rename from baselines/deprecated/previously_seen_api_call_per_user_roles_in_cloudtrail.yml rename to deprecated/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml diff --git a/baselines/deprecated/previously_seen_aws_provisioning_activity_sources.yml b/deprecated/baselines/previously_seen_aws_provisioning_activity_sources.yml similarity index 100% rename from baselines/deprecated/previously_seen_aws_provisioning_activity_sources.yml rename to deprecated/baselines/previously_seen_aws_provisioning_activity_sources.yml diff --git a/baselines/previously_seen_aws_regions.yml b/deprecated/baselines/previously_seen_aws_regions.yml similarity index 100% rename from baselines/previously_seen_aws_regions.yml rename to deprecated/baselines/previously_seen_aws_regions.yml diff --git a/baselines/deprecated/previously_seen_ec2_amis.yml b/deprecated/baselines/previously_seen_ec2_amis.yml similarity index 100% rename from baselines/deprecated/previously_seen_ec2_amis.yml rename to deprecated/baselines/previously_seen_ec2_amis.yml diff --git a/baselines/deprecated/previously_seen_ec2_instance_types.yml b/deprecated/baselines/previously_seen_ec2_instance_types.yml similarity index 100% rename from baselines/deprecated/previously_seen_ec2_instance_types.yml rename to deprecated/baselines/previously_seen_ec2_instance_types.yml diff --git a/baselines/deprecated/previously_seen_ec2_launches_by_user.yml b/deprecated/baselines/previously_seen_ec2_launches_by_user.yml similarity index 100% rename from baselines/deprecated/previously_seen_ec2_launches_by_user.yml rename to deprecated/baselines/previously_seen_ec2_launches_by_user.yml diff --git a/baselines/previously_seen_ec2_modifications_by_user.yml b/deprecated/baselines/previously_seen_ec2_modifications_by_user.yml similarity index 100% rename from baselines/previously_seen_ec2_modifications_by_user.yml rename to deprecated/baselines/previously_seen_ec2_modifications_by_user.yml diff --git a/baselines/deprecated/previously_seen_users_in_cloudtrail.yml b/deprecated/baselines/previously_seen_users_in_cloudtrail.yml similarity index 100% rename from baselines/deprecated/previously_seen_users_in_cloudtrail.yml rename to deprecated/baselines/previously_seen_users_in_cloudtrail.yml diff --git a/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml b/deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml similarity index 100% rename from baselines/systems_ready_for_spectre_meltdown_windows_patch.yml rename to deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml diff --git a/baselines/deprecated/update_previously_seen_users_in_cloudtrail.yml b/deprecated/baselines/update_previously_seen_users_in_cloudtrail.yml similarity index 100% rename from baselines/deprecated/update_previously_seen_users_in_cloudtrail.yml rename to deprecated/baselines/update_previously_seen_users_in_cloudtrail.yml diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml b/deprecated/detections/abnormally_high_aws_instances_launched_by_user.yml similarity index 90% rename from detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml rename to deprecated/detections/abnormally_high_aws_instances_launched_by_user.yml index 2bf544975c..85eed5f107 100644 --- a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml +++ b/deprecated/detections/abnormally_high_aws_instances_launched_by_user.yml @@ -51,3 +51,10 @@ tags: - userName risk_score: 25.0 security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml b/deprecated/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml similarity index 88% rename from detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml rename to deprecated/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml index 5e87158127..307def30b7 100644 --- a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml +++ b/deprecated/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml @@ -47,3 +47,10 @@ tags: - src_user risk_score: 25.0 security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml b/deprecated/detections/abnormally_high_aws_instances_terminated_by_user.yml similarity index 90% rename from detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml rename to deprecated/detections/abnormally_high_aws_instances_terminated_by_user.yml index 4f19cf183c..4b7dbec756 100644 --- a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml +++ b/deprecated/detections/abnormally_high_aws_instances_terminated_by_user.yml @@ -51,3 +51,10 @@ tags: - userName risk_score: 25 security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml b/deprecated/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml similarity index 88% rename from detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml rename to deprecated/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml index c05b11bc3f..cc3dcea0c6 100644 --- a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml +++ b/deprecated/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml @@ -46,3 +46,10 @@ tags: - src_user risk_score: 25 security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/deprecated/detections/asl_aws_createaccesskey.yml b/deprecated/detections/asl_aws_createaccesskey.yml new file mode 100644 index 0000000000..de8161e3ec --- /dev/null +++ b/deprecated/detections/asl_aws_createaccesskey.yml @@ -0,0 +1,97 @@ +name: ASL AWS CreateAccessKey +id: ccb3e4af-23d6-407f-9842-a26212816c9e +version: 2 +date: '2024-10-17' +author: Patrick Bareiss, Splunk +status: deprecated +type: Hunting +description: This detection rule monitors for the creation of AWS Identity and Access + Management (IAM) access keys. An IAM access key consists of an access key ID and + secret access key, which are used to sign programmatic requests to AWS services. + While IAM access keys can be legitimately used by developers and administrators + for API access, their creation can also be indicative of malicious activity. Attackers + who have gained unauthorized access to an AWS environment might create access keys + as a means to establish persistence or to exfiltrate data through the APIs. Moreover, + because access keys can be used to authenticate with AWS services without the need + for further interaction, they can be particularly appealing for bad actors looking + to operate under the radar. Consequently, it's important to vigilantly monitor and + scrutinize access key creation events, especially if they are associated with unusual + activity or are created by users who don't typically perform these actions. This + hunting query identifies when a potentially compromised user creates a IAM access + key for another user who may have higher privilleges, which can be a sign for privilege + escalation. Hunting queries are designed to be executed manual during threat hunting. +data_source: [] +search: '`amazon_security_lake` api.operation=CreateAccessKey http_request.user_agent!=console.amazonaws.com + api.response.error=null | rename unmapped{}.key as unmapped_key , unmapped{}.value + as unmapped_value | eval keyjoin=mvzip(unmapped_key,unmapped_value) | mvexpand keyjoin + | rex field=keyjoin "^(?[^,]+),(?.*)$" | eval {key} = value | search + responseElements.accessKey.userName = * | rename identity.user.name as identity_user_name, + responseElements.accessKey.userName as responseElements_accessKey_userName | eval + match=if(identity_user_name=responseElements_accessKey_userName,1,0) | search match=0 + | rename identity_user_name as identity.user.name , responseElements_accessKey_userName + as responseElements.accessKey.userName | stats count min(_time) as firstTime max(_time) + as lastTime by responseElements.accessKey.userName api.operation api.service.name + identity.user.account_uid identity.user.credential_uid identity.user.name identity.user.type + identity.user.uid identity.user.uuid http_request.user_agent src_endpoint.ip | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` |`asl_aws_createaccesskey_filter`' +how_to_implement: You must install Splunk Add-On for AWS Version v7.0.0 (https://splunkbase.splunk.com/app/1876) + that includes includes a merge of all the capabilities of the Splunk Add-on for + Amazon Security Lake. This search works with Amazon Security Lake logs which are + parsed in the Open Cybersecurity Schema Framework (OCSF)format. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has legitimately created keys for another user. +references: +- https://bishopfox.com/blog/privilege-escalation-in-aws +- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ +tags: + analytic_story: + - AWS IAM Privilege Escalation + asset_type: AWS Account + confidence: 90 + impact: 70 + message: User $responseElements.accessKey.userName$ is attempting to create access + keys for $responseElements.accessKey.userName$ from this IP $src_endpoint.ip$ + mitre_attack_id: + - T1078 + observable: + - name: src_endpoint.ip + type: IP Address + role: + - Attacker + - name: identity.user.name + type: User + role: + - Attacker + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - api.service.name + - api.operation + - identity.user.account_uid + - identity.user.credential_uid + - identity.user.name + - identity.user.type + - identity.user.uid + - identity.user.uuid + - http_request.user_agent + - src_endpoint.ip + - unmapped{}.key + - unmapped{}.value + risk_score: 63 + security_domain: threat +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/amazon_security_lake.json + sourcetype: aws:asl + source: aws_asl + update_timestamp: true +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/asl_aws_excessive_security_scanning.yml b/deprecated/detections/asl_aws_excessive_security_scanning.yml similarity index 60% rename from detections/deprecated/asl_aws_excessive_security_scanning.yml rename to deprecated/detections/asl_aws_excessive_security_scanning.yml index fdda20b3e0..21ddefa40d 100644 --- a/detections/deprecated/asl_aws_excessive_security_scanning.yml +++ b/deprecated/detections/asl_aws_excessive_security_scanning.yml @@ -9,12 +9,16 @@ description: This search looks for AWS CloudTrail events and analyse the amount eventNames which starts with Describe by a single user. This indicates that this user scans the configuration of your AWS cloud environment. data_source: [] -search: '`amazon_security_lake` api.operation=Describe* OR api.operation=List* OR api.operation=Get* - | stats dc(api.operation) as dc_api_operations min(_time) as firstTime max(_time) as lastTime values(http_request.user_agent) as http_request.user_agent - values(src_endpoint.ip) as src_endpoint.ip values(cloud.region) as cloud.region values(identity.user.account_uid) as identity.user.account_uid by identity.user.name - | where dc_api_operations > 50 | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)`|`asl_aws_excessive_security_scanning_filter`' -how_to_implement: You must install Splunk Add-On for AWS Version v7.0.0 (https://splunkbase.splunk.com/app/1876) that includes includes a merge of all the capabilities of the Splunk Add-on for Amazon Security Lake. This search works with Amazon Security Lake logs which are parsed in the Open Cybersecurity Schema Framework (OCSF)format. +search: '`amazon_security_lake` api.operation=Describe* OR api.operation=List* OR + api.operation=Get* | stats dc(api.operation) as dc_api_operations min(_time) as + firstTime max(_time) as lastTime values(http_request.user_agent) as http_request.user_agent + values(src_endpoint.ip) as src_endpoint.ip values(cloud.region) as cloud.region + values(identity.user.account_uid) as identity.user.account_uid by identity.user.name + | where dc_api_operations > 50 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|`asl_aws_excessive_security_scanning_filter`' +how_to_implement: You must install Splunk Add-On for AWS Version v7.0.0 (https://splunkbase.splunk.com/app/1876) + that includes includes a merge of all the capabilities of the Splunk Add-on for + Amazon Security Lake. This search works with Amazon Security Lake logs which are + parsed in the Open Cybersecurity Schema Framework (OCSF)format. known_false_positives: While this search has no known false positives. references: - https://github.com/aquasecurity/cloudsploit @@ -47,4 +51,11 @@ tags: - http_request.user_agent - src_endpoint.ip risk_score: 18 - security_domain: network \ No newline at end of file + security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/asl_aws_password_policy_changes.yml b/deprecated/detections/asl_aws_password_policy_changes.yml similarity index 52% rename from detections/deprecated/asl_aws_password_policy_changes.yml rename to deprecated/detections/asl_aws_password_policy_changes.yml index 1a66d779cf..5cb7e0ad2a 100644 --- a/detections/deprecated/asl_aws_password_policy_changes.yml +++ b/deprecated/detections/asl_aws_password_policy_changes.yml @@ -5,20 +5,23 @@ date: '2024-10-17' author: Patrick Bareiss, Splunk status: deprecated type: Hunting -description: This search looks for AWS CloudTrail events from Amazon Security Lake where a user is making successful - API calls to view/update/delete the existing password policy in an AWS organization. - It is unlikely for a regular user to conduct this operation. These events may potentially - be malicious, adversaries often use this information to gain more understanding - of the password defenses in place and exploit them to increase their attack surface - when a user account is compromised. +description: This search looks for AWS CloudTrail events from Amazon Security Lake + where a user is making successful API calls to view/update/delete the existing password + policy in an AWS organization. It is unlikely for a regular user to conduct this + operation. These events may potentially be malicious, adversaries often use this + information to gain more understanding of the password defenses in place and exploit + them to increase their attack surface when a user account is compromised. data_source: [] -search: '`amazon_security_lake` "api.service.name"="iam.amazonaws.com" "api.operation" IN ("UpdateAccountPasswordPolicy","GetAccountPasswordPolicy","DeleteAccountPasswordPolicy") "api.response.error"=null - | stats count min(_time) as firstTime max(_time) as lastTime by identity.user.account_uid identity.user.credential_uid identity.user.name - identity.user.type identity.user.uid identity.user.uuid http_request.user_agent src_endpoint.ip cloud.region - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `asl_aws_password_policy_changes_filter`' -how_to_implement: You must install Splunk Add-On for AWS Version v7.0.0 (https://splunkbase.splunk.com/app/1876) that includes includes a merge of all the capabilities of the Splunk Add-on for Amazon Security Lake. This search works with Amazon Security Lake logs which are parsed in the Open Cybersecurity Schema Framework (OCSF)format. +search: '`amazon_security_lake` "api.service.name"="iam.amazonaws.com" "api.operation" + IN ("UpdateAccountPasswordPolicy","GetAccountPasswordPolicy","DeleteAccountPasswordPolicy") + "api.response.error"=null | stats count min(_time) as firstTime max(_time) as lastTime + by identity.user.account_uid identity.user.credential_uid identity.user.name identity.user.type + identity.user.uid identity.user.uuid http_request.user_agent src_endpoint.ip cloud.region + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_password_policy_changes_filter`' +how_to_implement: You must install Splunk Add-On for AWS Version v7.0.0 (https://splunkbase.splunk.com/app/1876) + that includes includes a merge of all the capabilities of the Splunk Add-on for + Amazon Security Lake. This search works with Amazon Security Lake logs which are + parsed in the Open Cybersecurity Schema Framework (OCSF)format. known_false_positives: While this search has no known false positives, it is possible that an AWS admin has legitimately triggered an AWS audit tool activity which may trigger this event. @@ -31,11 +34,12 @@ tags: asset_type: AWS Account confidence: 80 impact: 90 - message: User $identity.user.name$ is attempting to $api.operation$ the password policy for accounts + message: User $identity.user.name$ is attempting to $api.operation$ the password + policy for accounts mitre_attack_id: - T1201 observable: - - name: src_endpoint.ip + - name: src_endpoint.ip type: IP Address role: - Attacker @@ -66,4 +70,11 @@ tests: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/aws_password_policy/amazon_security_lake.json sourcetype: aws:asl source: aws_asl - update_timestamp: true \ No newline at end of file + update_timestamp: true +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_city.yml similarity index 73% rename from detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml rename to deprecated/detections/aws_cloud_provisioning_from_previously_unseen_city.yml index c647d388b3..0c51cdfe3d 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml +++ b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_city.yml @@ -5,10 +5,10 @@ date: '2024-10-17' author: David Dorsey, Splunk status: deprecated type: Anomaly -description: 'This search looks for AWS provisioning activities from previously unseen +description: This search looks for AWS provisioning activities from previously unseen cities. Provisioning activities are defined broadly as any event that begins with "Run" or "Create." This search is deprecated and have been translated to use the - latest Change Datamodel.' + latest Change Datamodel. data_source: [] search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceIPAddress | search City=* [search `cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation @@ -27,16 +27,16 @@ how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or late that have provisioned AWS resources. known_false_positives: 'This is a strictly behavioral search, so we define "false positive" slightly differently. Every time this fires, it will accurately reflect - the first occurrence in the time period you''re searching within, plus what is - stored in the cache feature. But while there are really no "false positives" - in a traditional sense, there is definitely lots of noise. - - This search will fire any time a new city is seen in the **GeoIP** database for any kind of provisioning - activity. If you typically do all provisioning from tools inside of your city, - there should be few false positives. If you are located in countries where the - free version of **MaxMind GeoIP** that ships by default with Splunk has weak resolution - (particularly small countries in less economically powerful regions), this may - be much less valuable to you.' + the first occurrence in the time period you''re searching within, plus what is stored + in the cache feature. But while there are really no "false positives" in a traditional + sense, there is definitely lots of noise. + + This search will fire any time a new city is seen in the **GeoIP** database for + any kind of provisioning activity. If you typically do all provisioning from tools + inside of your city, there should be few false positives. If you are located in + countries where the free version of **MaxMind GeoIP** that ships by default with + Splunk has weak resolution (particularly small countries in less economically powerful + regions), this may be much less valuable to you.' references: [] tags: analytic_story: @@ -62,3 +62,10 @@ tags: - sourceIPAddress risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_country.yml similarity index 77% rename from detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml rename to deprecated/detections/aws_cloud_provisioning_from_previously_unseen_country.yml index 7a6ad8bddf..dbeec54766 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml +++ b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_country.yml @@ -5,10 +5,10 @@ date: '2024-10-17' author: David Dorsey, Splunk status: deprecated type: Anomaly -description: 'This search looks for AWS provisioning activities from previously unseen +description: This search looks for AWS provisioning activities from previously unseen countries. Provisioning activities are defined broadly as any event that begins with "Run" or "Create." This search is deprecated and have been translated to use - the latest Change Datamodel.' + the latest Change Datamodel. data_source: [] search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceIPAddress | search Country=* [search `cloudtrail` (eventName=Run* OR eventName=Create*) | @@ -31,13 +31,13 @@ known_false_positives: 'This is a strictly behavioral search, so we define "fals the first occurrence in the time period you''re searching over plus what is stored in the cache feature. But while there are really no \"false positives\" in a traditional sense, there is definitely lots of noise. - - This search will fire any time a new country is seen in the **GeoIP** database for any kind of provisioning activity. - If you typically do all provisioning from tools inside of your country, there - should be few false positives. If you are located in countries where the free - version of **MaxMind GeoIP** that ships by default with Splunk has weak resolution - (particularly small countries in less economically powerful regions), this may - be much less valuable to you.' + + This search will fire any time a new country is seen in the **GeoIP** database for + any kind of provisioning activity. If you typically do all provisioning from tools + inside of your country, there should be few false positives. If you are located + in countries where the free version of **MaxMind GeoIP** that ships by default with + Splunk has weak resolution (particularly small countries in less economically powerful + regions), this may be much less valuable to you.' references: [] tags: analytic_story: @@ -63,3 +63,10 @@ tags: - sourceIPAddress risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml similarity index 73% rename from detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml rename to deprecated/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml index 145370cb23..12a301e28c 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml +++ b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml @@ -5,10 +5,10 @@ date: '2024-10-17' author: David Dorsey, Splunk status: deprecated type: Anomaly -description: 'This search looks for AWS provisioning activities from previously unseen +description: This search looks for AWS provisioning activities from previously unseen IP addresses. Provisioning activities are defined broadly as any event that begins with "Run" or "Create." This search is deprecated and have been translated to use - the latest Change Datamodel.' + the latest Change Datamodel. data_source: [] search: '`cloudtrail` (eventName=Run* OR eventName=Create*) [search `cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceIPAddress | search Country=* | stats earliest(_time) @@ -27,15 +27,15 @@ how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or late that have provisioned AWS resources. known_false_positives: 'This is a strictly behavioral search, so we define "false positive" slightly differently. Every time this fires, it will accurately reflect - the first occurrence in the time period you''re searching within, plus what is - stored in the cache feature. But while there are really no "false positives" - in a traditional sense, there is definitely lots of noise. - - This search will fire any time a new IP address is seen in the **GeoIP** database for any kind - of provisioning activity. If you typically do all provisioning from tools inside - of your country, there should be few false positives. If you are located in countries - where the free version of **MaxMind GeoIP** that ships by default with Splunk - has weak resolution (particularly small countries in less economically powerful + the first occurrence in the time period you''re searching within, plus what is stored + in the cache feature. But while there are really no "false positives" in a traditional + sense, there is definitely lots of noise. + + This search will fire any time a new IP address is seen in the **GeoIP** database + for any kind of provisioning activity. If you typically do all provisioning from + tools inside of your country, there should be few false positives. If you are located + in countries where the free version of **MaxMind GeoIP** that ships by default with + Splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you.' references: [] tags: @@ -60,3 +60,10 @@ tags: - sourceIPAddress risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_region.yml similarity index 77% rename from detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml rename to deprecated/detections/aws_cloud_provisioning_from_previously_unseen_region.yml index 9dfc9679ef..8600eb155d 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml +++ b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_region.yml @@ -27,16 +27,16 @@ how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or late that have provisioned AWS resources. known_false_positives: 'This is a strictly behavioral search, so we define "false positive" slightly differently. Every time this fires, it will accurately reflect - the first occurrence in the time period you''re searching within, plus what is - stored in the cache feature. But while there are really no "false positives" - in a traditional sense, there is definitely lots of noise. - - This search will fire any time a new region is seen in the **GeoIP** database for any kind of provisioning - activity. If you typically do all provisioning from tools inside of your region, - there should be few false positives. If you are located in regions where the free - version of **MaxMind GeoIP** that ships by default with Splunk has weak resolution - (particularly small countries in less economically powerful regions), this may - be much less valuable to you.' + the first occurrence in the time period you''re searching within, plus what is stored + in the cache feature. But while there are really no "false positives" in a traditional + sense, there is definitely lots of noise. + + This search will fire any time a new region is seen in the **GeoIP** database for + any kind of provisioning activity. If you typically do all provisioning from tools + inside of your region, there should be few false positives. If you are located in + regions where the free version of **MaxMind GeoIP** that ships by default with Splunk + has weak resolution (particularly small countries in less economically powerful + regions), this may be much less valuable to you.' references: [] tags: analytic_story: @@ -66,3 +66,10 @@ tags: - sourceIPAddress risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml b/deprecated/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml similarity index 86% rename from detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml rename to deprecated/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml index 9383a5975a..8e98f72783 100644 --- a/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml +++ b/deprecated/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml @@ -37,3 +37,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml b/deprecated/detections/clients_connecting_to_multiple_dns_servers.yml similarity index 91% rename from detections/deprecated/clients_connecting_to_multiple_dns_servers.yml rename to deprecated/detections/clients_connecting_to_multiple_dns_servers.yml index c34d8a2bb0..691b938e92 100644 --- a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml +++ b/deprecated/detections/clients_connecting_to_multiple_dns_servers.yml @@ -21,7 +21,7 @@ how_to_implement: 'This search requires that DNS data is being ingested and popu contribute additional context to the notable. To see the additional metadata, add the following fields, if not already present, to Incident Review - Event Attributes (Configure > Incident Management > Incident Review Settings > Add New Entry): - + * **Label:** Distinct DNS Connections, **Field:** dest_count Detailed documentation on how to create a new field within Incident Review may be @@ -57,3 +57,10 @@ tags: - DNS.src risk_score: 25 security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/cloud_network_access_control_list_deleted.yml b/deprecated/detections/cloud_network_access_control_list_deleted.yml similarity index 89% rename from detections/deprecated/cloud_network_access_control_list_deleted.yml rename to deprecated/detections/cloud_network_access_control_list_deleted.yml index 37556f398f..f20c12b374 100644 --- a/detections/deprecated/cloud_network_access_control_list_deleted.yml +++ b/deprecated/detections/cloud_network_access_control_list_deleted.yml @@ -50,3 +50,10 @@ tags: - arn risk_score: 25 security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/deprecated/detections/correlation_by_repository_and_risk.yml b/deprecated/detections/correlation_by_repository_and_risk.yml new file mode 100644 index 0000000000..2a2c850641 --- /dev/null +++ b/deprecated/detections/correlation_by_repository_and_risk.yml @@ -0,0 +1,60 @@ +name: Correlation by Repository and Risk +id: 8da9fdd9-6a1b-4ae0-8a34-8c25e6be9687 +version: 2 +date: '2024-10-17' +author: Patrick Bareiss, Splunk +status: deprecated +type: Correlation +description: This search has been deprecated and updated with Risk Rule for Dev Sec + Ops by Repository detection. The following analytic detects by correlating repository + and risk score to identify patterns and trends in the data based on the level of + risk associated. The analytic adds any null values and calculates the sum of the + risk scores for each detection. Then, the analytic captures the source and user + information for each detection and sorts the results in ascending order based on + the risk score. Finally, the analytic filters the detections with a risk score below + 80 and focuses only on high-risk detections.This detection is important because + it provides valuable insights into the distribution of high-risk activities across + different repositories. It also identifies the most vulnerable repositories that + are frequently targeted by potential threats. Additionally, it proactively detects + and responds to potential threats, thereby minimizing the impact of attacks and + safeguarding critical assets. Finally, it provides a comprehensive view of the risk + landscape and helps to make informed decisions to protect the organization's data + and infrastructure. False positives might occur so it is important to identify the + impact of the attack and prioritize response and mitigation efforts. +data_source: [] +search: '`risk_index` | fillnull | stats sum(risk_score) as risk_score values(source) + as signals values(user) as user by repository | sort - risk_score | where risk_score + > 80 | `correlation_by_repository_and_risk_filter`' +how_to_implement: For Dev Sec Ops POC +known_false_positives: unknown +references: [] +tags: + analytic_story: + - Dev Sec Ops + asset_type: AWS Account + confidence: 100 + impact: 70 + message: Correlation triggered for user $user$ + mitre_attack_id: + - T1204.003 + - T1204 + observable: + - name: user + type: User + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + risk_score: 70 + security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/deprecated/detections/correlation_by_user_and_risk.yml b/deprecated/detections/correlation_by_user_and_risk.yml new file mode 100644 index 0000000000..c622de19e5 --- /dev/null +++ b/deprecated/detections/correlation_by_user_and_risk.yml @@ -0,0 +1,56 @@ +name: Correlation by User and Risk +id: 610e12dc-b6fa-4541-825e-4a0b3b6f6773 +version: 2 +date: '2024-10-17' +author: Patrick Bareiss, Splunk +status: deprecated +type: Correlation +description: The following analytic detects the correlation between the user and risk + score and identifies users with a high risk score that pose a significant security + risk such as unauthorized access attempts, suspicious behavior, or potential insider + threats. Next, the analytic calculates the sum of the risk scores and groups the + results by user, the corresponding signals, and the repository. The results are + sorted in descending order based on the risk score and filtered to include records + with a risk score greater than 80. Finally, the results are passed through a correlation + filter specific to the user and risk. This detection is important because it identifies + users who have a high risk score and helps to prioritize investigations and allocate + resources. False positives might occur but the impact of such an attack can vary + depending on the specific scenario such as data exfiltration, system compromise, + or the disruption of critical services. Please investigate this notable event. +data_source: [] +search: '`risk_index` | fillnull | stats sum(risk_score) as risk_score values(source) + as signals values(repository) as repository by user | sort - risk_score | where + risk_score > 80 | `correlation_by_user_and_risk_filter`' +how_to_implement: For Dev Sec Ops POC +known_false_positives: unknown +references: [] +tags: + analytic_story: + - Dev Sec Ops + asset_type: AWS Account + confidence: 100 + impact: 70 + message: Correlation triggered for user $user$ + mitre_attack_id: + - T1204.003 + - T1204 + observable: + - name: user + type: User + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + risk_score: 70 + security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml b/deprecated/detections/detect_activity_related_to_pass_the_hash_attacks.yml similarity index 70% rename from detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml rename to deprecated/detections/detect_activity_related_to_pass_the_hash_attacks.yml index 5ee8df78d5..22025c5ae5 100644 --- a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml +++ b/deprecated/detections/detect_activity_related_to_pass_the_hash_attacks.yml @@ -6,14 +6,17 @@ author: Bhavin Patel, Patrick Bareiss, Splunk status: deprecated type: Hunting description: This search looks for specific authentication events from the Windows - Security Event logs to detect potential attempts at using the Pass-the-Hash technique. This search is DEPRECATED as it is possible for event code 4624 to generate a high level of noise, as legitimate logon events may also trigger this event code. This can be especially true in environments with high levels of user activity, such as those with many concurrent logons or frequent logon attempts. + Security Event logs to detect potential attempts at using the Pass-the-Hash technique. + This search is DEPRECATED as it is possible for event code 4624 to generate a high + level of noise, as legitimate logon events may also trigger this event code. This + can be especially true in environments with high levels of user activity, such as + those with many concurrent logons or frequent logon attempts. data_source: - Windows Event Log Security 4624 -search: '`wineventlog_security` EventCode=4624 (Logon_Type=3 Logon_Process=NtLmSsp NOT AccountName="ANONYMOUS LOGON") OR (Logon_Type=9 Logon_Process=seclogo) - | fillnull - | stats count min(_time) as firstTime max(_time) as lastTime by EventCode, Logon_Type, WorkstationName, user, dest - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` +search: '`wineventlog_security` EventCode=4624 (Logon_Type=3 Logon_Process=NtLmSsp + NOT AccountName="ANONYMOUS LOGON") OR (Logon_Type=9 Logon_Process=seclogo) | fillnull + | stats count min(_time) as firstTime max(_time) as lastTime by EventCode, Logon_Type, + WorkstationName, user, dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_activity_related_to_pass_the_hash_attacks_filter`' how_to_implement: To successfully implement this search, you must ingest your Windows Security Event logs and leverage the latest TA for Windows. @@ -62,3 +65,10 @@ tests: source: WinEventLog:Security sourcetype: WinEventLog update_timestamp: true +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml b/deprecated/detections/detect_api_activity_from_users_without_mfa.yml similarity index 83% rename from detections/deprecated/detect_api_activity_from_users_without_mfa.yml rename to deprecated/detections/detect_api_activity_from_users_without_mfa.yml index 57163720a1..d2a62d1ef7 100644 --- a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml +++ b/deprecated/detections/detect_api_activity_from_users_without_mfa.yml @@ -17,17 +17,18 @@ search: '`cloudtrail` userIdentity.sessionContext.attributes.mfaAuthenticated=fa as user]| stats count min(_time) as firstTime max(_time) as lastTime values(eventName) as eventName by userIdentity.arn userIdentity.type user | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_api_activity_from_users_without_mfa_filter`' - -how_to_implement: 'You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS - (version 4.4.0 or later), then configure your AWS CloudTrail inputs. Leverage the support search `Create - a list of approved AWS service accounts`: run it once every 30 days to create a list of service accounts and validate them. +how_to_implement: 'You must install the AWS App for Splunk (version 5.1.0 or later) + and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail + inputs. Leverage the support search `Create a list of approved AWS service accounts`: + run it once every 30 days to create a list of service accounts and validate them. This search produces fields (`eventName`,`userIdentity.type`,`userIdentity.arn`) that are not yet supported by ES Incident Review and therefore cannot be viewed when a notable event is raised. These fields contribute additional context to the notable. To see the additional metadata, add the following fields, if not already - present, to Incident Review - Event Attributes (Configure > Incident Management > Incident Review Settings > Add New Entry): - + present, to Incident Review - Event Attributes (Configure > Incident Management + > Incident Review Settings > Add New Entry): + * **Label:** AWS Event Name, **Field:** eventName * **Label:** AWS User ARN, **Field:** userIdentity.arn @@ -67,3 +68,10 @@ tags: - user risk_score: 25.0 security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml b/deprecated/detections/detect_aws_api_activities_from_unapproved_accounts.yml similarity index 93% rename from detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml rename to deprecated/detections/detect_aws_api_activities_from_unapproved_accounts.yml index eadfb4cb2e..711bd75a49 100644 --- a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml +++ b/deprecated/detections/detect_aws_api_activities_from_unapproved_accounts.yml @@ -31,7 +31,7 @@ how_to_implement: 'You must install the AWS App for Splunk (version 5.1.0 or lat additional metadata, add the following fields, if not already present, to Incident Review - Event Attributes (Configure > Incident Management > Incident Review Settings > Add New Entry): - + * **Label:** AWS Event Name, **Field:** eventName * **Label:** First Time, **Field:** firstTime @@ -71,3 +71,10 @@ tags: - user risk_score: 25.0 security_domain: access +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml b/deprecated/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml similarity index 78% rename from detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml rename to deprecated/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml index ed39395ce8..59c9e63884 100644 --- a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml +++ b/deprecated/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml @@ -20,21 +20,21 