From b622c65defd1c336c136ad2d80b9a1bb61aa1bb0 Mon Sep 17 00:00:00 2001 From: research bot Date: Thu, 28 Jul 2022 22:52:59 +0000 Subject: [PATCH 1/2] updating docs and package bits [ci skip] --- dist/escu/app.manifest | 2 +- dist/escu/default/analyticstories.conf | 326 ++++- dist/escu/default/app.conf | 4 +- dist/escu/default/collections.conf | 2 +- dist/escu/default/content-version.conf | 2 +- dist/escu/default/es_investigations.conf | 2 +- dist/escu/default/macros.conf | 102 +- dist/escu/default/savedsearches.conf | 1180 ++++++++++++++++- dist/escu/default/transforms.conf | 2 +- dist/escu/default/workflow_actions.conf | 2 +- docs/_pages/detections.md | 24 + docs/_pages/stories.md | 5 + ...od_without_successful_netbackup_backups.md | 2 +- ...17-09-12-unsuccessful_netbackup_backups.md | 2 +- .../2017-09-23-monitor_dns_for_brand_abuse.md | 2 +- ...-23-monitor_web_traffic_for_brand_abuse.md | 2 +- ...-10-23-wmi_permanent_event_subscription.md | 2 +- ...-10-23-wmi_temporary_event_subscription.md | 2 +- .../2018-12-03-remote_wmi_command_attempt.md | 2 +- .../2018-12-06-suspicious_java_classes.md | 2 +- ...ikatz_via_powershell_and_eventcode_4703.md | 2 +- .../2019-04-25-suspicious_file_write.md | 2 +- .../2020-02-21-dump_lsass_via_comsvcs_dll.md | 2 +- ...n_eks_kubernetes_cluster_scan_detection.md | 2 +- ...mazon_eks_kubernetes_pod_scan_detection.md | 2 +- ...5-gcp_kubernetes_cluster_scan_detection.md | 2 +- ...0-first_time_seen_child_process_of_zoom.md | 2 +- .../2020-07-06-windows_event_log_cleared.md | 4 +- ...20-07-08-detect_new_local_admin_account.md | 2 +- ..._to_phishing_sites_leveraging_evilginx2.md | 8 +- ...ce_modified_with_previously_unseen_user.md | 2 +- ...first_time_seen_running_windows_service.md | 2 +- ...shell_process_-_execution_policy_bypass.md | 3 +- ...th_invalid_credentials_from_the_same_ip.md | 2 +- .../2020-07-21-okta_failed_sso_attempts.md | 2 +- ...1-okta_user_logins_from_multiple_cities.md | 2 +- ...-suspicious_email_attachment_extensions.md | 2 +- ...ct_windows_dns_sigred_via_splunk_stream.md | 2 +- ...ivity_from_previously_unseen_ip_address.md | 2 +- ..._activity_from_previously_unseen_region.md | 2 +- ...ng_activity_from_previously_unseen_city.md | 2 +- ...tivity_related_to_pass_the_hash_attacks.md | 2 +- ...2020-11-09-common_ransomware_extensions.md | 2 +- .../2020-11-09-common_ransomware_notes.md | 2 +- ..._system_network_configuration_discovery.md | 2 +- ...rohibited_applications_spawning_cmd_exe.md | 2 +- ...12-15-o365_suspicious_rights_delegation.md | 2 +- .../2020-12-16-o365_pst_export_alert.md | 2 +- ...-o365_suspicious_admin_email_forwarding.md | 2 +- ...6-o365_suspicious_user_email_forwarding.md | 2 +- ...cious_microsoft_workflow_compiler_usage.md | 2 +- ..._connecting_to_dynamic_domain_providers.md | 2 +- ...ell_process_with_obfuscation_techniques.md | 2 +- ...20-detect_rundll32_inline_hta_execution.md | 2 +- .../2021-01-20-suspicious_mshta_spawn.md | 2 +- ...o365_add_app_role_assignment_grant_user.md | 2 +- ...1-01-26-o365_excessive_sso_logon_errors.md | 2 +- ...1-01-26-o365_new_federated_domain_added.md | 2 +- ...ect_regsvr32_application_control_bypass.md | 2 +- ...cious_regsvr32_register_suspicious_path.md | 2 +- ...32_application_control_bypass_-_advpack.md | 2 +- ...2_application_control_bypass_-_setupapi.md | 2 +- ...2_application_control_bypass_-_syssetup.md | 2 +- .../2021-02-04-suspicious_rundll32_startw.md | 2 +- ...9-suspicious_rundll32_dllregisterserver.md | 2 +- ...2-22-suspicious_curl_network_connection.md | 1 + ...2021-03-03-nishang_powershelltcponeline.md | 2 +- docs/_posts/2021-03-03-w3wp_spawning_shell.md | 4 +- ...16-windows_high_file_deletion_frequency.md | 5 +- ...3-17-clop_ransomware_known_service_name.md | 2 +- ...021-03-29-powershell_start-bitstransfer.md | 2 +- ...021-03-31-disabling_firewall_with_netsh.md | 2 +- ...icious_powershell_executed_as_a_service.md | 2 +- ...heduled_task_created_within_public_path.md | 2 +- .../2021-04-12-excel_spawning_powershell.md | 2 +- ...t_scheduled_task_created_to_spawn_shell.md | 2 +- .../2021-04-12-winword_spawning_powershell.md | 3 +- ...fice_application_spawn_rundll32_process.md | 2 +- ...14-office_document_executing_macro_code.md | 1 + ...hedule_task_with_http_command_arguments.md | 2 +- ...dule_task_with_rundll32_command_trigger.md | 2 +- ...ocess_spawned_cmd_or_powershell_process.md | 4 +- ...ultiple_archive_files_http_post_traffic.md | 2 +- ...e_product_spawning_rundll32_with_no_dll.md | 2 +- ...-04-22-plain_http_post_exfiltrated_data.md | 2 +- .../_posts/2021-04-22-winword_spawning_cmd.md | 3 +- ...04-26-office_product_spawning_bitsadmin.md | 2 +- ...021-04-26-office_product_spawning_mshta.md | 2 +- ...21-05-04-process_kill_base_on_file_path.md | 2 +- ...2021-05-05-suspicious_process_file_path.md | 1 + ...merate_users_local_group_using_telegram.md | 2 +- ...s_or_script_creation_in_suspicious_path.md | 1 + ...-allow_inbound_traffic_in_firewall_rule.md | 2 +- .../2021-05-20-cmd_echo_pipe_-_escalation.md | 2 +- ...-04-known_services_killed_by_ransomware.md | 2 +- ...021-06-09-unloading_amsi_via_reflection.md | 2 +- ...7-suspicious_event_log_service_behavior.md | 2 +- ...ursive_delete_of_directory_in_batch_cmd.md | 2 +- ...w_file_and_printing_sharing_in_firewall.md | 2 +- ...-23-allow_network_discovery_in_firewall.md | 2 +- ...1-print_spooler_adding_a_printer_driver.md | 2 +- ...-print_spooler_failed_to_load_a_plug-in.md | 2 +- .../2021-07-01-spoolsv_spawning_rundll32.md | 2 +- ...a_spawning_rundll32_or_regsvr32_process.md | 2 +- ...-07-19-office_product_spawn_cmd_process.md | 3 +- ...of_shadowcopy_with_script_block_logging.md | 2 +- ...7-26-suspicious_icedid_rundll32_cmdline.md | 2 +- ...21-07-26-suspicious_rundll32_plugininit.md | 2 +- ...gsvr32_with_known_silent_switch_cmdline.md | 2 +- ...fice_application_spawn_regsvr32_process.md | 2 +- ...8-16-gsuite_email_suspicious_attachment.md | 2 +- ...mail_with_attachment_to_external_domain.md | 2 +- ...9-aws_ecr_container_upload_unknown_user.md | 2 +- ...mail_suspicious_subject_with_attachment.md | 2 +- ...1-08-20-github_commit_changes_in_master.md | 2 +- ...email_with_known_abuse_web_service_link.md | 2 +- ...21-08-24-adsisearcher_account_discovery.md | 2 +- ...get_aduser_with_powershell_script_block.md | 2 +- ...omain_group_discovery_with_adsisearcher.md | 2 +- ...elevated_group_discovery_with_powerview.md | 2 +- ...petitpotam_network_share_access_request.md | 2 +- ...itpotam_suspicious_kerberos_tgt_request.md | 2 +- ...1-09-01-circle_ci_disable_security_step.md | 2 +- .../2021-09-01-github_commit_in_develop.md | 2 +- .../2021-09-01-github_dependabot_alert.md | 2 +- ...1-github_pull_request_from_unknown_user.md | 4 +- ...21-09-02-circle_ci_disable_security_job.md | 2 +- ...2021-09-08-rundll32_control_rundll_hunt.md | 2 +- ...control_rundll_world_writable_directory.md | 2 +- ...21-09-13-xsl_script_execution_with_wmic.md | 2 +- ...me_process_accessing_chrome_default_dir.md | 2 +- ...efox_process_access_firefox_profile_dir.md | 2 +- ...edential_dump_from_registry_via_reg_exe.md | 2 +- .../_posts/2021-09-16-bits_job_persistence.md | 2 +- .../2021-09-16-bitsadmin_download_file.md | 2 +- ...of_shadow_copy_with_wmic_and_powershell.md | 4 +- ...mping_via_copy_command_from_shadow_copy.md | 2 +- ...tial_dumping_via_symlink_to_shadow_copy.md | 2 +- ...16-detect_html_help_url_in_command_line.md | 2 +- ...ml_help_using_infotech_storage_handlers.md | 2 +- ...09-16-detect_mshta_inline_hta_execution.md | 2 +- ...-09-16-detect_mshta_url_in_command_line.md | 2 +- ...9-16-detect_psexec_with_accepteula_flag.md | 2 +- .../2021-09-16-dump_lsass_via_procdump.md | 2 +- ...09-16-local_account_discovery_with_wmic.md | 2 +- ...2021-09-16-office_product_spawning_wmic.md | 2 +- .../2021-09-16-processes_launching_netsh.md | 2 +- ...32_silent_and_install_param_dll_loading.md | 2 +- .../2021-10-05-rundll32_shimcache_flush.md | 2 +- .../2021-10-05-suspicious_copy_on_system32.md | 2 +- ...iceprincipalnames_discovery_with_setspn.md | 2 +- ...ows_task_scheduler_event_action_started.md | 2 +- .../2021-11-11-wmic_xsl_execution_via_url.md | 2 +- ...12-remote_process_instantiation_via_wmi.md | 2 +- ...21-11-12-runas_execution_in_commandline.md | 2 +- ...s_instantiation_via_dcom_and_powershell.md | 2 +- ...ss_instantiation_via_wmi_and_powershell.md | 2 +- ...ion_via_wmi_and_powershell_script_block.md | 2 +- ..._instantiation_via_winrm_and_powershell.md | 2 +- ...ile_written_in_administrative_smb_share.md | 2 +- ...info_gathering_using_dxdiag_application.md | 2 +- ...ce_created_with_suspicious_service_path.md | 2 +- ...dows_service_created_within_public_path.md | 2 +- ...ell_windows_defender_exclusion_commands.md | 2 +- ...