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime | table dest domain url] | table count src dest query answer domain url | `detect_dns_requests_to_phishing_sites_leveraging_evilginx2_filter`' how_to_implement: 'You need to ingest data from your DNS logs in the Network_Resolution datamodel. Specifically you must ingest the domain that is being queried and the - IP of the host originating the request. Ideally, you should also be ingesting - the answer to the query and the query type. This approach allows you to also create + IP of the host originating the request. Ideally, you should also be ingesting the + answer to the query and the query type. This approach allows you to also create your own localized passive DNS capability which can aid you in future investigations. You will have to add legitimate domain names to the `legit_domains.csv` file shipped with the app. - + **Splunk>Phantom Playbook Integration** - - If Splunk>Phantom is also configured in your environment, a Playbook called `Lets Encrypt Domain - Investigate` can be configured to run when any results are found by this detection - search. To use this integration, install the Phantom App for Splunk `https://splunkbase.splunk.com/app/3411/`, - add the correct hostname to the "Phantom Instance" field in the Adaptive Response - Actions when configuring this detection search, and set the corresponding Playbook - to active. - + + If Splunk>Phantom is also configured in your environment, a Playbook called `Lets + Encrypt Domain Investigate` can be configured to run when any results are found + by this detection search. To use this integration, install the Phantom App for Splunk + `https://splunkbase.splunk.com/app/3411/`, add the correct hostname to the "Phantom + Instance" field in the Adaptive Response Actions when configuring this detection + search, and set the corresponding Playbook to active. + (Playbook link:`https://my.phantom.us/4.2/playbook/lets-encrypt-domain-investigate/`)' known_false_positives: If a known good domain is not listed in the legit_domains.csv file, then the search could give you false postives. Please update that lookup file @@ -67,3 +67,10 @@ tags: - host risk_score: 25 security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/detect_long_dns_txt_record_response.yml b/deprecated/detections/detect_long_dns_txt_record_response.yml similarity index 92% rename from detections/deprecated/detect_long_dns_txt_record_response.yml rename to deprecated/detections/detect_long_dns_txt_record_response.yml index 0ee750d14d..e092d9aa27 100644 --- a/detections/deprecated/detect_long_dns_txt_record_response.yml +++ b/deprecated/detections/detect_long_dns_txt_record_response.yml @@ -57,3 +57,10 @@ tags: - DNS.answer risk_score: 25 security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/detect_mimikatz_using_loaded_images.yml b/deprecated/detections/detect_mimikatz_using_loaded_images.yml similarity index 86% rename from detections/deprecated/detect_mimikatz_using_loaded_images.yml rename to deprecated/detections/detect_mimikatz_using_loaded_images.yml index 82d0f52559..c5435b0a50 100644 --- a/detections/deprecated/detect_mimikatz_using_loaded_images.yml +++ b/deprecated/detections/detect_mimikatz_using_loaded_images.yml @@ -6,13 +6,14 @@ author: Patrick Bareiss, Splunk status: deprecated type: TTP description: This search looks for reading loaded Images unique to credential dumping - with Mimikatz. Deprecated because mimikatz libraries changed and very noisy sysmon Event Code. + with Mimikatz. Deprecated because mimikatz libraries changed and very noisy sysmon + Event Code. data_source: - Sysmon EventID 7 search: '`sysmon` EventCode=7 | stats values(ImageLoaded) as ImageLoaded values(ProcessId) as ProcessId by dest, Image | search ImageLoaded=*WinSCard.dll ImageLoaded=*cryptdll.dll - ImageLoaded=*hid.dll ImageLoaded=*samlib.dll ImageLoaded=*vaultcli.dll | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` - | `detect_mimikatz_using_loaded_images_filter`' + ImageLoaded=*hid.dll ImageLoaded=*samlib.dll ImageLoaded=*vaultcli.dll | `security_content_ctime(firstTime)`| + `security_content_ctime(lastTime)` | `detect_mimikatz_using_loaded_images_filter`' how_to_implement: This search needs Sysmon Logs and a sysmon configuration, which includes EventCode 7 with powershell.exe. This search uses an input macro named `sysmon`. We strongly recommend that you specify your environment-specific configurations @@ -70,3 +71,10 @@ tests: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml b/deprecated/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml similarity index 91% rename from detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml rename to deprecated/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml index 3ea450633d..99dd86af2c 100644 --- a/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml +++ b/deprecated/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml @@ -53,3 +53,10 @@ tags: - Process_ID risk_score: 25 security_domain: access +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/detect_new_api_calls_from_user_roles.yml b/deprecated/detections/detect_new_api_calls_from_user_roles.yml similarity index 91% rename from detections/deprecated/detect_new_api_calls_from_user_roles.yml rename to deprecated/detections/detect_new_api_calls_from_user_roles.yml index 1d1e581158..37d677570f 100644 --- a/detections/deprecated/detect_new_api_calls_from_user_roles.yml +++ b/deprecated/detections/detect_new_api_calls_from_user_roles.yml @@ -54,3 +54,10 @@ tags: - eventName risk_score: 25.0 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/detect_new_user_aws_console_login.yml b/deprecated/detections/detect_new_user_aws_console_login.yml similarity index 91% rename from detections/deprecated/detect_new_user_aws_console_login.yml rename to deprecated/detections/detect_new_user_aws_console_login.yml index 0c539bc079..18a97dae15 100644 --- a/detections/deprecated/detect_new_user_aws_console_login.yml +++ b/deprecated/detections/detect_new_user_aws_console_login.yml @@ -51,3 +51,10 @@ tags: - userIdentity.arn risk_score: 25 security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/detect_spike_in_aws_api_activity.yml b/deprecated/detections/detect_spike_in_aws_api_activity.yml similarity index 93% rename from detections/deprecated/detect_spike_in_aws_api_activity.yml rename to deprecated/detections/detect_spike_in_aws_api_activity.yml index 1d4d44c736..9a639938c8 100644 --- a/detections/deprecated/detect_spike_in_aws_api_activity.yml +++ b/deprecated/detections/detect_spike_in_aws_api_activity.yml @@ -38,16 +38,16 @@ how_to_implement: 'You must install the AWS App for Splunk (version 5.1.0 or lat notable. To see the additional metadata, add the following fields, if not already present, to Incident Review - Event Attributes (Configure > Incident Management > Incident Review Settings > Add New Entry): - + * **Label:** AWS Event Name, **Field:** eventName - + * **Label:** Number of API Calls, **Field:** numberOfApiCalls * **Label:** Unique API Calls, **Field:** uniqueApisCalled Detailed documentation on how to create a new field within Incident Review may be found here: `https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Customizenotables#Add_a_field_to_the_notable_event_details`' -known_false_positives: 'None.' +known_false_positives: None. references: [] tags: analytic_story: @@ -73,3 +73,10 @@ tags: - userIdentity.arn risk_score: 25.0 security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/detect_spike_in_network_acl_activity.yml b/deprecated/detections/detect_spike_in_network_acl_activity.yml similarity index 93% rename from detections/deprecated/detect_spike_in_network_acl_activity.yml rename to deprecated/detections/detect_spike_in_network_acl_activity.yml index aad850685d..e535fb7bcf 100644 --- a/detections/deprecated/detect_spike_in_network_acl_activity.yml +++ b/deprecated/detections/detect_spike_in_network_acl_activity.yml @@ -59,3 +59,10 @@ tags: - userIdentity.arn risk_score: 25.0 security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/detect_spike_in_security_group_activity.yml b/deprecated/detections/detect_spike_in_security_group_activity.yml similarity index 93% rename from detections/deprecated/detect_spike_in_security_group_activity.yml rename to deprecated/detections/detect_spike_in_security_group_activity.yml index 83ea1712f8..037ca525fc 100644 --- a/detections/deprecated/detect_spike_in_security_group_activity.yml +++ b/deprecated/detections/detect_spike_in_security_group_activity.yml @@ -60,3 +60,10 @@ tags: - serIdentity.arn risk_score: 25.0 security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/detect_usb_device_insertion.yml b/deprecated/detections/detect_usb_device_insertion.yml similarity index 90% rename from detections/deprecated/detect_usb_device_insertion.yml rename to deprecated/detections/detect_usb_device_insertion.yml index db90a65dd1..0e49d26e52 100644 --- a/detections/deprecated/detect_usb_device_insertion.yml +++ b/deprecated/detections/detect_usb_device_insertion.yml @@ -50,3 +50,10 @@ tags: - All_Changes.dest risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml b/deprecated/detections/detect_web_traffic_to_dynamic_domain_providers.yml similarity index 91% rename from detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml rename to deprecated/detections/detect_web_traffic_to_dynamic_domain_providers.yml index 461584c0ff..bf1579497c 100644 --- a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml +++ b/deprecated/detections/detect_web_traffic_to_dynamic_domain_providers.yml @@ -24,7 +24,7 @@ how_to_implement: 'This search requires you to be ingesting web-traffic logs. Yo contribute additional context to the notable. To see the additional metadata, add the following fields, if not already present, to Incident Review - Event Attributes (Configure > Incident Management > Incident Review Settings > Add New Entry): - + * **Label:** IsDynamicDNS, **Field:** isDynDNS Detailed documentation on how to create a new field within Incident Review may be @@ -59,3 +59,10 @@ tags: - Web.dest risk_score: 25 security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/detection_of_dns_tunnels.yml b/deprecated/detections/detection_of_dns_tunnels.yml similarity index 94% rename from detections/deprecated/detection_of_dns_tunnels.yml rename to deprecated/detections/detection_of_dns_tunnels.yml index a892c3f878..0099a24136 100644 --- a/detections/deprecated/detection_of_dns_tunnels.yml +++ b/deprecated/detections/detection_of_dns_tunnels.yml @@ -72,3 +72,10 @@ tags: - DNS.src risk_score: 25 security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml b/deprecated/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml similarity index 88% rename from detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml rename to deprecated/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml index 5e629764f5..74f8d27df3 100644 --- a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml +++ b/deprecated/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml @@ -48,3 +48,10 @@ tags: - DNS.dest risk_score: 25 security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/dns_record_changed.yml b/deprecated/detections/dns_record_changed.yml similarity index 77% rename from detections/deprecated/dns_record_changed.yml rename to deprecated/detections/dns_record_changed.yml index 86d8f9a32d..2252a3ccc1 100644 --- a/detections/deprecated/dns_record_changed.yml +++ b/deprecated/detections/dns_record_changed.yml @@ -21,18 +21,17 @@ how_to_implement: 'To successfully implement this search you will need to ensure DNS data is populating the `Network_Resolution` data model. It also requires that the `discover_dns_record` lookup table be populated by the included support search "Discover DNS record". - + **Splunk>Phantom Playbook Integration** - - If Splunk>Phantom is also configured in your environment, a Playbook called "DNS Hijack Enrichment" - can be configured to run when any results are found by this detection search. - The playbook takes in the DNS record changed and uses Geoip, whois, Censys and - PassiveTotal to detect if DNS issuers changed. To use this integration, install - the Phantom App for Splunk `https://splunkbase.splunk.com/app/3411/`, add the - correct hostname to the \"Phantom Instance\" field in the Adaptive Response Actions - when configuring this detection search, and set the corresponding Playbook to - active. - + + If Splunk>Phantom is also configured in your environment, a Playbook called "DNS + Hijack Enrichment" can be configured to run when any results are found by this detection + search. The playbook takes in the DNS record changed and uses Geoip, whois, Censys + and PassiveTotal to detect if DNS issuers changed. To use this integration, install + the Phantom App for Splunk `https://splunkbase.splunk.com/app/3411/`, add the correct + hostname to the \"Phantom Instance\" field in the Adaptive Response Actions when + configuring this detection search, and set the corresponding Playbook to active. + (Playbook Link:`https://my.phantom.us/4.2/playbook/dns-hijack-enrichment/`)' known_false_positives: Legitimate DNS changes can be detected in this search. Investigate, verify and update the list of provided current answers for the domains in question @@ -65,3 +64,10 @@ tags: - DNS.query risk_score: 25 security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/dump_lsass_via_procdump_rename.yml b/deprecated/detections/dump_lsass_via_procdump_rename.yml similarity index 82% rename from detections/deprecated/dump_lsass_via_procdump_rename.yml rename to deprecated/detections/dump_lsass_via_procdump_rename.yml index 855f6eb447..cdfa6f9d80 100644 --- a/detections/deprecated/dump_lsass_via_procdump_rename.yml +++ b/deprecated/detections/dump_lsass_via_procdump_rename.yml @@ -17,9 +17,10 @@ description: 'Detect a renamed instance of procdump.exe dumping the lsass proces data_source: - Sysmon EventID 1 search: '`sysmon` OriginalFileName=procdump process_name!=procdump*.exe EventID=1 - (CommandLine=*-ma* OR CommandLine=*-mm*) CommandLine=*lsass* | stats count min(_time) as firstTime max(_time) as lastTime by dest, parent_process_name, - process_name, OriginalFileName, CommandLine | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` | `dump_lsass_via_procdump_rename_filter`' + (CommandLine=*-ma* OR CommandLine=*-mm*) CommandLine=*lsass* | stats count min(_time) + as firstTime max(_time) as lastTime by dest, parent_process_name, process_name, + OriginalFileName, CommandLine | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `dump_lsass_via_procdump_rename_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. @@ -67,3 +68,10 @@ tags: - parent_process_name risk_score: 80 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml b/deprecated/detections/ec2_instance_modified_with_previously_unseen_user.yml similarity index 91% rename from detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml rename to deprecated/detections/ec2_instance_modified_with_previously_unseen_user.yml index 57a1ffc0ed..19b03da337 100644 --- a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml +++ b/deprecated/detections/ec2_instance_modified_with_previously_unseen_user.yml @@ -50,3 +50,10 @@ tags: - userIdentity.arn risk_score: 25.0 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml b/deprecated/detections/ec2_instance_started_in_previously_unseen_region.yml similarity index 90% rename from detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml rename to deprecated/detections/ec2_instance_started_in_previously_unseen_region.yml index 716cabaac4..4f5e068c80 100644 --- a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml +++ b/deprecated/detections/ec2_instance_started_in_previously_unseen_region.yml @@ -48,3 +48,10 @@ tags: - awsRegion risk_score: 25.0 security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml b/deprecated/detections/ec2_instance_started_with_previously_unseen_ami.yml similarity index 91% rename from detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml rename to deprecated/detections/ec2_instance_started_with_previously_unseen_ami.yml index 1079fb6ecd..68c5c09e25 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml +++ b/deprecated/detections/ec2_instance_started_with_previously_unseen_ami.yml @@ -51,3 +51,10 @@ tags: - requestParameters.instancesSet.items{}.imageId risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml b/deprecated/detections/ec2_instance_started_with_previously_unseen_instance_type.yml similarity index 91% rename from detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml rename to deprecated/detections/ec2_instance_started_with_previously_unseen_instance_type.yml index cfcf851d26..87cb3a3d79 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml +++ b/deprecated/detections/ec2_instance_started_with_previously_unseen_instance_type.yml @@ -51,3 +51,10 @@ tags: - requestParameters.instanceType risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml b/deprecated/detections/ec2_instance_started_with_previously_unseen_user.yml similarity index 91% rename from detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml rename to deprecated/detections/ec2_instance_started_with_previously_unseen_user.yml index d7c889af4d..a166707c18 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml +++ b/deprecated/detections/ec2_instance_started_with_previously_unseen_user.yml @@ -52,3 +52,10 @@ tags: - userIdentity.arn risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml b/deprecated/detections/execution_of_file_with_spaces_before_extension.yml similarity index 91% rename from detections/deprecated/execution_of_file_with_spaces_before_extension.yml rename to deprecated/detections/execution_of_file_with_spaces_before_extension.yml index 81d0c1dfc1..a2a45553fb 100644 --- a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml +++ b/deprecated/detections/execution_of_file_with_spaces_before_extension.yml @@ -54,3 +54,10 @@ tags: - Processes.process_name risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml b/deprecated/detections/extended_period_without_successful_netbackup_backups.yml similarity index 88% rename from detections/deprecated/extended_period_without_successful_netbackup_backups.yml rename to deprecated/detections/extended_period_without_successful_netbackup_backups.yml index c69fd4d11c..2ced6406e7 100644 --- a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml +++ b/deprecated/detections/extended_period_without_successful_netbackup_backups.yml @@ -42,3 +42,10 @@ tags: - COMPUTERNAME risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/first_time_seen_command_line_argument.yml b/deprecated/detections/first_time_seen_command_line_argument.yml similarity index 93% rename from detections/deprecated/first_time_seen_command_line_argument.yml rename to deprecated/detections/first_time_seen_command_line_argument.yml index 6f2f93c141..b5a6364f0c 100644 --- a/detections/deprecated/first_time_seen_command_line_argument.yml +++ b/deprecated/detections/first_time_seen_command_line_argument.yml @@ -66,3 +66,10 @@ tags: - Processes.dest risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml b/deprecated/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml similarity index 91% rename from detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml rename to deprecated/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml index fa2a7afa38..e5a3ef7e9b 100644 --- a/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml +++ b/deprecated/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml @@ -53,3 +53,10 @@ tags: - data.protoPayload.response.bindings{}.members{} risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml b/deprecated/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml similarity index 90% rename from detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml rename to deprecated/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml index 2e08af647c..af58e0f84c 100644 --- a/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml +++ b/deprecated/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml @@ -52,3 +52,10 @@ tags: - data.resource.labels.project_id risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/gcp_detect_oauth_token_abuse.yml b/deprecated/detections/gcp_detect_oauth_token_abuse.yml similarity index 88% rename from detections/deprecated/gcp_detect_oauth_token_abuse.yml rename to deprecated/detections/gcp_detect_oauth_token_abuse.yml index 6571a5fe9e..f6ea31f548 100644 --- a/detections/deprecated/gcp_detect_oauth_token_abuse.yml +++ b/deprecated/detections/gcp_detect_oauth_token_abuse.yml @@ -42,3 +42,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml b/deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml similarity index 90% rename from detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml rename to deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml index 82b0c7452c..eeb2f67cd3 100644 --- a/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml +++ b/deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml @@ -46,3 +46,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/identify_new_user_accounts.yml b/deprecated/detections/identify_new_user_accounts.yml similarity index 87% rename from detections/deprecated/identify_new_user_accounts.yml rename to deprecated/detections/identify_new_user_accounts.yml index 751871c2a8..fcb8455587 100644 --- a/detections/deprecated/identify_new_user_accounts.yml +++ b/deprecated/detections/identify_new_user_accounts.yml @@ -41,3 +41,10 @@ tags: - _time risk_score: 25 security_domain: access +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml b/deprecated/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml similarity index 86% rename from detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml rename to deprecated/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml index 96583b21a3..25d0af025d 100644 --- a/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml +++ b/deprecated/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml @@ -36,3 +36,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml b/deprecated/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml similarity index 85% rename from detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml rename to deprecated/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml index 00ddb8c2c3..94882aca5a 100644 --- a/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml +++ b/deprecated/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml @@ -37,4 +37,11 @@ tags: required_fields: - _time risk_score: 25 - security_domain: threat \ No newline at end of file + security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml b/deprecated/detections/kubernetes_aws_detect_sensitive_role_access.yml similarity index 79% rename from detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml rename to deprecated/detections/kubernetes_aws_detect_sensitive_role_access.yml index 29ef8de65e..5ed12ae1b4 100644 --- a/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml +++ b/deprecated/detections/kubernetes_aws_detect_sensitive_role_access.yml @@ -14,8 +14,8 @@ search: '`aws_cloudwatchlogs_eks` objectRef.resource=clusterroles OR clusterrole user.groups{} |`kubernetes_aws_detect_sensitive_role_access_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with cloudwatch logs. -known_false_positives: 'Sensitive role resource access is necessary for cluster operation, - however source IP, namespace and user group may indicate possible malicious use.' +known_false_positives: Sensitive role resource access is necessary for cluster operation, + however source IP, namespace and user group may indicate possible malicious use. references: [] tags: analytic_story: @@ -37,3 +37,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml b/deprecated/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml similarity index 86% rename from detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml rename to deprecated/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml index 344bfa7d85..4c81079f4a 100644 --- a/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml +++ b/deprecated/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml @@ -38,3 +38,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml b/deprecated/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml similarity index 87% rename from detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml rename to deprecated/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml index cc6f35af8d..09ff8955ab 100644 --- a/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml +++ b/deprecated/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml @@ -38,3 +38,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml b/deprecated/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml similarity index 87% rename from detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml rename to deprecated/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml index 2eb82e151b..ec33251e7a 100644 --- a/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml +++ b/deprecated/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml @@ -38,3 +38,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml b/deprecated/detections/kubernetes_azure_detect_sensitive_object_access.yml similarity index 86% rename from detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml rename to deprecated/detections/kubernetes_azure_detect_sensitive_object_access.yml index 44c2dc672f..a470c001f3 100644 --- a/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml +++ b/deprecated/detections/kubernetes_azure_detect_sensitive_object_access.yml @@ -37,3 +37,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml b/deprecated/detections/kubernetes_azure_detect_sensitive_role_access.yml similarity index 79% rename from detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml rename to deprecated/detections/kubernetes_azure_detect_sensitive_role_access.yml index f882bd700a..00932aaf7d 100644 --- a/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml +++ b/deprecated/detections/kubernetes_azure_detect_sensitive_role_access.yml @@ -14,8 +14,8 @@ search: '`kubernetes_azure` category=kube-audit | spath input=properties.log| se | dedup user.username user.groups{} |`kubernetes_azure_detect_sensitive_role_access_filter`' how_to_implement: You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics -known_false_positives: 'Sensitive role resource access is necessary for cluster operation, - however source IP, namespace and user group may indicate possible malicious use.' +known_false_positives: Sensitive role resource access is necessary for cluster operation, + however source IP, namespace and user group may indicate possible malicious use. references: [] tags: analytic_story: @@ -37,3 +37,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml b/deprecated/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml similarity index 86% rename from detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml rename to deprecated/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml index b9231eb62b..c345b14a62 100644 --- a/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml +++ b/deprecated/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml @@ -37,3 +37,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml b/deprecated/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml similarity index 88% rename from detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml rename to deprecated/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml index 41181a8aff..86dd0621de 100644 --- a/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml +++ b/deprecated/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml @@ -40,3 +40,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml b/deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml similarity index 85% rename from detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml rename to deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml index 6ed545867f..74794dde94 100644 --- a/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml +++ b/deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml @@ -37,3 +37,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/kubernetes_azure_scan_fingerprint.yml b/deprecated/detections/kubernetes_azure_scan_fingerprint.yml similarity index 85% rename from detections/deprecated/kubernetes_azure_scan_fingerprint.yml rename to deprecated/detections/kubernetes_azure_scan_fingerprint.yml index 910b36c4bf..72f1bba3ad 100644 --- a/detections/deprecated/kubernetes_azure_scan_fingerprint.yml +++ b/deprecated/detections/kubernetes_azure_scan_fingerprint.yml @@ -39,3 +39,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml b/deprecated/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml similarity index 87% rename from detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml rename to deprecated/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml index bc40619269..7706de6b0b 100644 --- a/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml +++ b/deprecated/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml @@ -38,3 +38,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml b/deprecated/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml similarity index 86% rename from detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml rename to deprecated/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml index 7d5af8b4a6..195639fc04 100644 --- a/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml +++ b/deprecated/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml @@ -38,3 +38,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml b/deprecated/detections/kubernetes_gcp_detect_sensitive_object_access.yml similarity index 86% rename from detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml rename to deprecated/detections/kubernetes_gcp_detect_sensitive_object_access.yml index 7cdbc43651..665d937d58 100644 --- a/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml +++ b/deprecated/detections/kubernetes_gcp_detect_sensitive_object_access.yml @@ -38,3 +38,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml b/deprecated/detections/kubernetes_gcp_detect_sensitive_role_access.yml similarity index 80% rename from detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml rename to deprecated/detections/kubernetes_gcp_detect_sensitive_role_access.yml index 9bcd081b67..836872d1fd 100644 --- a/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml +++ b/deprecated/detections/kubernetes_gcp_detect_sensitive_role_access.yml @@ -14,9 +14,9 @@ search: '`google_gcp_pubsub_message` data.labels.authorization.k8s.io/reason=Clu | dedup src_ip src_user |`kubernetes_gcp_detect_sensitive_role_access_filter`' how_to_implement: You must install splunk add on for GCP. This search works with pubsub messaging servicelogs. -known_false_positives: 'Sensitive role resource access is necessary for cluster operation, +known_false_positives: Sensitive role resource access is necessary for cluster operation, however source IP, user agent, decision and reason may indicate possible malicious - use.' + use. references: [] tags: analytic_story: @@ -38,3 +38,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml b/deprecated/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml similarity index 88% rename from detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml rename to deprecated/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml index fb104b1612..a2cbe45d1e 100644 --- a/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml +++ b/deprecated/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml @@ -40,3 +40,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml b/deprecated/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml similarity index 87% rename from detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml rename to deprecated/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml index c0fd76eb6b..8fadc9d1df 100644 --- a/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml +++ b/deprecated/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml @@ -39,3 +39,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/monitor_dns_for_brand_abuse.yml b/deprecated/detections/monitor_dns_for_brand_abuse.yml similarity index 88% rename from detections/deprecated/monitor_dns_for_brand_abuse.yml rename to deprecated/detections/monitor_dns_for_brand_abuse.yml index aeb1119c9c..b01440d8f8 100644 --- a/detections/deprecated/monitor_dns_for_brand_abuse.yml +++ b/deprecated/detections/monitor_dns_for_brand_abuse.yml @@ -45,3 +45,10 @@ tags: - _time risk_score: 25 security_domain: network +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml b/deprecated/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml similarity index 78% rename from detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml rename to deprecated/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml index dd8ef0e990..11ae13267b 100644 --- a/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml +++ b/deprecated/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml @@ -5,12 +5,11 @@ date: '2024-10-17' author: Michael Haag, Mauricio Velazco, Rico Valdez, Splunk status: deprecated type: TTP -description: - '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta Multiple Users Failing To Authenticate From Ip`. - This analytic identifies multiple failed logon attempts from - a single IP in a short period of time. Use this analytic to identify patterns of suspicious logins from a - single source and filter as needed or use this to drive tuning for higher fidelity - analytics.' +description: '**DEPRECATION NOTE** - This search has been deprecated and replaced + with `Okta Multiple Users Failing To Authenticate From Ip`. This analytic identifies + multiple failed logon attempts from a single IP in a short period of time. Use this + analytic to identify patterns of suspicious logins from a single source and filter + as needed or use this to drive tuning for higher fidelity analytics.' data_source: [] search: '`okta` eventType=user.session.start outcome.result=FAILURE | rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city @@ -66,4 +65,11 @@ tests: attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/okta_multiple_users_from_ip/okta_multiple_users_from_ip.log source: Okta - sourcetype: OktaIM2:log \ No newline at end of file + sourcetype: OktaIM2:log +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/o365_suspicious_admin_email_forwarding.yml b/deprecated/detections/o365_suspicious_admin_email_forwarding.yml similarity index 78% rename from detections/deprecated/o365_suspicious_admin_email_forwarding.yml rename to deprecated/detections/o365_suspicious_admin_email_forwarding.yml index 2476713d4c..6cf91d0053 100644 --- a/detections/deprecated/o365_suspicious_admin_email_forwarding.yml +++ b/deprecated/detections/o365_suspicious_admin_email_forwarding.yml @@ -5,10 +5,9 @@ date: '2024-10-17' author: Patrick Bareiss, Splunk status: deprecated type: Anomaly -description: - '**DEPRECATION NOTE** - This search has been deprecated and replaced with `O365 Mailbox Email Forwarding Enabled`. - This search detects when an admin configured a forwarding rule for multiple - mailboxes to the same destination.' +description: '**DEPRECATION NOTE** - This search has been deprecated and replaced + with `O365 Mailbox Email Forwarding Enabled`. This search detects when an admin + configured a forwarding rule for multiple mailboxes to the same destination.' data_source: [] search: '`o365_management_activity` Operation=Set-Mailbox | spath input=Parameters | rename Identity AS src_user | search ForwardingAddress=* | stats dc(src_user) @@ -52,3 +51,10 @@ tests: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114.003/o365_mailbox_forwarding_enabled/o365_mailbox_forwarding_enabled.json sourcetype: o365:management:activity source: o365 +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/deprecated/detections/o365_suspicious_rights_delegation.yml b/deprecated/detections/o365_suspicious_rights_delegation.yml new file mode 100644 index 0000000000..a58f998aeb --- /dev/null +++ b/deprecated/detections/o365_suspicious_rights_delegation.yml @@ -0,0 +1,86 @@ +name: O365 Suspicious Rights Delegation +id: b25d2973-303e-47c8-bacd-52b61604c6a7 +version: 3 +date: '2024-10-17' +author: Patrick Bareiss, Mauricio Velazco, Splunk +status: deprecated +type: TTP +description: '**DEPRECATION NOTE** - This search has been deprecated and replaced + with `O365 Elevated Mailbox Permission Assigned`. This analytic identifies instances + where potentially suspicious rights are delegated within the Office 365 environment. + Specifically, it detects when a user is granted FullAccess, SendAs, or SendOnBehalf + permissions on another users mailbox. Such permissions can allow a user to access, + send emails from, or send emails on behalf of the target mailbox. The detection + leverages O365 audit logs, focusing on the Add-MailboxPermission operation. By parsing + the parameters of this operation, the analytic filters for events where FullAccess, + SendAs, or SendOnBehalf rights are granted. It then aggregates this data to capture + the source user (who was granted the permissions), the destination user (whose mailbox + was affected), the specific operation, and the type of access rights granted. Delegating + mailbox rights, especially those as powerful as FullAccess, can pose significant + security risks. While there are legitimate scenarios for these permissions, such + as an executive assistant needing access to an executives mailbox, there are also + malicious scenarios where an attacker or a compromised insider might grant themselves + unauthorized access to sensitive mailboxes. Monitoring for these permissions changes + is crucial to detect potential insider threats, compromised accounts, or other malicious + activities.If the detection is a true positive, it indicates that a user has been + granted potentially high-risk permissions on another users mailbox. This could lead + to unauthorized access to sensitive emails, impersonation through sending emails + as or on behalf of the mailbox owner, or data manipulation by altering or deleting + emails. Immediate investigation is required to validate the legitimacy of the permission + change and to assess the potential risks associated with the granted access.' +data_source: [] +search: '`o365_management_activity` Operation=Add-MailboxPermission | spath input=Parameters + | rename User AS src_user, Identity AS dest_user | search AccessRights=FullAccess + OR AccessRights=SendAs OR AccessRights=SendOnBehalf | stats count earliest(_time) + as firstTime latest(_time) as lastTime by user src_user dest_user Operation AccessRights + |`security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` |`o365_suspicious_rights_delegation_filter`' +how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest + Office 365 management activity events. +known_false_positives: While there are legitimate scenarios for these permissions, + such as an executive assistant needing access to an executive's mailbox, there are + also malicious scenarios. Investigate and filter as needed. +references: +- https://www.mandiant.com/resources/blog/remediation-and-hardening-strategies-for-microsoft-365-to-defend-against-unc2452 +- https://attack.mitre.org/techniques/T1098/002/ +- https://attack.mitre.org/techniques/T1114/002/ +tags: + analytic_story: + - Office 365 Collection Techniques + asset_type: O365 Tenant + confidence: 60 + impact: 80 + message: User $user$ has delegated suspicious rights $AccessRights$ to user $dest_user$ + that allow access to sensitive + mitre_attack_id: + - T1114.002 + - T1114 + - T1098.002 + - T1098 + observable: + - name: user + type: User + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Operation + - Parameters + risk_score: 48 + security_domain: threat +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114.002/suspicious_rights_delegation/suspicious_rights_delegation.json + sourcetype: o365:management:activity + source: o365 +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/deprecated/detections/o365_suspicious_user_email_forwarding.yml b/deprecated/detections/o365_suspicious_user_email_forwarding.yml new file mode 100644 index 0000000000..86149fa3ed --- /dev/null +++ b/deprecated/detections/o365_suspicious_user_email_forwarding.yml @@ -0,0 +1,88 @@ +name: O365 Suspicious User Email Forwarding +id: f8dfe015-dbb3-4569-ba75-b13787e06aa4 +version: 3 +date: '2024-10-17' +author: Patrick Bareiss, Splunk +status: deprecated +type: Anomaly +description: '**DEPRECATION NOTE** - This search has been deprecated and replaced + with `O365 Mailbox Email Forwarding Enabled`. The following analytic detects when + multiple users have configured a forwarding rule to the same destination to proactively + identify and investigate potential security risks related to email forwarding and + take appropriate actions to protect the organizations data and prevent unauthorized + access or data breaches. This detection is made by a Splunk query to O365 management + activity logs with the operation `Set-Mailbox` to gather information about mailbox + configurations. Then, the query uses the `spath` function to extract the parameters + and rename the "Identity" field as "src_user" and searches for entries where the + "ForwardingSmtpAddress" field is not empty, which indicates the presence of a forwarding + rule. Next, the analytic uses the `stats` command to group the results by the forwarding + email address and count the number of unique source users (`src_user`). Finally, + it filters the results and only retains entries where the count of source users + (`count_src_user`) is greater than 1, which indicates that multiple users have set + up forwarding rules to the same destination. This detection is important because + it suggests that multiple users are forwarding emails to the same destination without + proper authorization, which can lead to the exposure of sensitive information, loss + of data control, or unauthorized access to confidential emails. Investigating and + addressing this issue promptly can help prevent data breaches and mitigate potential + damage.indicates a potential security risk since multiple users forwarding emails + to the same destination can be a sign of unauthorized access, data exfiltration, + or a compromised account. Additionally, it also helps to determine if the forwarding + rules are legitimate or if they indicate a security incident. False positives can + occur if there are legitimate reasons for multiple users to forward emails to the + same destination, such as a shared mailbox or a team collaboration scenario. Next + steps include further investigation and context analysis to determine the legitimacy + of the forwarding rules.' +data_source: [] +search: '`o365_management_activity` Operation=Set-Mailbox | spath input=Parameters + | rename Identity AS src_user | search ForwardingSmtpAddress=* | stats dc(src_user) + AS count_src_user earliest(_time) as firstTime latest(_time) as lastTime values(src_user) + AS src_user values(user) AS user by ForwardingSmtpAddress | where count_src_user + > 1 |`security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` |`o365_suspicious_user_email_forwarding_filter`' +how_to_implement: You must install splunk Microsoft Office 365 add-on. This search + works with o365:management:activity +known_false_positives: unknown +references: [] +tags: + analytic_story: + - Office 365 Collection Techniques + - Data Exfiltration + asset_type: O365 Tenant + confidence: 60 + impact: 80 + message: User $user$ configured multiple users $src_user$ with a count of $count_src_user$, + a forwarding rule to same destination $ForwardingSmtpAddress$ + mitre_attack_id: + - T1114.003 + - T1114 + observable: + - name: user + type: User + role: + - Victim + - name: ForwardingSmtpAddress + type: Email Address + role: + - Attacker + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Operation + - Parameters + risk_score: 48 + security_domain: threat +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114.003/o365_mailbox_forwarding_enabled/o365_mailbox_forwarding_enabled.json + sourcetype: o365:management:activity + source: o365 +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/okta_account_locked_out.yml b/deprecated/detections/okta_account_locked_out.yml similarity index 66% rename from detections/deprecated/okta_account_locked_out.yml rename to deprecated/detections/okta_account_locked_out.yml index d7a30ee439..224e8d02fa 100644 --- a/detections/deprecated/okta_account_locked_out.yml +++ b/deprecated/detections/okta_account_locked_out.yml @@ -5,15 +5,15 @@ date: '2024-10-17' author: Michael Haag, Splunk status: deprecated type: Anomaly -description: - '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta Multiple Accounts Locked Out`. - The following analytic utilizes the user.acount.lock event to identify - associates who are locked out of Okta. An adversary attempting to brute force or - password spray account names may lock accounts out depending on the threshold.' +description: '**DEPRECATION NOTE** - This search has been deprecated and replaced + with `Okta Multiple Accounts Locked Out`. The following analytic utilizes the user.acount.lock + event to identify associates who are locked out of Okta. An adversary attempting + to brute force or password spray account names may lock accounts out depending on + the threshold.' data_source: [] search: '`okta` eventType=user.account.lock | stats count min(_time) as firstTime - max(_time) as lastTime values(displayMessage) values(src_user) as user by src_ip eventType status - | where count >=3 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| + max(_time) as lastTime values(displayMessage) values(src_user) as user by src_ip + eventType status | where count >=3 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `okta_account_locked_out_filter`' how_to_implement: This analytic is specific to Okta and requires Okta logs to be ingested. known_false_positives: False positives may be present. Tune Okta and tune the analytic @@ -53,4 +53,11 @@ tests: attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110/okta_multiple_accounts_lockout/okta_multiple_accounts_lockout.log source: Okta - sourcetype: OktaIM2:log \ No newline at end of file + sourcetype: OktaIM2:log +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/okta_account_lockout_events.yml b/deprecated/detections/okta_account_lockout_events.yml similarity index 65% rename from detections/deprecated/okta_account_lockout_events.yml rename to deprecated/detections/okta_account_lockout_events.yml index 4d15cada48..06c2cf17aa 100644 --- a/detections/deprecated/okta_account_lockout_events.yml +++ b/deprecated/detections/okta_account_lockout_events.yml @@ -5,16 +5,16 @@ date: '2024-10-17' author: Michael Haag, Rico Valdez, Splunk status: deprecated type: Anomaly -description: - '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta Multiple Accounts Locked Out`. - The following anomaly will generate based on account lockout events utilizing - Okta eventTypes of user.account.lock.limit or user.account.lock. Per the Okta docs - site, this event is fired when a user account has reached the lockout limit. The - account will not auto-unlock and a user or client cannot gain access to the account. - This event indicates an account that will not be able to log in until remedial action - is taken by the account admin. This event can be used to understand the specifics - of an account lockout. Often this indicates a client application that is repeatedly - attempting to authenticate with invalid credentials such as an old password.' +description: '**DEPRECATION NOTE** - This search has been deprecated and replaced + with `Okta Multiple Accounts Locked Out`. The following anomaly will generate based + on account lockout events utilizing Okta eventTypes of user.account.lock.limit or + user.account.lock. Per the Okta docs site, this event is fired when a user account + has reached the lockout limit. The account will not auto-unlock and a user or client + cannot gain access to the account. This event indicates an account that will not + be able to log in until remedial action is taken by the account admin. This event + can be used to understand the specifics of an account lockout. Often this indicates + a client application that is repeatedly attempting to authenticate with invalid + credentials such as an old password.' data_source: [] search: '`okta` eventType IN (user.account.lock.limit,user.account.lock) | rename client.geographicalContext.country as country, client.geographicalContext.state @@ -63,4 +63,11 @@ tests: attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110/okta_multiple_accounts_lockout/okta_multiple_accounts_lockout.log source: Okta - sourcetype: OktaIM2:log \ No newline at end of file + sourcetype: OktaIM2:log +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/okta_failed_sso_attempts.yml b/deprecated/detections/okta_failed_sso_attempts.yml similarity index 77% rename from detections/deprecated/okta_failed_sso_attempts.yml rename to deprecated/detections/okta_failed_sso_attempts.yml index a6b0768935..112d88560b 100644 --- a/detections/deprecated/okta_failed_sso_attempts.yml +++ b/deprecated/detections/okta_failed_sso_attempts.yml @@ -5,7 +5,10 @@ date: '2024-10-17' author: Michael Haag, Rico Valdez, Splunk status: deprecated type: Anomaly -description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with this detection `Okta Unauthorized Access to Application - DM`. The following anomaly identifies failed Okta SSO events utilizing the legacy Okta event "unauth app access attempt".' +description: '**DEPRECATION NOTE** - This search has been deprecated and replaced + with this detection `Okta Unauthorized Access to Application - DM`. The following + anomaly identifies failed Okta SSO events utilizing the legacy Okta event "unauth + app access attempt".' data_source: [] search: '`okta` eventType=app.generic.unauth_app_access_attempt | stats min(_time) as firstTime max(_time) as lastTime values(app) as Apps count by src_user, result @@ -45,3 +48,10 @@ tags: - src_ip risk_score: 16 security_domain: access +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml b/deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml new file mode 100644 index 0000000000..87da183f88 --- /dev/null +++ b/deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml @@ -0,0 +1,60 @@ +name: Okta ThreatInsight Login Failure with High Unknown users +id: 632663b0-4562-4aad-abe9-9f621a049738 +version: 3 +date: '2024-10-17' +author: Okta, Inc, Michael Haag, Splunk +type: TTP +status: deprecated +data_source: [] +description: '**DEPRECATION NOTE** - This search has been deprecated and replaced + with `Okta ThreatInsight Threat Detected`. The following analytic utilizes Oktas + ThreatInsight to identify Login failures with high unknown users count and any included + secondary outcome reasons. This event will trigger when a brute force attempt occurs + with unknown usernames attempted.' +search: '`okta` eventType="security.threat.detected" AND outcome.reason="Login failures + with high unknown users count*" | stats count min(_time) as firstTime max(_time) + as lastTime values(displayMessage) by user eventType client.userAgent.rawUserAgent + client.userAgent.browser outcome.reason | `security_content_ctime(firstTime)` | + `security_content_ctime(lastTime)` | `okta_threatinsight_login_failure_with_high_unknown_users_filter`' +how_to_implement: This search is specific to Okta and requires Okta logs to be ingested + in your Splunk deployment. +known_false_positives: Fidelity of this is high as it is Okta ThreatInsight. Filter + and modify as needed. +references: +- https://help.okta.com/en-us/Content/Topics/Security/threat-insight/configure-threatinsight-system-log.htm +tags: + analytic_story: + - Suspicious Okta Activity + asset_type: Infrastructure + confidence: 100 + impact: 50 + message: Okta ThreatInsight has detected or prevented a high number of login failures. + mitre_attack_id: + - T1078 + - T1078.001 + - T1110.004 + observable: + - name: user + type: User + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - eventType + - client.userAgent.rawUserAgent + - client.userAgent.browser + - outcome.reason + - displayMessage + risk_score: 50 + security_domain: access +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml b/deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml new file mode 100644 index 0000000000..0d27bd7714 --- /dev/null +++ b/deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml @@ -0,0 +1,59 @@ +name: Okta ThreatInsight Suspected PasswordSpray Attack +id: 25dbad05-6682-4dd5-9ce9-8adecf0d9ae2 +version: 3 +date: '2024-10-17' +author: Okta, Inc, Michael Haag, Splunk +type: TTP +status: deprecated +data_source: [] +description: '**DEPRECATION NOTE** - This search has been deprecated and replaced + with `Okta ThreatInsight Threat Detected`. The following analytic utilizes Oktas + ThreatInsight to identify "PasswordSpray" and any included secondary outcome reasons. + This event will trigger when a brute force attempt occurs with unknown usernames + attempted.' +search: '`okta` eventType="security.threat.detected" AND outcome.reason="Password + Spray" | stats count min(_time) as firstTime max(_time) as lastTime values(displayMessage) + by eventType client.userAgent.rawUserAgent client.userAgent.browser outcome.reason + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `okta_threatinsight_suspected_passwordspray_attack_filter`' +how_to_implement: This search is specific to Okta and requires Okta logs to be ingested + in your Splunk deployment. +known_false_positives: Fidelity of this is high as it is Okta ThreatInsight. Filter + and modify as needed. +references: +- https://help.okta.com/en-us/Content/Topics/Security/threat-insight/configure-threatinsight-system-log.htm +tags: + analytic_story: + - Suspicious Okta Activity + asset_type: Infrastructure + confidence: 100 + impact: 60 + message: Okta ThreatInsight has detected or prevented a PasswordSpray attack. + mitre_attack_id: + - T1078 + - T1078.001 + - T1110.003 + observable: + - name: outcome.reason + type: Other + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - eventType + - client.userAgent.rawUserAgent + - client.userAgent.browser + - outcome.reason + - displayMessage + risk_score: 60 + security_domain: access +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml b/deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml similarity index 79% rename from detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml rename to deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml index 054e1f73d3..f63847c0fe 100644 --- a/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml +++ b/deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml @@ -5,11 +5,10 @@ date: '2024-10-17' author: Michael Haag, Marissa Bower, Splunk status: deprecated type: TTP -description: - '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta Multiple Failed MFA Requests For User`. - The following analytic identifies an account that has rejected more than - 2 Push notifications in a 10 minute window. Modify this query for your environment - by upping the count or time window.' +description: '**DEPRECATION NOTE** - This search has been deprecated and replaced + with `Okta Multiple Failed MFA Requests For User`. The following analytic identifies + an account that has rejected more than 2 Push notifications in a 10 minute window. + Modify this query for your environment by upping the count or time window.' data_source: [] search: '`okta` outcome.reason="User rejected Okta push verify" OR (debugContext.debugData.factor="OKTA_VERIFY_PUSH" outcome.result=FAILURE legacyEventType="core.user.factor.attempt_fail" "target{}.detailEntry.methodTypeUsed"="Get @@ -55,3 +54,10 @@ tags: - status risk_score: 64 security_domain: access +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/osquery_pack___coldroot_detection.yml b/deprecated/detections/osquery_pack___coldroot_detection.yml similarity index 87% rename from detections/deprecated/osquery_pack___coldroot_detection.yml rename to deprecated/detections/osquery_pack___coldroot_detection.yml index b135fd565c..44257496a8 100644 --- a/detections/deprecated/osquery_pack___coldroot_detection.yml +++ b/deprecated/detections/osquery_pack___coldroot_detection.yml @@ -41,3 +41,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/processes_created_by_netsh.yml b/deprecated/detections/processes_created_by_netsh.yml similarity index 92% rename from detections/deprecated/processes_created_by_netsh.yml rename to deprecated/detections/processes_created_by_netsh.yml index c5a02ce2ee..ff2748821a 100644 --- a/detections/deprecated/processes_created_by_netsh.yml +++ b/deprecated/detections/processes_created_by_netsh.yml @@ -59,3 +59,10 @@ tags: - _time risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/prohibited_software_on_endpoint.yml b/deprecated/detections/prohibited_software_on_endpoint.yml similarity index 90% rename from detections/deprecated/prohibited_software_on_endpoint.yml rename to deprecated/detections/prohibited_software_on_endpoint.yml index 03473629ef..74712201fe 100644 --- a/detections/deprecated/prohibited_software_on_endpoint.yml +++ b/deprecated/detections/prohibited_software_on_endpoint.yml @@ -50,3 +50,10 @@ tags: - _times risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml b/deprecated/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml similarity index 91% rename from detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml rename to deprecated/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml index 085db48699..cb34548430 100644 --- a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml +++ b/deprecated/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml @@ -54,3 +54,10 @@ tags: - _time risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/remote_registry_key_modifications.yml b/deprecated/detections/remote_registry_key_modifications.yml similarity index 89% rename from detections/deprecated/remote_registry_key_modifications.yml rename to deprecated/detections/remote_registry_key_modifications.yml index 9bd274acf5..c00c759ca6 100644 --- a/detections/deprecated/remote_registry_key_modifications.yml +++ b/deprecated/detections/remote_registry_key_modifications.yml @@ -47,3 +47,10 @@ tags: - _time risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml b/deprecated/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml similarity index 85% rename from detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml rename to deprecated/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml index 5733207051..7dad2ebfac 100644 --- a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml +++ b/deprecated/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml @@ -13,8 +13,8 @@ data_source: search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process) as process from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe (Processes.process= "*create*" OR Processes.process= - "*delete*") by Processes.parent_process Processes.process_name Processes.user Processes.dest | - `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)` + "*delete*") by Processes.parent_process Processes.process_name Processes.user Processes.dest + | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)` | search (process=*rhaegal* OR process=*drogon* OR *viserion_*) | `scheduled_tasks_used_in_badrabbit_ransomware_filter`' how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related @@ -53,3 +53,10 @@ tags: - _time risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml b/deprecated/detections/spectre_and_meltdown_vulnerable_systems.yml similarity index 87% rename from detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml rename to deprecated/detections/spectre_and_meltdown_vulnerable_systems.yml index 5a50ca1bbf..c79a00d7cc 100644 --- a/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml +++ b/deprecated/detections/spectre_and_meltdown_vulnerable_systems.yml @@ -40,3 +40,10 @@ tags: - _time risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/suspicious_changes_to_file_associations.yml b/deprecated/detections/suspicious_changes_to_file_associations.yml similarity index 92% rename from detections/deprecated/suspicious_changes_to_file_associations.yml rename to deprecated/detections/suspicious_changes_to_file_associations.yml index e18aeb3d9e..c569263518 100644 --- a/detections/deprecated/suspicious_changes_to_file_associations.yml +++ b/deprecated/detections/suspicious_changes_to_file_associations.yml @@ -55,3 +55,10 @@ tags: - _time risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/suspicious_email___uba_anomaly.yml b/deprecated/detections/suspicious_email___uba_anomaly.yml similarity index 90% rename from detections/deprecated/suspicious_email___uba_anomaly.yml rename to deprecated/detections/suspicious_email___uba_anomaly.yml index 95611cc4b1..23b68b050d 100644 --- a/detections/deprecated/suspicious_email___uba_anomaly.yml +++ b/deprecated/detections/suspicious_email___uba_anomaly.yml @@ -47,3 +47,10 @@ tags: - _time risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/suspicious_file_write.yml b/deprecated/detections/suspicious_file_write.yml similarity index 90% rename from detections/deprecated/suspicious_file_write.yml rename to deprecated/detections/suspicious_file_write.yml index 52be4ad801..863cb0c4cd 100644 --- a/detections/deprecated/suspicious_file_write.yml +++ b/deprecated/detections/suspicious_file_write.yml @@ -49,3 +49,10 @@ tags: - _time risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/suspicious_powershell_command_line_arguments.yml b/deprecated/detections/suspicious_powershell_command_line_arguments.yml similarity index 92% rename from detections/deprecated/suspicious_powershell_command_line_arguments.yml rename to deprecated/detections/suspicious_powershell_command_line_arguments.yml index 29dc289399..2b536189d1 100644 --- a/detections/deprecated/suspicious_powershell_command_line_arguments.yml +++ b/deprecated/detections/suspicious_powershell_command_line_arguments.yml @@ -60,3 +60,10 @@ tags: - _time risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/suspicious_rundll32_rename.yml b/deprecated/detections/suspicious_rundll32_rename.yml similarity index 93% rename from detections/deprecated/suspicious_rundll32_rename.yml rename to deprecated/detections/suspicious_rundll32_rename.yml index 0be18969d9..6881c250e5 100644 --- a/detections/deprecated/suspicious_rundll32_rename.yml +++ b/deprecated/detections/suspicious_rundll32_rename.yml @@ -75,3 +75,10 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/suspicious_writes_to_system_volume_information.yml b/deprecated/detections/suspicious_writes_to_system_volume_information.yml similarity index 78% rename from detections/deprecated/suspicious_writes_to_system_volume_information.yml rename to deprecated/detections/suspicious_writes_to_system_volume_information.yml index 9db993173f..43300e2c21 100644 --- a/detections/deprecated/suspicious_writes_to_system_volume_information.yml +++ b/deprecated/detections/suspicious_writes_to_system_volume_information.yml @@ -9,10 +9,10 @@ description: This search detects writes to the 'System Volume Information' folde by something other than the System process. data_source: - Sysmon EventID 1 -search: '(`sysmon` OR tag=process) EventCode=11 process_id!=4 file_path=*System\ Volume +search: (`sysmon` OR tag=process) EventCode=11 process_id!=4 file_path=*System\ Volume Information* | stats count min(_time) as firstTime max(_time) as lastTime by dest, Image, file_path | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` - | `suspicious_writes_to_system_volume_information_filter`' + | `suspicious_writes_to_system_volume_information_filter` how_to_implement: You need to be ingesting logs with both the process name and command-line from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. @@ -42,3 +42,10 @@ tags: - _time risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/uncommon_processes_on_endpoint.yml b/deprecated/detections/uncommon_processes_on_endpoint.yml similarity index 89% rename from detections/deprecated/uncommon_processes_on_endpoint.yml rename to deprecated/detections/uncommon_processes_on_endpoint.yml index cd005e9758..23e0cc4540 100644 --- a/detections/deprecated/uncommon_processes_on_endpoint.yml +++ b/deprecated/detections/uncommon_processes_on_endpoint.yml @@ -48,3 +48,10 @@ tags: - _time risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/unsigned_image_loaded_by_lsass.yml b/deprecated/detections/unsigned_image_loaded_by_lsass.yml similarity index 82% rename from detections/deprecated/unsigned_image_loaded_by_lsass.yml rename to deprecated/detections/unsigned_image_loaded_by_lsass.yml index abad39d5ec..b1a9c09380 100644 --- a/detections/deprecated/unsigned_image_loaded_by_lsass.yml +++ b/deprecated/detections/unsigned_image_loaded_by_lsass.yml @@ -10,9 +10,8 @@ description: This search detects loading of unsigned images by LSASS. Deprecated data_source: - Sysmon EventID 7 search: '`sysmon` EventID=7 Image=*lsass.exe Signed=false | stats count min(_time) - as firstTime max(_time) as lastTime by dest, Image, ImageLoaded, Signed, SHA1 - | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` - | `unsigned_image_loaded_by_lsass_filter`' + as firstTime max(_time) as lastTime by dest, Image, ImageLoaded, Signed, SHA1 | + `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `unsigned_image_loaded_by_lsass_filter`' how_to_implement: This search needs Sysmon Logs with a sysmon configuration, which includes EventCode 7 with lsass.exe. This search uses an input macro named `sysmon`. We strongly recommend that you specify your environment-specific configurations @@ -45,3 +44,10 @@ tags: - _time risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/unsuccessful_netbackup_backups.yml b/deprecated/detections/unsuccessful_netbackup_backups.yml similarity index 85% rename from detections/deprecated/unsuccessful_netbackup_backups.yml rename to deprecated/detections/unsuccessful_netbackup_backups.yml index 2a8da81803..ddfb921a8b 100644 --- a/detections/deprecated/unsuccessful_netbackup_backups.yml +++ b/deprecated/detections/unsuccessful_netbackup_backups.yml @@ -38,3 +38,10 @@ tags: - _time risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/web_fraud___account_harvesting.yml b/deprecated/detections/web_fraud___account_harvesting.yml similarity index 92% rename from detections/deprecated/web_fraud___account_harvesting.yml rename to deprecated/detections/web_fraud___account_harvesting.yml index ff403542db..621ccbd5f5 100644 --- a/detections/deprecated/web_fraud___account_harvesting.yml +++ b/deprecated/detections/web_fraud___account_harvesting.yml @@ -60,3 +60,10 @@ tags: - cookie risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml b/deprecated/detections/web_fraud___anomalous_user_clickspeed.yml similarity index 91% rename from detections/deprecated/web_fraud___anomalous_user_clickspeed.yml rename to deprecated/detections/web_fraud___anomalous_user_clickspeed.yml index 2708e005f0..6a593e0993 100644 --- a/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml +++ b/deprecated/detections/web_fraud___anomalous_user_clickspeed.yml @@ -55,3 +55,10 @@ tags: - cookie risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/web_fraud___password_sharing_across_accounts.yml b/deprecated/detections/web_fraud___password_sharing_across_accounts.yml similarity index 90% rename from detections/deprecated/web_fraud___password_sharing_across_accounts.yml rename to deprecated/detections/web_fraud___password_sharing_across_accounts.yml index 2d09283498..34c7716fb9 100644 --- a/detections/deprecated/web_fraud___password_sharing_across_accounts.yml +++ b/deprecated/detections/web_fraud___password_sharing_across_accounts.yml @@ -48,3 +48,10 @@ tags: - uri risk_score: 25 security_domain: threat +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/windows_connhost_exe_started_forcefully.yml b/deprecated/detections/windows_connhost_exe_started_forcefully.yml similarity index 80% rename from detections/deprecated/windows_connhost_exe_started_forcefully.yml rename to deprecated/detections/windows_connhost_exe_started_forcefully.yml index 97ce18f097..9ccf7b3180 100644 --- a/detections/deprecated/windows_connhost_exe_started_forcefully.yml +++ b/deprecated/detections/windows_connhost_exe_started_forcefully.yml @@ -5,11 +5,11 @@ date: '2024-10-17' author: Rod Soto, Jose Hernandez, Splunk status: deprecated type: TTP -description: 'The search looks for the Console Window Host process (connhost.exe) - executed using the force flag -ForceV1. This is not regular behavior in the Windows - OS and is often seen executed by the Ryuk Ransomware. DEPRECATED This event is actually +description: The search looks for the Console Window Host process (connhost.exe) executed + using the force flag -ForceV1. This is not regular behavior in the Windows OS and + is often seen executed by the Ryuk Ransomware. DEPRECATED This event is actually seen in the windows 10 client of attack_range_local. After further testing we realized - this is not specific to Ryuk.' + this is not specific to Ryuk. data_source: - Sysmon EventID 1 search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) @@ -51,3 +51,10 @@ tags: - _time risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml b/deprecated/detections/windows_dll_search_order_hijacking_hunt.yml similarity index 92% rename from detections/deprecated/windows_dll_search_order_hijacking_hunt.yml rename to deprecated/detections/windows_dll_search_order_hijacking_hunt.yml index 659b65928e..37d2cd825a 100644 --- a/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml +++ b/deprecated/detections/windows_dll_search_order_hijacking_hunt.yml @@ -27,7 +27,8 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.user Processes.parent_process_name Processes.process_name Processes.process_path | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `drop_dm_object_name(Processes)` | lookup hijacklibs library AS process_name OUTPUT islibrary | search islibrary - = True | rename parent_process_name as process_name , process_name AS ImageLoaded, process_path AS Module_Path | `windows_dll_search_order_hijacking_hunt_filter`' + = True | rename parent_process_name as process_name , process_name AS ImageLoaded, + process_path AS Module_Path | `windows_dll_search_order_hijacking_hunt_filter`' how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, @@ -81,3 +82,10 @@ tests: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog update_timestamp: true +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/detections/deprecated/windows_hosts_file_modification.yml b/deprecated/detections/windows_hosts_file_modification.yml similarity index 88% rename from detections/deprecated/windows_hosts_file_modification.yml rename to deprecated/detections/windows_hosts_file_modification.yml index 5a02313c4d..5bde2e57dd 100644 --- a/detections/deprecated/windows_hosts_file_modification.yml +++ b/deprecated/detections/windows_hosts_file_modification.yml @@ -43,3 +43,10 @@ tags: - _time risk_score: 25 security_domain: endpoint +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/deprecated/detections/windows_lateral_tool_transfer_remcom.yml b/deprecated/detections/windows_lateral_tool_transfer_remcom.yml new file mode 100644 index 0000000000..0cc2a2a69b --- /dev/null +++ b/deprecated/detections/windows_lateral_tool_transfer_remcom.yml @@ -0,0 +1,114 @@ +name: Windows Lateral Tool Transfer RemCom +id: e373a840-5bdc-47ef-b2fd-9cc7aaf387f0 +version: 5 +date: '2024-12-10' +author: Michael Haag, Splunk +type: TTP +status: deprecated +data_source: +- Sysmon EventID 1 +- Windows Event Log Security 4688 +- CrowdStrike ProcessRollup2 +description: NOTE - This search is deprecated in favor of `Windows Service Execution + RemCom` as the latter is a more accurate name for the detection. The following analytic + identifies the execution of RemCom.exe, an open-source alternative to PsExec, used + for lateral movement and remote command execution. It leverages data from Endpoint + Detection and Response (EDR) agents, focusing on process names, original file names, + and command-line arguments. This activity is significant as it indicates potential + lateral movement within the network. If confirmed malicious, this could allow an + attacker to execute commands remotely, potentially leading to further compromise + and control over additional systems within the network. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=remcom.exe + OR Processes.original_file_name=RemCom.exe) Processes.process="*\\*" Processes.process + IN ("*/user:*", "*/pwd:*") by Processes.dest Processes.user Processes.parent_process_name + Processes.process_name Processes.original_file_name Processes.process Processes.process_id + Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `windows_lateral_tool_transfer_remcom_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. +known_false_positives: False positives may be present based on Administrative use. + Filter as needed. +references: +- https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/ +- https://github.com/kavika13/RemCom +drilldown_searches: +- name: View the detection results for - "$user$" and "$dest$" + search: '%original_detection_search% | search user = "$user$" dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$user$" and "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", + "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) + as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk + Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +tags: + analytic_story: + - Active Directory Discovery + asset_type: Endpoint + confidence: 50 + impact: 80 + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest$ by user $user$ attempting to move laterally. + mitre_attack_id: + - T1570 + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Process + role: + - Attacker + - name: process_name + type: Process + role: + - Attacker + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 40 + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1570/remcom/remcom_windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog +deprecation_metadata: + date: 01-20-2025 + version: 5.0.0 + replacement_id: null + replacement_name: null + migration_guide: URL_to_migration_doc + reason: These analytics are deprecated and are no longer supported diff --git a/investigations/all_backup_logs_for_host.yml b/deprecated/investigations/all_backup_logs_for_host.yml similarity index 100% rename from investigations/all_backup_logs_for_host.yml rename to deprecated/investigations/all_backup_logs_for_host.yml diff --git a/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml b/deprecated/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml similarity index 100% rename from investigations/amazon_eks_kubernetes_activity_by_src_ip.yml rename to deprecated/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml diff --git a/investigations/aws_investigate_security_hub_alerts_by_dest.yml b/deprecated/investigations/aws_investigate_security_hub_alerts_by_dest.yml similarity index 100% rename from investigations/aws_investigate_security_hub_alerts_by_dest.yml rename to deprecated/investigations/aws_investigate_security_hub_alerts_by_dest.yml diff --git a/investigations/aws_investigate_user_activities_by_accesskeyid.yml b/deprecated/investigations/aws_investigate_user_activities_by_accesskeyid.yml similarity index 100% rename from investigations/aws_investigate_user_activities_by_accesskeyid.yml rename to deprecated/investigations/aws_investigate_user_activities_by_accesskeyid.yml diff --git a/investigations/aws_investigate_user_activities_by_arn.yml b/deprecated/investigations/aws_investigate_user_activities_by_arn.yml similarity index 100% rename from investigations/aws_investigate_user_activities_by_arn.yml rename to deprecated/investigations/aws_investigate_user_activities_by_arn.yml diff --git a/investigations/aws_network_acl_details_from_id.yml b/deprecated/investigations/aws_network_acl_details_from_id.yml similarity index 100% rename from investigations/aws_network_acl_details_from_id.yml rename to deprecated/investigations/aws_network_acl_details_from_id.yml diff --git a/investigations/aws_network_interface_details_via_resourceid.yml b/deprecated/investigations/aws_network_interface_details_via_resourceid.yml similarity index 100% rename from investigations/aws_network_interface_details_via_resourceid.yml rename to deprecated/investigations/aws_network_interface_details_via_resourceid.yml diff --git a/investigations/aws_s3_bucket_details_via_bucketname.yml b/deprecated/investigations/aws_s3_bucket_details_via_bucketname.yml similarity index 100% rename from investigations/aws_s3_bucket_details_via_bucketname.yml rename to deprecated/investigations/aws_s3_bucket_details_via_bucketname.yml diff --git a/investigations/gcp_kubernetes_activity_by_src_ip.yml b/deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml similarity index 100% rename from investigations/gcp_kubernetes_activity_by_src_ip.yml rename to deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml diff --git a/investigations/get_all_aws_activity_from_city.yml b/deprecated/investigations/get_all_aws_activity_from_city.yml similarity index 100% rename from investigations/get_all_aws_activity_from_city.yml rename to deprecated/investigations/get_all_aws_activity_from_city.yml diff --git a/investigations/get_all_aws_activity_from_country.yml b/deprecated/investigations/get_all_aws_activity_from_country.yml similarity index 100% rename from investigations/get_all_aws_activity_from_country.yml rename to deprecated/investigations/get_all_aws_activity_from_country.yml diff --git a/investigations/get_all_aws_activity_from_ip_address.yml b/deprecated/investigations/get_all_aws_activity_from_ip_address.yml similarity index 100% rename from investigations/get_all_aws_activity_from_ip_address.yml rename to deprecated/investigations/get_all_aws_activity_from_ip_address.yml diff --git a/investigations/get_all_aws_activity_from_region.yml b/deprecated/investigations/get_all_aws_activity_from_region.yml similarity index 100% rename from investigations/get_all_aws_activity_from_region.yml rename to deprecated/investigations/get_all_aws_activity_from_region.yml diff --git a/investigations/get_backup_logs_for_endpoint.yml b/deprecated/investigations/get_backup_logs_for_endpoint.yml similarity index 100% rename from investigations/get_backup_logs_for_endpoint.yml rename to deprecated/investigations/get_backup_logs_for_endpoint.yml diff --git a/investigations/get_certificate_logs_for_a_domain.yml b/deprecated/investigations/get_certificate_logs_for_a_domain.yml similarity index 100% rename from investigations/get_certificate_logs_for_a_domain.yml rename to deprecated/investigations/get_certificate_logs_for_a_domain.yml diff --git a/investigations/get_dns_server_history_for_a_host.yml b/deprecated/investigations/get_dns_server_history_for_a_host.yml similarity index 100% rename from investigations/get_dns_server_history_for_a_host.yml rename to deprecated/investigations/get_dns_server_history_for_a_host.yml diff --git a/investigations/get_dns_traffic_ratio.yml b/deprecated/investigations/get_dns_traffic_ratio.yml similarity index 100% rename from investigations/get_dns_traffic_ratio.yml rename to deprecated/investigations/get_dns_traffic_ratio.yml diff --git a/investigations/get_ec2_instance_details_by_instanceid.yml b/deprecated/investigations/get_ec2_instance_details_by_instanceid.yml similarity index 100% rename from investigations/get_ec2_instance_details_by_instanceid.yml rename to deprecated/investigations/get_ec2_instance_details_by_instanceid.yml diff --git a/investigations/get_ec2_launch_details.yml b/deprecated/investigations/get_ec2_launch_details.yml similarity index 100% rename from investigations/get_ec2_launch_details.yml rename to deprecated/investigations/get_ec2_launch_details.yml diff --git a/investigations/get_email_info.yml b/deprecated/investigations/get_email_info.yml similarity index 100% rename from investigations/get_email_info.yml rename to deprecated/investigations/get_email_info.yml diff --git a/investigations/get_emails_from_specific_sender.yml b/deprecated/investigations/get_emails_from_specific_sender.yml similarity index 100% rename from investigations/get_emails_from_specific_sender.yml rename to deprecated/investigations/get_emails_from_specific_sender.yml diff --git a/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml b/deprecated/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml similarity index 100% rename from investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml rename to deprecated/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml diff --git a/investigations/get_history_of_email_sources.yml b/deprecated/investigations/get_history_of_email_sources.yml similarity index 100% rename from investigations/get_history_of_email_sources.yml rename to deprecated/investigations/get_history_of_email_sources.yml diff --git a/investigations/get_logon_rights_modifications_for_endpoint.yml b/deprecated/investigations/get_logon_rights_modifications_for_endpoint.yml similarity index 100% rename from investigations/get_logon_rights_modifications_for_endpoint.yml rename to deprecated/investigations/get_logon_rights_modifications_for_endpoint.yml diff --git a/investigations/get_logon_rights_modifications_for_user.yml b/deprecated/investigations/get_logon_rights_modifications_for_user.yml similarity index 100% rename from investigations/get_logon_rights_modifications_for_user.yml rename to deprecated/investigations/get_logon_rights_modifications_for_user.yml diff --git a/investigations/get_notable_history.yml b/deprecated/investigations/get_notable_history.yml similarity index 100% rename from investigations/get_notable_history.yml rename to deprecated/investigations/get_notable_history.yml diff --git a/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml b/deprecated/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml similarity index 100% rename from investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml rename to deprecated/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml diff --git a/investigations/get_parent_process_info.yml b/deprecated/investigations/get_parent_process_info.yml similarity index 100% rename from investigations/get_parent_process_info.yml rename to deprecated/investigations/get_parent_process_info.yml diff --git a/investigations/get_process_file_activity.yml b/deprecated/investigations/get_process_file_activity.yml similarity index 100% rename from investigations/get_process_file_activity.yml rename to deprecated/investigations/get_process_file_activity.yml diff --git a/investigations/get_process_info.yml b/deprecated/investigations/get_process_info.yml similarity index 100% rename from investigations/get_process_info.yml rename to deprecated/investigations/get_process_info.yml diff --git a/investigations/get_process_information_for_port_activity.yml b/deprecated/investigations/get_process_information_for_port_activity.yml similarity index 100% rename from investigations/get_process_information_for_port_activity.yml rename to deprecated/investigations/get_process_information_for_port_activity.yml diff --git a/investigations/get_process_responsible_for_the_dns_traffic.yml b/deprecated/investigations/get_process_responsible_for_the_dns_traffic.yml similarity index 100% rename from investigations/get_process_responsible_for_the_dns_traffic.yml rename to deprecated/investigations/get_process_responsible_for_the_dns_traffic.yml diff --git a/investigations/get_sysmon_wmi_activity_for_host.yml b/deprecated/investigations/get_sysmon_wmi_activity_for_host.yml similarity index 100% rename from investigations/get_sysmon_wmi_activity_for_host.yml rename to deprecated/investigations/get_sysmon_wmi_activity_for_host.yml diff --git a/investigations/get_web_session_information_via_session_id.yml b/deprecated/investigations/get_web_session_information_via_session_id.yml similarity index 100% rename from investigations/get_web_session_information_via_session_id.yml rename to deprecated/investigations/get_web_session_information_via_session_id.yml diff --git a/investigations/investigate_aws_activities_via_region_name.yml b/deprecated/investigations/investigate_aws_activities_via_region_name.yml similarity index 100% rename from investigations/investigate_aws_activities_via_region_name.yml rename to deprecated/investigations/investigate_aws_activities_via_region_name.yml diff --git a/investigations/investigate_aws_user_activities_by_user_field.yml b/deprecated/investigations/investigate_aws_user_activities_by_user_field.yml similarity index 100% rename from investigations/investigate_aws_user_activities_by_user_field.yml rename to deprecated/investigations/investigate_aws_user_activities_by_user_field.yml diff --git a/investigations/investigate_failed_logins_for_multiple_destinations.yml b/deprecated/investigations/investigate_failed_logins_for_multiple_destinations.yml similarity index 100% rename from investigations/investigate_failed_logins_for_multiple_destinations.yml rename to deprecated/investigations/investigate_failed_logins_for_multiple_destinations.yml diff --git a/investigations/investigate_network_traffic_from_src_ip.yml b/deprecated/investigations/investigate_network_traffic_from_src_ip.yml similarity index 100% rename from investigations/investigate_network_traffic_from_src_ip.yml rename to deprecated/investigations/investigate_network_traffic_from_src_ip.yml diff --git a/investigations/investigate_okta_activity_by_app.yml b/deprecated/investigations/investigate_okta_activity_by_app.yml similarity index 100% rename from investigations/investigate_okta_activity_by_app.yml rename to deprecated/investigations/investigate_okta_activity_by_app.yml diff --git a/investigations/investigate_okta_activity_by_ip_address.yml b/deprecated/investigations/investigate_okta_activity_by_ip_address.yml similarity index 100% rename from investigations/investigate_okta_activity_by_ip_address.yml rename to deprecated/investigations/investigate_okta_activity_by_ip_address.yml diff --git a/investigations/investigate_pass_the_hash_attempts.yml b/deprecated/investigations/investigate_pass_the_hash_attempts.yml similarity index 100% rename from investigations/investigate_pass_the_hash_attempts.yml rename to deprecated/investigations/investigate_pass_the_hash_attempts.yml diff --git a/investigations/investigate_pass_the_ticket_attempts.yml b/deprecated/investigations/investigate_pass_the_ticket_attempts.yml similarity index 100% rename from investigations/investigate_pass_the_ticket_attempts.yml rename to deprecated/investigations/investigate_pass_the_ticket_attempts.yml diff --git a/investigations/investigate_previous_unseen_user.yml b/deprecated/investigations/investigate_previous_unseen_user.yml similarity index 100% rename from investigations/investigate_previous_unseen_user.yml rename to deprecated/investigations/investigate_previous_unseen_user.yml diff --git a/investigations/investigate_successful_remote_desktop_authentications.yml b/deprecated/investigations/investigate_successful_remote_desktop_authentications.yml similarity index 100% rename from investigations/investigate_successful_remote_desktop_authentications.yml rename to deprecated/investigations/investigate_successful_remote_desktop_authentications.yml diff --git a/investigations/investigate_suspicious_strings_in_http_header.yml b/deprecated/investigations/investigate_suspicious_strings_in_http_header.yml similarity index 100% rename from investigations/investigate_suspicious_strings_in_http_header.yml rename to deprecated/investigations/investigate_suspicious_strings_in_http_header.yml diff --git a/investigations/investigate_user_activities_in_okta.yml b/deprecated/investigations/investigate_user_activities_in_okta.yml similarity index 100% rename from investigations/investigate_user_activities_in_okta.yml rename to deprecated/investigations/investigate_user_activities_in_okta.yml diff --git a/investigations/investigate_web_posts_from_src.yml b/deprecated/investigations/investigate_web_posts_from_src.yml similarity index 100% rename from investigations/investigate_web_posts_from_src.yml rename to deprecated/investigations/investigate_web_posts_from_src.yml diff --git a/lookups/aws_service_accounts.csv b/deprecated/lookups/aws_service_accounts.csv similarity index 100% rename from lookups/aws_service_accounts.csv rename to deprecated/lookups/aws_service_accounts.csv diff --git a/lookups/aws_service_accounts.yml b/deprecated/lookups/aws_service_accounts.yml similarity index 100% rename from lookups/aws_service_accounts.yml rename to deprecated/lookups/aws_service_accounts.yml diff --git a/lookups/discovered_dns_records.csv b/deprecated/lookups/discovered_dns_records.csv similarity index 100% rename from lookups/discovered_dns_records.csv rename to deprecated/lookups/discovered_dns_records.csv diff --git a/lookups/discovered_dns_records.yml b/deprecated/lookups/discovered_dns_records.yml similarity index 100% rename from lookups/discovered_dns_records.yml rename to deprecated/lookups/discovered_dns_records.yml diff --git a/stories/deprecated/aws_cryptomining.yml b/deprecated/stories/aws_cryptomining.yml similarity index 100% rename from stories/deprecated/aws_cryptomining.yml rename to deprecated/stories/aws_cryptomining.yml diff --git a/stories/deprecated/aws_suspicious_provisioning_activities.yml b/deprecated/stories/aws_suspicious_provisioning_activities.yml similarity index 100% rename from stories/deprecated/aws_suspicious_provisioning_activities.yml rename to deprecated/stories/aws_suspicious_provisioning_activities.yml diff --git a/stories/deprecated/common_phishing_frameworks.yml b/deprecated/stories/common_phishing_frameworks.yml similarity index 100% rename from stories/deprecated/common_phishing_frameworks.yml rename to deprecated/stories/common_phishing_frameworks.yml diff --git a/stories/deprecated/container_implantation_monitoring_and_investigation.yml b/deprecated/stories/container_implantation_monitoring_and_investigation.yml similarity index 100% rename from stories/deprecated/container_implantation_monitoring_and_investigation.yml rename to deprecated/stories/container_implantation_monitoring_and_investigation.yml diff --git a/stories/deprecated/host_redirection.yml b/deprecated/stories/host_redirection.yml similarity index 100% rename from stories/deprecated/host_redirection.yml rename to deprecated/stories/host_redirection.yml diff --git a/stories/deprecated/kubernetes_sensitive_role_activity.yml b/deprecated/stories/kubernetes_sensitive_role_activity.yml similarity index 100% rename from stories/deprecated/kubernetes_sensitive_role_activity.yml rename to deprecated/stories/kubernetes_sensitive_role_activity.yml diff --git a/stories/deprecated/lateral_movement.yml b/deprecated/stories/lateral_movement.yml similarity index 100% rename from stories/deprecated/lateral_movement.yml rename to deprecated/stories/lateral_movement.yml diff --git a/stories/deprecated/monitor_backup_solution.yml b/deprecated/stories/monitor_backup_solution.yml similarity index 100% rename from stories/deprecated/monitor_backup_solution.yml rename to deprecated/stories/monitor_backup_solution.yml diff --git a/stories/deprecated/monitor_for_unauthorized_software.yml b/deprecated/stories/monitor_for_unauthorized_software.yml similarity index 100% rename from stories/deprecated/monitor_for_unauthorized_software.yml rename to deprecated/stories/monitor_for_unauthorized_software.yml diff --git a/stories/deprecated/office_365_detections.yml b/deprecated/stories/office_365_detections.yml similarity index 100% rename from stories/deprecated/office_365_detections.yml rename to deprecated/stories/office_365_detections.yml diff --git a/stories/deprecated/spectre_and_meltdown_vulnerabilities.yml b/deprecated/stories/spectre_and_meltdown_vulnerabilities.yml similarity index 100% rename from stories/deprecated/spectre_and_meltdown_vulnerabilities.yml rename to deprecated/stories/spectre_and_meltdown_vulnerabilities.yml diff --git a/stories/deprecated/suspicious_aws_ec2_activities.yml b/deprecated/stories/suspicious_aws_ec2_activities.yml similarity index 100% rename from stories/deprecated/suspicious_aws_ec2_activities.yml rename to deprecated/stories/suspicious_aws_ec2_activities.yml diff --git a/stories/deprecated/unusual_aws_ec2_modifications.yml b/deprecated/stories/unusual_aws_ec2_modifications.yml similarity index 100% rename from stories/deprecated/unusual_aws_ec2_modifications.yml rename to deprecated/stories/unusual_aws_ec2_modifications.yml diff --git a/stories/deprecated/web_fraud_detection.yml b/deprecated/stories/web_fraud_detection.yml similarity index 100% rename from stories/deprecated/web_fraud_detection.yml rename to deprecated/stories/web_fraud_detection.yml diff --git a/detections/deprecated/asl_aws_createaccesskey.yml b/detections/deprecated/asl_aws_createaccesskey.yml deleted file mode 100644 index 477f384c24..0000000000 --- a/detections/deprecated/asl_aws_createaccesskey.yml +++ /dev/null @@ -1,87 +0,0 @@ -name: ASL AWS CreateAccessKey -id: ccb3e4af-23d6-407f-9842-a26212816c9e -version: 2 -date: '2024-10-17' -author: Patrick Bareiss, Splunk -status: deprecated -type: Hunting -description: This detection rule monitors for the creation of AWS Identity and Access Management (IAM) access keys. - An IAM access key consists of an access key ID and secret access key, which are used to sign programmatic requests to AWS services. - While IAM access keys can be legitimately used by developers and administrators for API access, their creation can also be indicative - of malicious activity. Attackers who have gained unauthorized access to an AWS environment might create access keys as a means to - establish persistence or to exfiltrate data through the APIs. Moreover, because access keys can be used to authenticate with AWS - services without the need for further interaction, they can be particularly appealing for bad actors looking to operate under the radar. - Consequently, it's important to vigilantly monitor and scrutinize access key creation events, especially if they are associated with - unusual activity or are created by users who don't typically perform these actions. This hunting query identifies when a potentially compromised user - creates a IAM access key for another user who may have higher privilleges, which can be a sign for privilege escalation. Hunting queries are designed to be executed - manual during threat hunting. -data_source: [] -search: '`amazon_security_lake` api.operation=CreateAccessKey http_request.user_agent!=console.amazonaws.com api.response.error=null - | rename unmapped{}.key as unmapped_key , unmapped{}.value as unmapped_value - | eval keyjoin=mvzip(unmapped_key,unmapped_value) - | mvexpand keyjoin - | rex field=keyjoin "^(?[^,]+),(?.*)$" - | eval {key} = value - | search responseElements.accessKey.userName = * - | rename identity.user.name as identity_user_name, responseElements.accessKey.userName as responseElements_accessKey_userName - | eval match=if(identity_user_name=responseElements_accessKey_userName,1,0) - | search match=0 - | rename identity_user_name as identity.user.name , responseElements_accessKey_userName as responseElements.accessKey.userName - | stats count min(_time) as firstTime max(_time) as lastTime by responseElements.accessKey.userName - api.operation api.service.name identity.user.account_uid identity.user.credential_uid identity.user.name - identity.user.type identity.user.uid identity.user.uuid http_request.user_agent src_endpoint.ip - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - |`asl_aws_createaccesskey_filter`' -how_to_implement: You must install Splunk Add-On for AWS Version v7.0.0 (https://splunkbase.splunk.com/app/1876) that includes includes a merge of all the capabilities of the Splunk Add-on for Amazon Security Lake. This search works with Amazon Security Lake logs which are parsed in the Open Cybersecurity Schema Framework (OCSF)format. -known_false_positives: While this search has no known false positives, it is possible - that an AWS admin has legitimately created keys for another user. -references: -- https://bishopfox.com/blog/privilege-escalation-in-aws -- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ -tags: - analytic_story: - - AWS IAM Privilege Escalation - asset_type: AWS Account - confidence: 90 - impact: 70 - message: User $responseElements.accessKey.userName$ is attempting to create access keys for $responseElements.accessKey.userName$ - from this IP $src_endpoint.ip$ - mitre_attack_id: - - T1078 - observable: - - name: src_endpoint.ip - type: IP Address - role: - - Attacker - - name: identity.user.name - type: User - role: - - Attacker - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - api.service.name - - api.operation - - identity.user.account_uid - - identity.user.credential_uid - - identity.user.name - - identity.user.type - - identity.user.uid - - identity.user.uuid - - http_request.user_agent - - src_endpoint.ip - - unmapped{}.key - - unmapped{}.value - risk_score: 63 - security_domain: threat -tests: -- name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/amazon_security_lake.json - sourcetype: aws:asl - source: aws_asl - update_timestamp: true - diff --git a/detections/deprecated/correlation_by_repository_and_risk.yml b/detections/deprecated/correlation_by_repository_and_risk.yml deleted file mode 100644 index ef3930edee..0000000000 --- a/detections/deprecated/correlation_by_repository_and_risk.yml +++ /dev/null @@ -1,39 +0,0 @@ -name: Correlation by Repository and Risk -id: 8da9fdd9-6a1b-4ae0-8a34-8c25e6be9687 -version: 2 -date: '2024-10-17' -author: Patrick Bareiss, Splunk -status: deprecated -type: Correlation -description: |- - This search has been deprecated and updated with Risk Rule for Dev Sec Ops by Repository detection. The following analytic detects by correlating repository and risk score to identify patterns and trends in the data based on the level of risk associated. The