-11-29-detect_rclone_command-line_usage.md | 2 +- ...-12-10-curl_download_and_bash_execution.md | 1 + .../2021-12-13-linux_java_spawning_shell.md | 2 +- ...2021-12-13-windows_java_spawning_shells.md | 2 +- ..._add_files_in_known_crontab_directories.md | 1 + ...-17-linux_at_allow_config_file_creation.md | 1 + ...1-12-17-linux_edit_cron_table_parameter.md | 1 + ..._cronjob_entry_on_existing_cronjob_file.md | 1 + ...ssible_cronjob_modification_with_editor.md | 1 + ...rvice_file_created_in_systemd_directory.md | 1 + .../2021-12-20-linux_service_restarted.md | 1 + ...-12-20-linux_service_started_or_enabled.md | 1 + ...1-12-21-linux_change_file_owner_to_root.md | 1 + ...-12-21-linux_setuid_using_chmod_utility.md | 1 + ...file_created_in_kernel_driver_directory.md | 1 + ...sert_kernel_module_using_insmod_utility.md | 1 + ...ll_kernel_module_using_modprobe_utility.md | 1 + ...ux_common_process_for_elevation_control.md | 1 + ...ess_or_modification_of_sshd_config_file.md | 1 + ...11-linux_possible_ssh_key_file_creation.md | 1 + ..._connect_to_internet_with_hidden_window.md | 2 +- ...-cmd_carry_out_string_command_parameter.md | 3 +- ...us_powershell_process_-_encoded_command.md | 3 +- ...dows_dotnet_binary_in_non_standard_path.md | 2 +- .../2022-01-20-ping_sleep_batch_command.md | 2 +- .../2022-01-24-windows_nirsoft_utilities.md | 2 +- ...01-28-linux_pkexec_privilege_escalation.md | 1 + ...2022-02-03-o365_added_service_principal.md | 2 +- ...22-02-03-o365_bypass_mfa_via_trusted_ip.md | 2 +- docs/_posts/2022-02-03-o365_disable_mfa.md | 2 +- ...dows_remote_assistance_spawning_process.md | 2 +- ...022-02-08-rundll_loading_dll_by_ordinal.md | 2 +- ...oasting_spn_request_with_rc4_encryption.md | 2 +- ...2-15-windows_diskshadow_proxy_execution.md | 2 +- ...excessive_authentication_failures_alert.md | 2 +- ...2-02-22-windows_wmi_process_call_create.md | 2 +- ...ndows_excessive_disabled_services_event.md | 2 +- ...re_with_powershell_script_block_logging.md | 2 +- ...tz_with_powershell_script_block_logging.md | 2 +- ...oresttrust_with_powershell_script_block.md | 2 +- ...022-02-25-powershell_domain_enumeration.md | 2 +- ...-powershell_enable_smb1protocol_feature.md | 2 +- ...ss_process_injection_via_getprocaddress.md | 2 +- ...25-powershell_processing_stream_of_data.md | 2 +- .../2022-02-25-recon_using_wmi_class.md | 2 +- ...rincipalnames_discovery_with_powershell.md | 2 +- docs/_posts/2022-03-04-macos_lolbin.md | 2 +- ..._regsvcs_with_no_command_line_arguments.md | 2 +- ...ice_ticket_request_using_rc4_encryption.md | 2 +- ..._no_command_line_arguments_with_network.md | 2 +- ...ious_gpupdate_no_command_line_arguments.md | 2 +- ...ious_rundll32_no_command_line_arguments.md | 2 +- ...wordpolicy_with_powershell_script_block.md | 2 +- ...domainuser_with_powershell_script_block.md | 2 +- ...oup_discovery_with_script_block_logging.md | 2 +- ...getadgroup_with_powershell_script_block.md | 2 +- ...rrent_user_with_powershell_script_block.md | 2 +- ...tlocaluser_with_powershell_script_block.md | 2 +- ...sion_on_remote_endpoint_with_powershell.md | 2 +- ...ntication_flag_disabled_with_powershell.md | 2 +- ...022-03-22-powershell_execute_com_object.md | 2 +- ...owershell_using_memory_as_backing_store.md | 2 +- ...3-22-recon_avproduct_through_pwh_or_wmi.md | 2 +- ...on_via_dcom_and_powershell_script_block.md | 2 +- ...n_via_winrm_and_powershell_script_block.md | 2 +- ...y_with_env_vars_powershell_script_block.md | 2 +- ...uter_unconstrained_delegation_discovery.md | 2 +- ...view_unconstrained_delegation_discovery.md | 2 +- ...erview_constrained_delegation_discovery.md | 2 +- ...connection_with_powershell_script_block.md | 2 +- ...ithub_actions_disable_security_workflow.md | 2 +- ...4-windows_driver_load_non-standard_path.md | 2 +- ...4-04-windows_event_for_service_disabled.md | 2 +- ..._spring4shell_http_request_class_module.md | 2 +- .../2022-04-07-any_powershell_downloadfile.md | 3 +- ...022-04-07-any_powershell_downloadstring.md | 2 +- ...022-04-18-nltest_domain_trust_discovery.md | 2 +- ...nux_adding_crontab_using_list_parameter.md | 1 + ...ndows_linked_policies_in_adsi_discovery.md | 2 +- ...s_root_domain_linked_policies_discovery.md | 2 +- ..._script_contains_base64_encoded_content.md | 2 +- ...oup_discovery_with_script_block_logging.md | 2 +- ...6-windows_hidden_schedule_task_settings.md | 2 +- ...ter_account_created_by_computer_account.md | 2 +- ...uter_account_requesting_kerberos_ticket.md | 2 +- ...windows_kerberos_local_successful_logon.md | 2 +- ...04-28-windows_computer_account_with_spn.md | 2 +- ...05-02-delete_shadowcopy_with_powershell.md | 2 +- ...-05-02-exchange_powershell_module_usage.md | 2 +- ...omaintrust_with_powershell_script_block.md | 2 +- ...wordpolicy_with_powershell_script_block.md | 2 +- ...mainpolicy_with_powershell_script_block.md | 2 +- ...adcomputer_with_powershell_script_block.md | 2 +- ...incomputer_with_powershell_script_block.md | 2 +- ...controller_with_powershell_script_block.md | 2 +- ...omaingroup_with_powershell_script_block.md | 2 +- ...s_computer_with_powershell_script_block.md | 2 +- ...t_ds_group_with_powershell_script_block.md | 2 +- ...ct_ds_user_with_powershell_script_block.md | 2 +- ...er_account_with_powershell_script_block.md | 2 +- .../2022-05-02-mailsniper_invoke_functions.md | 2 +- ...-05-02-powershell_creating_thread_mutex.md | 2 +- ...ading_dotnet_into_memory_via_reflection.md | 2 +- ...shell_remove_windows_defender_directory.md | 2 +- ...-02-windows_krbrelayup_service_creation.md | 2 +- ...2-wmi_recon_running_process_or_services.md | 2 +- ...uthentication_discovery_with_get-aduser.md | 2 +- ...authentication_discovery_with_powerview.md | 2 +- ...22-05-11-potential_password_in_username.md | 2 +- ...22-05-26-linux_at_application_execution.md | 1 + docs/_posts/2022-05-26-macos_plutil.md | 2 +- ...work_info_through_ip_check_web_services.md | 1 + ...werview_kerberos_service_ticket_request.md | 2 +- ...2-06-22-windows_powerview_spn_discovery.md | 2 +- ..._impair_defense_add_xml_applocker_rules.md | 2 +- ...mote_system_discovery_with_adsisearcher.md | 2 +- ...dows_powershell_import_applocker_policy.md | 2 +- ...zure_active_directory_high_risk_sign-in.md | 169 +++ ...umber_of_failed_authentications_from_ip.md | 173 +++ ...defense_evasion_stop_logging_cloudtrail.md | 168 +++ ...e_users_failing_to_authenticate_from_ip.md | 170 +++ ...successful_single-factor_authentication.md | 162 +++ ...3-aws_defense_evasion_delete_cloudtrail.md | 168 +++ ...ad_successful_powershell_authentication.md | 174 +++ ...hentication_failed_during_mfa_challenge.md | 179 +++ ...-powershell_disable_security_monitoring.md | 2 +- ...nse_evasion_delete_cloudwatch_log_group.md | 168 +++ ...7-aws_defense_evasion_update_cloudtrail.md | 168 +++ ..._and_privilege_escalation_risk_behavior.md | 167 +++ ...7-20-registry_keys_used_for_persistence.md | 177 +++ ...-aws_defense_evasion_putbucketlifecycle.md | 173 +++ ...efense_evasion_impair_security_services.md | 171 +++ ...2022-07-27-linux_decode_base64_to_shell.md | 179 +++ ...2-07-27-linux_kernel_module_enumeration.md | 174 +++ ...ated_files_or_information_base64_decode.md | 172 +++ ...-linux_ssh_authorized_keys_modification.md | 170 +++ ...inux_ssh_remote_services_script_execute.md | 169 +++ ...07-27-windows_system_logoff_commandline.md | 170 +++ ...07-27-windows_system_reboot_commandline.md | 170 +++ ...-27-windows_system_shutdown_commandline.md | 170 +++ .../2022-07-28-linux_clipboard_data_copy.md | 170 +++ ...ws_command_shell_dcrat_forkbomb_payload.md | 177 +++ ...ndows_system_time_discovery_w32tm_delay.md | 171 +++ docs/_stories/aws_defense_evasion.md | 46 + ...azure_active_directory_account_takeover.md | 52 + docs/_stories/darkcrystal_rat.md | 62 + docs/_stories/linux_living_off_the_land.md | 68 + docs/_stories/linux_persistence_techniques.md | 4 +- docs/_stories/linux_privilege_escalation.md | 4 +- docs/_stories/linux_rootkit.md | 48 + docs/mitre-map/coverage.json | 120 +- 315 files changed, 6482 insertions(+), 395 deletions(-) create mode 100644 docs/_posts/2022-07-11-azure_active_directory_high_risk_sign-in.md create mode 100644 docs/_posts/2022-07-11-azure_ad_unusual_number_of_failed_authentications_from_ip.md create mode 100644 docs/_posts/2022-07-12-aws_defense_evasion_stop_logging_cloudtrail.md create mode 100644 docs/_posts/2022-07-12-azure_ad_multiple_users_failing_to_authenticate_from_ip.md create mode 100644 docs/_posts/2022-07-12-azure_ad_successful_single-factor_authentication.md create mode 100644 docs/_posts/2022-07-13-aws_defense_evasion_delete_cloudtrail.md create mode 100644 docs/_posts/2022-07-13-azure_ad_successful_powershell_authentication.md create mode 100644 docs/_posts/2022-07-14-azure_ad_authentication_failed_during_mfa_challenge.md create mode 100644 docs/_posts/2022-07-17-aws_defense_evasion_delete_cloudwatch_log_group.md create mode 100644 docs/_posts/2022-07-17-aws_defense_evasion_update_cloudtrail.md create mode 100644 docs/_posts/2022-07-20-linux_persistence_and_privilege_escalation_risk_behavior.md create mode 100644 docs/_posts/2022-07-20-registry_keys_used_for_persistence.md create mode 100644 docs/_posts/2022-07-25-aws_defense_evasion_putbucketlifecycle.md create mode 100644 docs/_posts/2022-07-26-aws_defense_evasion_impair_security_services.md create mode 100644 docs/_posts/2022-07-27-linux_decode_base64_to_shell.md create mode 100644 docs/_posts/2022-07-27-linux_kernel_module_enumeration.md create mode 100644 docs/_posts/2022-07-27-linux_obfuscated_files_or_information_base64_decode.md create mode 100644 docs/_posts/2022-07-27-linux_ssh_authorized_keys_modification.md create mode 100644 docs/_posts/2022-07-27-linux_ssh_remote_services_script_execute.md create mode 100644 docs/_posts/2022-07-27-windows_system_logoff_commandline.md create mode 100644 docs/_posts/2022-07-27-windows_system_reboot_commandline.md create mode 100644 docs/_posts/2022-07-27-windows_system_shutdown_commandline.md create mode 100644 docs/_posts/2022-07-28-linux_clipboard_data_copy.md create mode 100644 docs/_posts/2022-07-28-windows_command_shell_dcrat_forkbomb_payload.md create mode 100644 docs/_posts/2022-07-28-windows_system_time_discovery_w32tm_delay.md create mode 100644 docs/_stories/aws_defense_evasion.md create mode 100644 docs/_stories/azure_active_directory_account_takeover.md create mode 100644 docs/_stories/darkcrystal_rat.md create mode 100644 docs/_stories/linux_living_off_the_land.md create mode 100644 docs/_stories/linux_rootkit.md diff --git a/dist/escu/app.manifest b/dist/escu/app.manifest index f8df6d0f59..4e8eef3903 100644 --- a/dist/escu/app.manifest +++ b/dist/escu/app.manifest @@ -5,7 +5,7 @@ "id": { "group": null, "name": "DA-ESS-ContentUpdate", - "version": "3.45.0" + "version": "3.46.0" }, "author": [ { diff --git a/dist/escu/default/analyticstories.conf b/dist/escu/default/analyticstories.conf index 803b84d6dc..06e2e3ac27 100644 --- a/dist/escu/default/analyticstories.conf +++ b/dist/escu/default/analyticstories.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2022-07-19T21:28:12 UTC +# On Date: 2022-07-28T22:42:05 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# @@ -207,6 +207,66 @@ annotations = {"cis20": ["CIS 16"], "kill_chain_phases": ["Actions on Objectives known_false_positives = Using multiple AWS accounts and roles is perfectly valid behavior. It's suspicious when an account requests privileges of an account it hasn't before. You should validate with the account owner that this is a legitimate request. providing_technologies = null +[savedsearch://ESCU - AWS Defense Evasion Delete Cloudtrail - Rule] +type = detection +asset_type = AWS Account +confidence = medium +explanation = This analytic identifies AWS `DeleteTrail` events within CloudTrail logs. Adversaries often try to impair their target's defenses by stopping their malicious activity from being logged, so that they may operate with stealth and avoid detection. When the adversary has the right type of permissions in the compromised AWS environment, they may delete the the entire cloudtrail that is logging activities in the environment. +how_to_implement = You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562.008", "T1562"], "nist": ["DE.CM"]} +known_false_positives = While this search has no known false positives, it is possible that an AWS admin has stopped cloudTrail logging. Please investigate this activity. +providing_technologies = ["Amazon Web Services - Cloudtrail"] + +[savedsearch://ESCU - AWS Defense Evasion Delete CloudWatch Log Group - Rule] +type = detection +asset_type = AWS Account +confidence = medium +explanation = This analytic identifies AWS `DeleteLogGroup` events in CloudTrail logs. Attackers may evade the logging capability by deleting the log group in CloudWatch. This will stop sending the logs and metrics to CloudWatch. When the adversary has the right type of permissions within the compromised AWS environment, they may delete the CloudWatch log group that is logging activities in the environment. +how_to_implement = You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562", "T1562.008"], "nist": ["DE.CM"]} +known_false_positives = While this search has no known false positives, it is possible that an AWS admin has deleted CloudWatch logging. Please investigate this activity. +providing_technologies = ["Amazon Web Services - Cloudtrail"] + +[savedsearch://ESCU - AWS Defense Evasion Impair Security Services - Rule] +type = detection +asset_type = AWS Account +confidence = medium +explanation = This analytic looks for several delete specific API calls made to AWS Security Services like CloudWatch, GuardDuty and Web Application Firewalls. These API calls are often leveraged by adversaries to weaken existing security defenses by deleting logging configurations in the CloudWatch alarm, delete a set of detectors from your Guardduty environment or simply delete a bunch of CloudWatch alarms to remain stealthy and avoid detection. +how_to_implement = You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562.008", "T1562"], "nist": ["DE.CM"]} +known_false_positives = While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names. +providing_technologies = ["Amazon Web Services - Cloudtrail"] + +[savedsearch://ESCU - AWS Defense Evasion PutBucketLifecycle - Rule] +type = detection +asset_type = AWS Account +confidence = medium +explanation = This analytic identifies `PutBucketLifecycle` events in CloudTrail logs where a user has created a new lifecycle rule for an S3 bucket with a short expiration period. Attackers may use this API call to impair the CloudTrail logging by removing logs from the S3 bucket by changing the object expiration day to 1 day, in which case the CloudTrail logs will be deleted. +how_to_implement = You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. We recommend our users to set the expiration days value according to your company's log retention policies. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562.008", "T1562"], "nist": ["DE.CM"]} +known_false_positives = While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names. +providing_technologies = ["Amazon Web Services - Cloudtrail"] + +[savedsearch://ESCU - AWS Defense Evasion Stop Logging Cloudtrail - Rule] +type = detection +asset_type = AWS Account +confidence = medium +explanation = This analytic identifies `StopLogging` events in CloudTrail logs. Adversaries often try to impair their target's defenses by stopping their macliious activity from being logged, so that they may operate with stealth and avoid detection. When the adversary has the right type of permissions in the compromised AWS environment, they may easily stop logging. +how_to_implement = You must install Splunk AWS Add on and enable Cloudtrail logs in your AWS Environment. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562.008", "T1562"], "nist": ["DE.CM"]} +known_false_positives = While this search has no known false positives, it is possible that an AWS admin has stopped cloudtrail logging. Please investigate this activity. +providing_technologies = ["Amazon Web Services - Cloudtrail"] + +[savedsearch://ESCU - AWS Defense Evasion Update Cloudtrail - Rule] +type = detection +asset_type = AWS Account +confidence = medium +explanation = This analytic identifies `UpdateTrail` events in CloudTrail logs. Attackers may evade the logging capability by updating the settings and impairing them with wrong parameters. For example, Attackers may change the multi-regional log into a single region logs, which evades the logging for other regions. When the adversary has the right type of permissions in the compromised AWS environment, they may update the CloudTrail settings that is logging activities in your environment. +how_to_implement = You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562", "T1562.008"], "nist": ["DE.CM"]} +known_false_positives = While this search has no known false positives, it is possible that an AWS admin has updated cloudtrail logging. Please investigate this activity. +providing_technologies = ["Amazon Web Services - Cloudtrail"] + [savedsearch://ESCU - AWS Detect Users creating keys with encrypt policy without MFA - Rule] type = detection asset_type = AWS Account @@ -407,6 +467,69 @@ annotations = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives known_false_positives = While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. providing_technologies = ["Amazon Web Services - Cloudtrail"] +[savedsearch://ESCU - Azure Active Directory High Risk Sign-in - Rule] +type = detection +asset_type = Azure Active Directory +confidence = medium +explanation = The following analytic triggers on a high risk sign-in against Azure Active Directory identified by Azure Identity Protection. Identity Protection monitors sign-in events using heuristics and machine learning to identify potentially malicious events and categorizes them in three categories high, medium and low. +how_to_implement = You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase (https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the RiskyUsers and UserRiskEvents log category. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1110", "T1110.003"], "nist": ["DE.CM"]} +known_false_positives = Details for the risk calculation algorithm used by Identity Protection are unknown and may be prone to false positives. +providing_technologies = null + +[savedsearch://ESCU - Azure AD Authentication Failed During MFA Challenge - Rule] +type = detection +asset_type = Azure Active Directory +confidence = medium +explanation = The following analytic identifies an authentication attempt event against an Azure AD tenant that fails during the Multi Factor Authentication challenge. This behavior may represent an adversary trying to authenticate with compromised credentials. In some cases, adversaries may continuously repeat login attempts in order to bombard users with MFA push notifications, SMS messages, and phone calls, potentially resulting in the user finally accepting the authentication request. +how_to_implement = You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the RiskyUsers and UserRiskEvents log category. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1078", "T1078.004", "T1621"], "nist": ["DE.CM"]} +known_false_positives = Legitimate users may miss to reply the MFA challenge within the time window or deny it by mistake. +providing_technologies = null + +[savedsearch://ESCU - Azure AD Multiple Users Failing To Authenticate From Ip - Rule] +type = detection +asset_type = Azure Active Directory +confidence = medium +explanation = The following analytic identifies one source Ip failing to authenticate with 30 unique valid users within 5 minutes. This behavior could represent an adversary performing a Password Spraying attack against an Azure Active Directory tenant to obtain initial access or elevate privileges. Error Code 50126 represents an invalid password. This logic can be used for real time security monitoring as well as threat hunting exercises.\ +Azure AD tenants can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold if needed. +how_to_implement = You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the SignInLogs log category. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1110", "T1110.003"], "nist": ["DE.CM"]} +known_false_positives = A source Ip failing to authenticate with multiple users is not a common for legitimate behavior. +providing_technologies = null + +[savedsearch://ESCU - Azure AD Successful PowerShell Authentication - Rule] +type = detection +asset_type = Azure Active Directory +confidence = medium +explanation = The following analytic identifies a successful authentication event against an Azure AD tenant using PowerShell commandlets. This behavior is not common for regular, non administrative users. After compromising an account in Azure AD, attackers and red teams alike will perform enumeration and discovery techniques. One method of executing these techniques is leveraging the native PowerShell modules. +how_to_implement = You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the SignInLogs log category. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1078", "T1078.004"], "nist": ["DE.CM"]} +known_false_positives = Administrative users will likely use PowerShell commandlets to troubleshoot and maintain the environment. Filter as needed. +providing_technologies = null + +[savedsearch://ESCU - Azure AD Successful Single-Factor Authentication - Rule] +type = detection +asset_type = Azure Active Directory +confidence = medium +explanation = The following analytic identifies a successful authentication event against Azure Active Directory for an account without Multi-Factor Authentication enabled. This could be evidence of a missconfiguration, a policy violation or an account take over attempt that should be investigated +how_to_implement = You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the SignInLogs log category. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1003.002"], "nist": ["DE.CM"]} +known_false_positives = Although not recommended, certain users may be required without multi-factor authentication. Filter as needed +providing_technologies = null + +[savedsearch://ESCU - Azure AD Unusual Number of Failed Authentications From Ip - Rule] +type = detection +asset_type = Azure Active Directory +confidence = medium +explanation = The following analytic identifies one source Ip failing to authenticate with multiple valid users. This behavior could represent an adversary performing a Password Spraying attack against an Azure Active Directory tenant to obtain initial access or elevate privileges. Error Code 50126 represents an invalid password.\ +The detection calculates the standard deviation for source Ip and leverages the 3-sigma statistical rule to identify an unusual number of failed authentication attempts. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ +While looking for anomalies using statistical methods like the standard deviation can have benefits, we also recommend using threshold-based detections to complement coverage. A similar analytic following the threshold model is `Azure AD Multiple Users Failing To Authenticate From Ip`. +how_to_implement = You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the SignInLogs log category. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1110", "T1110.003"], "nist": ["DE.CM"]} +known_false_positives = A source Ip failing to authenticate with multiple users is not a common for legitimate behavior. +providing_technologies = null + [savedsearch://ESCU - Circle CI Disable Security Job - Rule] type = detection asset_type = CircleCI @@ -4254,6 +4377,16 @@ annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exp known_false_positives = Administrator or network operator can execute this command. Please update the filter macros to remove false positives. providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] +[savedsearch://ESCU - Linux Clipboard Data Copy - Rule] +type = detection +asset_type = Endpoint +confidence = medium +explanation = The following analytic identifies the use of Linux Xclip copying data out of the clipboard. Adversaries have utilized this technique to capture passwords, IP addresses, or store payloads. +how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1115"], "nist": ["DE.CM"]} +known_false_positives = False positives may be present on Linux desktop as it may commonly be used by administrators or end users. Filter as needed. +providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] + [savedsearch://ESCU - Linux Common Process For Elevation Control - Rule] type = detection asset_type = Endpoint @@ -4274,6 +4407,16 @@ annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exp known_false_positives = Administrator or network operator can execute this command. Please update the filter macros to remove false positives. providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] +[savedsearch://ESCU - Linux Decode Base64 to Shell - Rule] +type = detection +asset_type = Endpoint +confidence = medium +explanation = The following analytic identifies base64 being decoded and passed to a Linux shell. +how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Delivery", "Exploitation"], "mitre_attack": ["T1027", "T1059.004"], "nist": ["DE.CM"]} +known_false_positives = False positives may be present based on legitimate software being utilized. Filter as needed. +providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] + [savedsearch://ESCU - Linux Deleting Critical Directory Using RM Command - Rule] type = detection asset_type = Endpoint @@ -4454,6 +4597,16 @@ annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1190"]} known_false_positives = Filtering may be required on internal developer build systems or classify assets as web facing and restrict the analytic based on asset type. providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] +[savedsearch://ESCU - Linux Kernel Module Enumeration - Rule] +type = detection +asset_type = Endpoint +confidence = medium +explanation = The following analytic identifies the process kmod being utilized to list kernel modules in use. Typically, this is not seen as malicious, however it may be a precurser to the use of insmod to install a module. +how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1082", "T1014"], "nist": ["DE.CM"]} +known_false_positives = False positives are present based on automated tooling or system administrative usage. Filter as needed. +providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] + [savedsearch://ESCU - Linux Kworker Process In Writable Process Path - Rule] type = detection asset_type = Endpoint @@ -4474,6 +4627,26 @@ annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exp known_false_positives = Administrator or network operator can execute this command. Please update the filter macros to remove false positives. providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] +[savedsearch://ESCU - Linux Obfuscated Files or Information Base64 Decode - Rule] +type = detection +asset_type = Endpoint +confidence = medium +explanation = The following analytic identifies the use of base64 decode on Linux being utilized to deobfuscate a file. Identify the source of the file and determine if legitimate. Review parallel processes for further behavior before and after. +how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Delivery", "Exploitation"], "mitre_attack": ["T1027"], "nist": ["DE.CM"]} +known_false_positives = False positives may be present and will require some tuning based on processes. Filter as needed. +providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] + +[savedsearch://ESCU - Linux Persistence and Privilege Escalation Risk Behavior - Rule] +type = detection +asset_type = Endpoint +confidence = medium +explanation = The following correlation is specific to Linux persistence and privilege escalation tactics and is tied to two analytic stories and any Linux analytic tied to persistence and privilege escalation. These techniques often overlap with Persistence techniques, as OS features that let an adversary persist can execute in an elevated context. +how_to_implement = Ensure Linux anomaly and TTP analytics are enabled. TTP may be set to Notables for point detections, anomaly should not be notables but risk generators. The correlation relies on more than x amount of distict detection names generated before generating a notable. Modify the value as needed. Default value is set to 4. This value may need to be increased based on activity in your environment. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548"], "nist": ["DE.CM"]} +known_false_positives = False positives will be present based on many factors. Tune the correlation as needed to reduce too many triggers. +providing_technologies = null + [savedsearch://ESCU - Linux pkexec Privilege Escalation - Rule] type = detection asset_type = Endpoint @@ -4634,6 +4807,26 @@ annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exp known_false_positives = Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] +[savedsearch://ESCU - Linux SSH Authorized Keys Modification - Rule] +type = detection +asset_type = Endpoint +confidence = medium +explanation = The following analytic identifies based on process execution the modification of SSH Authorized Keys. Adversaries perform this behavior to persist on endpoints. During triage, review parallel processes and capture any additional file modifications for review. +how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Installation"], "mitre_attack": ["T1098.004"], "nist": ["DE.CM"]} +known_false_positives = Filtering will be required as system administrators will add and remove. One way to filter query is to add "echo". +providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] + +[savedsearch://ESCU - Linux SSH Remote Services Script Execute - Rule] +type = detection +asset_type = Endpoint +confidence = medium +explanation = The following analytic identifies SSH being utilized to move laterally and execute a script or file on the remote host. +how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1021.004"], "nist": ["DE.CM"]} +known_false_positives = This is not a common command to be executed. Filter as needed. +providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] + [savedsearch://ESCU - Linux Stop Services - Rule] type = detection asset_type = Endpoint @@ -7136,6 +7329,16 @@ annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exp known_false_positives = Not known at this moment. providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] +[savedsearch://ESCU - Windows Command Shell DCRat ForkBomb Payload - Rule] +type = detection +asset_type = Endpoint +confidence = medium +explanation = The following analytic identifies DCRat "forkbomb" payload feature. This technique was seen in dark crystal RAT backdoor capabilities where it will execute several cmd child process executing "notepad.exe & pause". This analytic detects the multiple cmd.exe and child process notepad.exe execution using batch script in the targeted host within 30s timeframe. this TTP can be a good pivot to check DCRat infection. +how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of wermgr.exe may be used. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1059.003", "T1059"], "nist": ["DE.CM"]} +known_false_positives = unknown +providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] + [savedsearch://ESCU - Windows Computer Account Created by Computer Account - Rule] type = detection asset_type = Endpoint @@ -8219,6 +8422,46 @@ annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Del known_false_positives = False positives will be present. Filter as needed. providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] +[savedsearch://ESCU - Windows System LogOff Commandline - Rule] +type = detection +asset_type = Endpoint +confidence = medium +explanation = The following analytic identifies Windows commandlined to logoff a windows host machine. This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact, interrupt access, aid destruction of the system like wiping disk or inhibit system recovery. This TTP is a good pivot to check why application trigger this commandline which is not so common way to logoff a machine. +how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1529"], "nist": ["DE.CM"]} +known_false_positives = Administrator may execute this commandline to trigger shutdown, logoff or restart the host machine. +providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] + +[savedsearch://ESCU - Windows System Reboot CommandLine - Rule] +type = detection +asset_type = Endpoint +confidence = medium +explanation = The following analytic identifies Windows commandlined to reboot a windows host machine. This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact, interrupt access, aid destruction of the system like wiping disk or inhibit system recovery. This TTP is a good pivot to check why application trigger this commandline which is not so common way to reboot a machine. Compare to shutdown and logoff shutdown.exe feature, reboot seen in some automation script like ansible to reboot the machine. +how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1529"], "nist": ["DE.CM"]} +known_false_positives = Administrator may execute this commandline to trigger shutdown or restart the host machine. +providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] + +[savedsearch://ESCU - Windows System Shutdown CommandLine - Rule] +type = detection +asset_type = Endpoint +confidence = medium +explanation = The following analytic identifies Windows commandlined to shutdown a windows host machine. This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact, interrupt access, aid destruction of the system like wiping disk or inhibit system recovery. This TTP is a good pivot to check why application trigger this commandline which is not so common way to shutdown a machine. +how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1529"], "nist": ["DE.CM"]} +known_false_positives = Administrator may execute this commandline to trigger shutdown or restart the host machine. +providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] + +[savedsearch://ESCU - Windows System Time Discovery W32tm Delay - Rule] +type = detection +asset_type = Endpoint +confidence = medium +explanation = The following analytic identifies DCRat delay time tactics using w32tm. This technique was seen in DCRAT malware where it uses stripchart function of w32tm.exe application to delay the execution of its payload like c2 communication , beaconing and execution. This anomaly detection may help the analyst to check other possible event like the process who execute this command that may lead to DCRat attack. +how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of wermgr.exe may be used. +annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1124"], "nist": ["DE.CM"]} +known_false_positives = unknown +providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] + [savedsearch://ESCU - Windows Terminating Lsass Process - Rule] type = detection asset_type = Endpoint @@ -9795,6 +10038,17 @@ narrative = Amazon Web Services (AWS) admins manage access to AWS resources and Herein lies the rub. In between the time between when the temporary credentials are issued and when they expire is a period of opportunity, where a user could leverage the temporary credentials to wreak havoc-spin up or remove instances, create new users, elevate privileges, and other malicious activities-throughout the environment.\ This Analytic Story includes searches that will help you monitor your AWS CloudTrail logs for evidence of suspicious cross-account activity. For example, while accessing multiple AWS accounts and roles may be perfectly valid behavior, it may be suspicious when an account requests privileges of an account it has not accessed in the past. After identifying suspicious activities, you can use the provided investigative searches to help you probe more deeply. +[analytic_story://AWS Defense Evasion] +category = Cloud Security +last_updated = 2022-07-15 +version = 1 +references = ["https://attack.mitre.org/tactics/TA0005/"] +maintainers = [{"company": "Splunk", "email": "-", "name": "Gowthamaraj Rajendran"}] +spec_version = 3 +searches = ["ESCU - AWS Defense Evasion Delete Cloudtrail - Rule", "ESCU - AWS Defense Evasion Delete CloudWatch Log Group - Rule", "ESCU - AWS Defense Evasion Impair Security Services - Rule", "ESCU - AWS Defense Evasion PutBucketLifecycle - Rule", "ESCU - AWS Defense Evasion Stop Logging Cloudtrail - Rule", "ESCU - AWS Defense Evasion Update Cloudtrail - Rule"] +description = Identify activity and techniques associated with the Evasion of Defenses within AWS, such as Disabling CloudTrail, Deleting CloudTrail and many others. +narrative = Adversaries employ a variety of techniques in order to avoid detection and operate without barriers. This often involves modifying the configuration of security monitoring tools to get around them or explicitly disabling them to prevent them from running. This Analytic Story includes analytics that identify activity consistent with adversaries attempting to disable various security mechanisms on AWS. Such activity may involve deleting the CloudTrail logs , as this is where all the AWS logs get stored or explicitly changing the retention policy of S3 buckets. Other times, adversaries attempt deletion of a specified AWS CloudWatch log group. + [analytic_story://AWS IAM Privilege Escalation] category = Cloud Security last_updated = 2021-03-08 @@ -9854,6 +10108,17 @@ searches = ["ESCU - Allow Inbound Traffic By Firewall Rule Registry - Rule", "ES description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the Azorult malware including firewall modification, icacl execution, spawning more process, botnet c2 communication, defense evasion and etc. The AZORULT malware was first discovered in 2016 to be an information stealer that steals browsing history, cookies, ID/passwords, cryptocurrency information and more. It can also be a downloader of other malware. A variant of this malware was able to create a new, hidden administrator account on the machine to set a registry key to establish a Remote Desktop Protocol (RDP) connection. Exploit kits such as Fallout Exploit Kit (EK) and phishing mails with social engineering technique are one of the major infection vectors of the AZORult malware. The current malspam and phishing emails use fake product order requests, invoice documents and payment information requests. This Trojan-Spyware connects to command and control (C&C) servers of attacker to send and receive information. narrative = Adversaries may use this technique to maximize the impact on the target organization in operations where network wide availability interruption is the goal. +[analytic_story://Azure Active Directory Account Takeover] +category = Adversary Tactics +last_updated = 2022-07-14 +version = 2 +references = ["https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-whatis", "https://azure.microsoft.com/en-us/services/active-directory/#overview", "https://attack.mitre.org/techniques/T1586/", "https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-compare-azure-ad-to-ad", "https://www.imperva.com/learn/application-security/account-takeover-ato/", "https://www.varonis.com/blog/azure-active-directory", "https://www.barracuda.com/glossary/account-takeover"] +maintainers = [{"company": "Splunk", "email": "-", "name": "Mauricio Velazco"}] +spec_version = 3 +searches = ["ESCU - Azure Active Directory High Risk Sign-in - Rule", "ESCU - Azure AD Authentication Failed During MFA Challenge - Rule", "ESCU - Azure AD Multiple Users Failing To Authenticate From Ip - Rule", "ESCU - Azure AD Successful PowerShell Authentication - Rule", "ESCU - Azure AD Successful Single-Factor Authentication - Rule", "ESCU - Azure AD Unusual Number of Failed Authentications From Ip - Rule"] +description = Monitor for activities and techniques associated with Account Takover attacks against Azure Active Directory tenants. +narrative = Azure Active Directory (Azure AD) is Microsofts enterprise cloud-based identity and access management (IAM) service. Azure AD is the backbone of most of Azure services like Office 365. It can sync with on-premise Active Directory environments and provide authentication to other cloud-based systems via the OAuth protocol. According to Microsoft, Azure AD manages more than 1.2 billion identities and processes over 8 billion authentications per day.