analytic adds any null values and calculates the sum of the risk scores for each detection. Then, the analytic captures the source and user information for each detection and sorts the results in ascending order based on the risk score. Finally, the analytic filters the detections with a risk score below 80 and focuses only on high-risk detections.This detection is important because it provides valuable insights into the distribution of high-risk activities across different repositories. It also identifies the most vulnerable repositories that are frequently targeted by potential threats. Additionally, it proactively detects and responds to potential threats, thereby minimizing the impact of attacks and safeguarding critical assets. Finally, it provides a comprehensive view of the risk landscape and helps to make informed decisions to protect the organization's data and infrastructure. False positives might occur so it is important to identify the impact of the attack and prioritize response and mitigation efforts. -data_source: [] -search: '`risk_index` | fillnull | stats sum(risk_score) as risk_score values(source) - as signals values(user) as user by repository | sort - risk_score | where risk_score - > 80 | `correlation_by_repository_and_risk_filter`' -how_to_implement: For Dev Sec Ops POC -known_false_positives: unknown -references: [] -tags: - analytic_story: - - Dev Sec Ops - asset_type: AWS Account - confidence: 100 - impact: 70 - message: Correlation triggered for user $user$ - mitre_attack_id: - - T1204.003 - - T1204 - observable: - - name: user - type: User - role: - - Victim - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - risk_score: 70 - security_domain: network diff --git a/detections/deprecated/correlation_by_user_and_risk.yml b/detections/deprecated/correlation_by_user_and_risk.yml deleted file mode 100644 index 582d10159d..0000000000 --- a/detections/deprecated/correlation_by_user_and_risk.yml +++ /dev/null @@ -1,39 +0,0 @@ -name: Correlation by User and Risk -id: 610e12dc-b6fa-4541-825e-4a0b3b6f6773 -version: 2 -date: '2024-10-17' -author: Patrick Bareiss, Splunk -status: deprecated -type: Correlation -description: |- - The following analytic detects the correlation between the user and risk score and identifies users with a high risk score that pose a significant security risk such as unauthorized access attempts, suspicious behavior, or potential insider threats. Next, the analytic calculates the sum of the risk scores and groups the results by user, the corresponding signals, and the repository. The results are sorted in descending order based on the risk score and filtered to include records with a risk score greater than 80. Finally, the results are passed through a correlation filter specific to the user and risk. This detection is important because it identifies users who have a high risk score and helps to prioritize investigations and allocate resources. False positives might occur but the impact of such an attack can vary depending on the specific scenario such as data exfiltration, system compromise, or the disruption of critical services. Please investigate this notable event. -data_source: [] -search: '`risk_index` | fillnull | stats sum(risk_score) as risk_score values(source) - as signals values(repository) as repository by user | sort - risk_score | where - risk_score > 80 | `correlation_by_user_and_risk_filter`' -how_to_implement: For Dev Sec Ops POC -known_false_positives: unknown -references: [] -tags: - analytic_story: - - Dev Sec Ops - asset_type: AWS Account - confidence: 100 - impact: 70 - message: Correlation triggered for user $user$ - mitre_attack_id: - - T1204.003 - - T1204 - observable: - - name: user - type: User - role: - - Victim - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - risk_score: 70 - security_domain: network diff --git a/detections/deprecated/o365_suspicious_rights_delegation.yml b/detections/deprecated/o365_suspicious_rights_delegation.yml deleted file mode 100644 index fcc6cd4f44..0000000000 --- a/detections/deprecated/o365_suspicious_rights_delegation.yml +++ /dev/null @@ -1,55 +0,0 @@ -name: O365 Suspicious Rights Delegation -id: b25d2973-303e-47c8-bacd-52b61604c6a7 -version: 3 -date: '2024-10-17' -author: Patrick Bareiss, Mauricio Velazco, Splunk -status: deprecated -type: TTP -description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `O365 Elevated Mailbox Permission Assigned`. - This analytic identifies instances where potentially suspicious rights are delegated within the Office 365 environment. Specifically, it detects when a user is granted FullAccess, SendAs, or SendOnBehalf permissions on another users mailbox. Such permissions can allow a user to access, send emails from, or send emails on behalf of the target mailbox. The detection leverages O365 audit logs, focusing on the Add-MailboxPermission operation. By parsing the parameters of this operation, the analytic filters for events where FullAccess, SendAs, or SendOnBehalf rights are granted. It then aggregates this data to capture the source user (who was granted the permissions), the destination user (whose mailbox was affected), the specific operation, and the type of access rights granted. Delegating mailbox rights, especially those as powerful as FullAccess, can pose significant security risks. While there are legitimate scenarios for these permissions, such as an executive assistant needing access to an executives mailbox, there are also malicious scenarios where an attacker or a compromised insider might grant themselves unauthorized access to sensitive mailboxes. Monitoring for these permissions changes is crucial to detect potential insider threats, compromised accounts, or other malicious activities.If the detection is a true positive, it indicates that a user has been granted potentially high-risk permissions on another users mailbox. This could lead to unauthorized access to sensitive emails, impersonation through sending emails as or on behalf of the mailbox owner, or data manipulation by altering or deleting emails. Immediate investigation is required to validate the legitimacy of the permission change and to assess the potential risks associated with the granted access.' -data_source: [] -search: '`o365_management_activity` Operation=Add-MailboxPermission | spath input=Parameters - | rename User AS src_user, Identity AS dest_user | search AccessRights=FullAccess - OR AccessRights=SendAs OR AccessRights=SendOnBehalf | stats count earliest(_time) - as firstTime latest(_time) as lastTime by user src_user dest_user Operation AccessRights - |`security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` |`o365_suspicious_rights_delegation_filter`' -how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest Office 365 management activity events. -known_false_positives: While there are legitimate scenarios for these permissions, such as an executive assistant needing access to an executive's mailbox, there are also malicious scenarios. Investigate and filter as needed. -references: -- https://www.mandiant.com/resources/blog/remediation-and-hardening-strategies-for-microsoft-365-to-defend-against-unc2452 -- https://attack.mitre.org/techniques/T1098/002/ -- https://attack.mitre.org/techniques/T1114/002/ -tags: - analytic_story: - - Office 365 Collection Techniques - asset_type: O365 Tenant - confidence: 60 - impact: 80 - message: User $user$ has delegated suspicious rights $AccessRights$ to user $dest_user$ - that allow access to sensitive - mitre_attack_id: - - T1114.002 - - T1114 - - T1098.002 - - T1098 - observable: - - name: user - type: User - role: - - Victim - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - - Operation - - Parameters - risk_score: 48 - security_domain: threat -tests: -- name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114.002/suspicious_rights_delegation/suspicious_rights_delegation.json - sourcetype: o365:management:activity - source: o365 diff --git a/detections/deprecated/o365_suspicious_user_email_forwarding.yml b/detections/deprecated/o365_suspicious_user_email_forwarding.yml deleted file mode 100644 index 2855f74738..0000000000 --- a/detections/deprecated/o365_suspicious_user_email_forwarding.yml +++ /dev/null @@ -1,57 +0,0 @@ -name: O365 Suspicious User Email Forwarding -id: f8dfe015-dbb3-4569-ba75-b13787e06aa4 -version: 3 -date: '2024-10-17' -author: Patrick Bareiss, Splunk -status: deprecated -type: Anomaly -description: - '**DEPRECATION NOTE** - This search has been deprecated and replaced with `O365 Mailbox Email Forwarding Enabled`. - The following analytic detects when multiple users have configured a forwarding rule to the same destination to proactively identify and investigate potential security risks related to email forwarding and take appropriate actions to protect the organizations data and prevent unauthorized access or data breaches. This detection is made by a Splunk query to O365 management activity logs with the operation `Set-Mailbox` to gather information about mailbox configurations. Then, the query uses the `spath` function to extract the parameters and rename the "Identity" field as "src_user" and searches for entries where the "ForwardingSmtpAddress" field is not empty, which indicates the presence of a forwarding rule. Next, the analytic uses the `stats` command to group the results by the forwarding email address and count the number of unique source users (`src_user`). Finally, it filters the results and only retains entries where the count of source users (`count_src_user`) is greater than 1, which indicates that multiple users have set up forwarding rules to the same destination. This detection is important because it suggests that multiple users are forwarding emails to the same destination without proper authorization, which can lead to the exposure of sensitive information, loss of data control, or unauthorized access to confidential emails. Investigating and addressing this issue promptly can help prevent data breaches and mitigate potential damage.indicates a potential security risk since multiple users forwarding emails to the same destination can be a sign of unauthorized access, data exfiltration, or a compromised account. Additionally, it also helps to determine if the forwarding rules are legitimate or if they indicate a security incident. False positives can occur if there are legitimate reasons for multiple users to forward emails to the same destination, such as a shared mailbox or a team collaboration scenario. Next steps include further investigation and context analysis to determine the legitimacy of the forwarding rules.' -data_source: [] -search: '`o365_management_activity` Operation=Set-Mailbox | spath input=Parameters - | rename Identity AS src_user | search ForwardingSmtpAddress=* | stats dc(src_user) - AS count_src_user earliest(_time) as firstTime latest(_time) as lastTime values(src_user) - AS src_user values(user) AS user by ForwardingSmtpAddress | where count_src_user - > 1 |`security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` |`o365_suspicious_user_email_forwarding_filter`' -how_to_implement: You must install splunk Microsoft Office 365 add-on. This search - works with o365:management:activity -known_false_positives: unknown -references: [] -tags: - analytic_story: - - Office 365 Collection Techniques - - Data Exfiltration - asset_type: O365 Tenant - confidence: 60 - impact: 80 - message: User $user$ configured multiple users $src_user$ with a count of $count_src_user$, - a forwarding rule to same destination $ForwardingSmtpAddress$ - mitre_attack_id: - - T1114.003 - - T1114 - observable: - - name: user - type: User - role: - - Victim - - name: ForwardingSmtpAddress - type: Email Address - role: - - Attacker - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - - Operation - - Parameters - risk_score: 48 - security_domain: threat -tests: -- name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114.003/o365_mailbox_forwarding_enabled/o365_mailbox_forwarding_enabled.json - sourcetype: o365:management:activity - source: o365 diff --git a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml b/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml deleted file mode 100644 index 0c308a051f..0000000000 --- a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml +++ /dev/null @@ -1,49 +0,0 @@ -name: Okta ThreatInsight Login Failure with High Unknown users -id: 632663b0-4562-4aad-abe9-9f621a049738 -version: 3 -date: '2024-10-17' -author: Okta, Inc, Michael Haag, Splunk -type: TTP -status: deprecated -data_source: [] -description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta ThreatInsight Threat Detected`. - The following analytic utilizes Oktas ThreatInsight to identify Login failures with high unknown users count and any included secondary outcome reasons. - This event will trigger when a brute force attempt occurs with unknown usernames attempted.' -search: '`okta` eventType="security.threat.detected" AND outcome.reason="Login failures with high unknown users count*" -| stats count min(_time) as firstTime max(_time) as lastTime values(displayMessage) by user eventType client.userAgent.rawUserAgent client.userAgent.browser outcome.reason -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` | `okta_threatinsight_login_failure_with_high_unknown_users_filter`' -how_to_implement: This search is specific to Okta and requires Okta logs to be - ingested in your Splunk deployment. -known_false_positives: Fidelity of this is high as it is Okta ThreatInsight. Filter and modify as needed. -references: -- https://help.okta.com/en-us/Content/Topics/Security/threat-insight/configure-threatinsight-system-log.htm -tags: - analytic_story: - - Suspicious Okta Activity - asset_type: Infrastructure - confidence: 100 - impact: 50 - message: Okta ThreatInsight has detected or prevented a high number of login failures. - mitre_attack_id: - - T1078 - - T1078.001 - - T1110.004 - observable: - - name: user - type: User - role: - - Victim - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - - eventType - - client.userAgent.rawUserAgent - - client.userAgent.browser - - outcome.reason - - displayMessage - risk_score: 50 - security_domain: access diff --git a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml b/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml deleted file mode 100644 index 9ca05aa50e..0000000000 --- a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml +++ /dev/null @@ -1,50 +0,0 @@ -name: Okta ThreatInsight Suspected PasswordSpray Attack -id: 25dbad05-6682-4dd5-9ce9-8adecf0d9ae2 -version: 3 -date: '2024-10-17' -author: Okta, Inc, Michael Haag, Splunk -type: TTP -status: deprecated -data_source: [] -description: - '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta ThreatInsight Threat Detected`. - The following analytic utilizes Oktas ThreatInsight to identify "PasswordSpray" and any included secondary outcome reasons. This event will trigger when a - brute force attempt occurs with unknown usernames attempted.' -search: '`okta` eventType="security.threat.detected" AND outcome.reason="Password Spray" -| stats count min(_time) as firstTime max(_time) as lastTime values(displayMessage) by eventType client.userAgent.rawUserAgent client.userAgent.browser outcome.reason -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` | `okta_threatinsight_suspected_passwordspray_attack_filter`' -how_to_implement: This search is specific to Okta and requires Okta logs to be - ingested in your Splunk deployment. -known_false_positives: Fidelity of this is high as it is Okta ThreatInsight. Filter and modify as needed. -references: -- https://help.okta.com/en-us/Content/Topics/Security/threat-insight/configure-threatinsight-system-log.htm -tags: - analytic_story: - - Suspicious Okta Activity - asset_type: Infrastructure - confidence: 100 - impact: 60 - message: Okta ThreatInsight has detected or prevented a PasswordSpray attack. - mitre_attack_id: - - T1078 - - T1078.001 - - T1110.003 - observable: - - name: outcome.reason - type: Other - role: - - Victim - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - - eventType - - client.userAgent.rawUserAgent - - client.userAgent.browser - - outcome.reason - - displayMessage - risk_score: 60 - security_domain: access diff --git a/detections/deprecated/windows_lateral_tool_transfer_remcom.yml b/detections/deprecated/windows_lateral_tool_transfer_remcom.yml deleted file mode 100644 index 167e76f761..0000000000 --- a/detections/deprecated/windows_lateral_tool_transfer_remcom.yml +++ /dev/null @@ -1,78 +0,0 @@ -name: Windows Lateral Tool Transfer RemCom -id: e373a840-5bdc-47ef-b2fd-9cc7aaf387f0 -version: 5 -date: '2024-12-10' -author: Michael Haag, Splunk -type: TTP -status: deprecated -data_source: -- Sysmon EventID 1 -- Windows Event Log Security 4688 -- CrowdStrike ProcessRollup2 -description: NOTE - This search is deprecated in favor of `Windows Service Execution RemCom` as the latter is a more accurate name for the detection. The following analytic identifies the execution of RemCom.exe, an open-source alternative to PsExec, used for lateral movement and remote command execution. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names, original file names, and command-line arguments. This activity is significant as it indicates potential lateral movement within the network. If confirmed malicious, this could allow an attacker to execute commands remotely, potentially leading to further compromise and control over additional systems within the network. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=remcom.exe OR Processes.original_file_name=RemCom.exe) Processes.process="*\\*" Processes.process IN ("*/user:*", "*/pwd:*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_lateral_tool_transfer_remcom_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: False positives may be present based on Administrative use. Filter as needed. -references: -- https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/ -- https://github.com/kavika13/RemCom -drilldown_searches: -- name: View the detection results for - "$user$" and "$dest$" - search: '%original_detection_search% | search user = "$user$" dest = "$dest$"' - earliest_offset: $info_min_time$ - latest_offset: $info_max_time$ -- name: View risk events for the last 7 days for - "$user$" and "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' - earliest_offset: $info_min_time$ - latest_offset: $info_max_time$ -tags: - analytic_story: - - Active Directory Discovery - asset_type: Endpoint - confidence: 50 - impact: 80 - message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to move laterally. - mitre_attack_id: - - T1570 - observable: - - name: user - type: User - role: - - Victim - - name: dest - type: Hostname - role: - - Victim - - name: parent_process_name - type: Process - role: - - Attacker - - name: process_name - type: Process - role: - - Attacker - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - - Processes.dest - - Processes.user - - Processes.parent_process_name - - Processes.parent_process - - Processes.original_file_name - - Processes.process_name - - Processes.process - - Processes.process_id - - Processes.parent_process_path - - Processes.process_path - - Processes.parent_process_id - risk_score: 40 - security_domain: endpoint -tests: -- name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1570/remcom/remcom_windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index cec1b2f2c7..0c5908738b 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -53,7 +53,6 @@ drilldown_searches: tags: analytic_story: - XMRig - - Monitor for Unauthorized Software - Unusual Processes - SamSam Ransomware - CISA AA22-264A