\ Account Takeover (ATO) is an attack whereby cybercriminals gain unauthorized access to online accounts by using different techniques like brute force, social engineering, phishing & spear phishing, credential stuffing, etc. By posing as the real user, cyber-criminals can change account details, send out phishing emails, steal financial information or sensitive data, or use any stolen information to access further accounts within the organization.\ This analytic storic groups detections that can help security operations teams identify the potential compromise of Azure Active Directory accounts. + [analytic_story://Baron Samedit CVE-2021-3156] category = Adversary Tactics last_updated = 2021-01-27 @@ -9983,17 +10248,6 @@ description = Detect and investigate tactics, techniques, and procedures leverag narrative = Threat actors typically architect and implement an infrastructure to use in various ways during the course of their attack campaigns. In some cases, they leverage this infrastructure for scanning and performing reconnaissance activities. In others, they may use this infrastructure to launch actual attacks. One of the most important functions of this infrastructure is to establish servers that will communicate with implants on compromised endpoints. These servers establish a command and control channel that is used to proxy data between the compromised endpoint and the attacker. These channels relay commands from the attacker to the compromised endpoint and the output of those commands back to the attacker.\ Because this communication is so critical for an adversary, they often use techniques designed to hide the true nature of the communications. There are many different techniques used to establish and communicate over these channels. This Analytic Story provides searches that look for a variety of the techniques used for these channels, as well as indications that these channels are active, by examining logs associated with border control devices and network-access control lists. -[analytic_story://Container Implantation Monitoring and Investigation] -category = Cloud Security -last_updated = 2020-02-20 -version = 1 -references = ["https://github.com/splunk/cloud-datamodel-security-research"] -maintainers = [{"company": "Rico Valdez, Splunk", "email": "-", "name": "Rod Soto"}] -spec_version = 3 -searches = [] -description = Use the searches in this story to monitor your Kubernetes registry repositories for upload, and deployment of potentially vulnerable, backdoor, or implanted containers. These searches provide information on source users, destination path, container names and repository names. The searches provide context to address Mitre T1525 which refers to container implantation upload to a company's repository either in Amazon Elastic Container Registry, Google Container Registry and Azure Container Registry. -narrative = Container Registrys provide a way for organizations to keep customized images of their development and infrastructure environment in private. However if these repositories are misconfigured or priviledge users credentials are compromise, attackers can potentially upload implanted containers which can be deployed across the organization. These searches allow operator to monitor who, when and what was uploaded to container registry. - [analytic_story://Credential Dumping] category = Adversary Tactics last_updated = 2020-02-04 @@ -10018,6 +10272,17 @@ searches = ["ESCU - Linux Iptables Firewall Modification - Rule", "ESCU - Linux description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the cyclopsblink malware including firewall modification, spawning more process, botnet c2 communication, defense evasion and etc. Cyclops Blink is a Linux ELF executable compiled for 32-bit x86 and PowerPC architecture that has targeted several network devices. The complete list of targeted devices is unknown at this time, but WatchGuard FireBox has specifically been listed as a target. The modular malware consists of core components and modules that are deployed as child processes using the Linux API fork. At this point, four modules have been identified that download and upload files, gather system information and contain updating mechanisms for the malware itself. Additional modules can be downloaded and executed from the command and control (C2) server. narrative = Adversaries may use this technique to maximize the impact on the target organization in operations where network wide availability interruption is the goal. +[analytic_story://DarkCrystal RAT] +category = Malware +last_updated = 2022-07-26 +version = 1 +references = ["https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor", "https://malpedia.caad.fkie.fraunhofer.de/details/win.dcrat"] +maintainers = [{"company": "Splunk", "email": "-", "name": "Teoderick Contreras"}] +spec_version = 3 +searches = ["ESCU - Any Powershell DownloadFile - Rule", "ESCU - CMD Carry Out String Command Parameter - Rule", "ESCU - Executables Or Script Creation In Suspicious Path - Rule", "ESCU - Malicious PowerShell Process - Encoded Command - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Office Document Executing Macro Code - Rule", "ESCU - Office Product Spawn CMD Process - Rule", "ESCU - Suspicious Process File Path - Rule", "ESCU - Windows Command Shell DCRat ForkBomb Payload - Rule", "ESCU - Windows Gather Victim Network Info Through Ip Check Web Services - Rule", "ESCU - Windows High File Deletion Frequency - Rule", "ESCU - Windows System LogOff Commandline - Rule", "ESCU - Windows System Reboot CommandLine - Rule", "ESCU - Windows System Shutdown CommandLine - Rule", "ESCU - Windows System Time Discovery W32tm Delay - Rule", "ESCU - Winword Spawning Cmd - Rule", "ESCU - Winword Spawning PowerShell - Rule"] +description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the DcRat malware including ddos, spawning more process, botnet c2 communication, defense evasion and etc. The DcRat malware is known commercial backdoor that was first released in 2018. This tool was sold in underground forum and known to be one of the cheapest commercial RATs. DcRat is modular and bespoke plugin framework make it a very flexible option, helpful for a range of nefearious uses. +narrative = Adversaries may use this technique to maximize the impact on the target organization in operations where network wide availability interruption is the goal. + [analytic_story://Data Destruction] category = Malware last_updated = 2022-02-14 @@ -10100,6 +10365,17 @@ description = Detect DNS and web requests to fake websites generated by the Evil narrative = As most people know, these emails use fraudulent domains, [email scraping](https://www.cyberscoop.com/emotet-trojan-phishing-scraping-templates-cofense-geodo/), familiar contact names inserted as senders, and other tactics to lure targets into clicking a malicious link, opening an attachment with a [nefarious payload](https://www.cyberscoop.com/emotet-trojan-phishing-scraping-templates-cofense-geodo/), or entering sensitive personal information that perpetrators may intercept. This attack technique requires a relatively low level of skill and allows adversaries to easily cast a wide net. Because phishing is a technique that relies on human psychology, you will never be able to eliminate this vulnerability 100%. But you can use automated detection to significantly reduce the risks.\ This Analytic Story focuses on detecting signs of MiTM attacks enabled by [EvilGinx2](https://github.com/kgretzky/evilginx2), a toolkit that sets up a transparent proxy between the targeted site and the user. In this way, the attacker is able to intercept credentials and two-factor identification tokens. It employs a proxy template to allow a registered domain to impersonate targeted sites, such as Linkedin, Amazon, Okta, Github, Twitter, Instagram, Reddit, Office 365, and others. It can even register SSL certificates and camouflage them via a URL shortener, making them difficult to detect. Searches in this story look for signs of MiTM attacks enabled by EvilGinx2. +[analytic_story://Container Implantation Monitoring and Investigation] +category = Cloud Security +last_updated = 2020-02-20 +version = 1 +references = ["https://github.com/splunk/cloud-datamodel-security-research"] +maintainers = [{"company": "Rico Valdez, Splunk", "email": "-", "name": "Rod Soto"}] +spec_version = 3 +searches = [] +description = Use the searches in this story to monitor your Kubernetes registry repositories for upload, and deployment of potentially vulnerable, backdoor, or implanted containers. These searches provide information on source users, destination path, container names and repository names. The searches provide context to address Mitre T1525 which refers to container implantation upload to a company's repository either in Amazon Elastic Container Registry, Google Container Registry and Azure Container Registry. +narrative = Container Registrys provide a way for organizations to keep customized images of their development and infrastructure environment in private. However if these repositories are misconfigured or priviledge users credentials are compromise, attackers can potentially upload implanted containers which can be deployed across the organization. These searches allow operator to monitor who, when and what was uploaded to container registry. + [analytic_story://Host Redirection] category = Abuse last_updated = 2017-09-14 @@ -10505,6 +10781,17 @@ searches = ["ESCU - AWS EKS Kubernetes cluster sensitive object access - Rule", description = This story addresses detection and response of accounts acccesing Kubernetes cluster sensitive objects such as configmaps or secrets providing information on items such as user user, group. object, namespace and authorization reason. narrative = Kubernetes is the most used container orchestration platform, this orchestration platform contains sensitive objects within its architecture, specifically configmaps and secrets, if accessed by an attacker can lead to further compromise. These searches allow operator to detect suspicious requests against Kubernetes sensitive objects. +[analytic_story://Linux Living Off The Land] +category = Adversary Tactics +last_updated = 2022-07-27 +version = 1 +references = ["https://gtfobins.github.io/"] +maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] +spec_version = 3 +searches = ["ESCU - Curl Download and Bash Execution - Rule", "ESCU - Linux Add Files In Known Crontab Directories - Rule", "ESCU - Linux Adding Crontab Using List Parameter - Rule", "ESCU - Linux At Allow Config File Creation - Rule", "ESCU - Linux At Application Execution - Rule", "ESCU - Linux Change File Owner To Root - Rule", "ESCU - Linux Clipboard Data Copy - Rule", "ESCU - Linux Common Process For Elevation Control - Rule", "ESCU - Linux Decode Base64 to Shell - Rule", "ESCU - Linux Edit Cron Table Parameter - Rule", "ESCU - Linux Obfuscated Files or Information Base64 Decode - Rule", "ESCU - Linux pkexec Privilege Escalation - Rule", "ESCU - Linux Possible Access Or Modification Of sshd Config File - Rule", "ESCU - Linux Possible Append Cronjob Entry on Existing Cronjob File - Rule", "ESCU - Linux Possible Cronjob Modification With Editor - Rule", "ESCU - Linux Possible Ssh Key File Creation - Rule", "ESCU - Linux Service File Created In Systemd Directory - Rule", "ESCU - Linux Service Restarted - Rule", "ESCU - Linux Service Started Or Enabled - Rule", "ESCU - Linux Setuid Using Chmod Utility - Rule", "ESCU - Linux SSH Authorized Keys Modification - Rule", "ESCU - Linux SSH Remote Services Script Execute - Rule", "ESCU - Suspicious Curl Network Connection - Rule"] +description = Linux Living Off The Land consists of binaries that may be used to bypass local security restrictions within misconfigured systems. +narrative = Similar to Windows LOLBAS project, the GTFOBins project focuses solely on Unix binaries that may be abused in multiple categories including Reverse Shell, File Upload, File Download and much more. These binaries are native to the operating system and the functionality is typically native. The behaviors are typically not malicious by default or vulnerable, but these are built in functionality of the applications. When reviewing any notables or hunting through mountains of events of interest, it's important to identify the binary, review command-line arguments, path of file, and capture any network and file modifications. Linux analysis may be a bit cumbersome due to volume and how process behavior is seen in EDR products. Piecing it together will require some effort. + [analytic_story://Linux Persistence Techniques] category = Adversary Tactics last_updated = 2021-12-17 @@ -10512,7 +10799,7 @@ version = 1 references = ["https://attack.mitre.org/techniques/T1053/", "https://kifarunix.com/scheduling-tasks-using-at-command-in-linux/", "https://gtfobins.github.io/gtfobins/at/", "https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-005.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "Teoderick Contreras"}] spec_version = 3 -searches = ["ESCU - Linux Add Files In Known Crontab Directories - Rule", "ESCU - Linux Add User Account - Rule", "ESCU - Linux Adding Crontab Using List Parameter - Rule", "ESCU - Linux At Allow Config File Creation - Rule", "ESCU - Linux At Application Execution - Rule", "ESCU - Linux Change File Owner To Root - Rule", "ESCU - Linux Common Process For Elevation Control - Rule", "ESCU - Linux Doas Conf File Creation - Rule", "ESCU - Linux Doas Tool Execution - Rule", "ESCU - Linux Edit Cron Table Parameter - Rule", "ESCU - Linux File Created In Kernel Driver Directory - Rule", "ESCU - Linux File Creation In Init Boot Directory - Rule", "ESCU - Linux File Creation In Profile Directory - Rule", "ESCU - Linux Insert Kernel Module Using Insmod Utility - Rule", "ESCU - Linux Install Kernel Module Using Modprobe Utility - Rule", "ESCU - Linux NOPASSWD Entry In Sudoers File - Rule", "ESCU - Linux Possible Access Or Modification Of sshd Config File - Rule", "ESCU - Linux Possible Access To Credential Files - Rule", "ESCU - Linux Possible Access To Sudoers File - Rule", "ESCU - Linux Possible Append Command To At Allow Config File - Rule", "ESCU - Linux Possible Append Command To Profile Config File - Rule", "ESCU - Linux Possible Append Cronjob Entry on Existing Cronjob File - Rule", "ESCU - Linux Possible Cronjob Modification With Editor - Rule", "ESCU - Linux Possible Ssh Key File Creation - Rule", "ESCU - Linux Preload Hijack Library Calls - Rule", "ESCU - Linux Service File Created In Systemd Directory - Rule", "ESCU - Linux Service Restarted - Rule", "ESCU - Linux Service Started Or Enabled - Rule", "ESCU - Linux Setuid Using Chmod Utility - Rule", "ESCU - Linux Setuid Using Setcap Utility - Rule", "ESCU - Linux Shred Overwrite Command - Rule", "ESCU - Linux Sudo OR Su Execution - Rule", "ESCU - Linux Sudoers Tmp File Creation - Rule", "ESCU - Linux Visudo Utility Execution - Rule"] +searches = ["ESCU - Linux Add Files In Known Crontab Directories - Rule", "ESCU - Linux Add User Account - Rule", "ESCU - Linux Adding Crontab Using List Parameter - Rule", "ESCU - Linux At Allow Config File Creation - Rule", "ESCU - Linux At Application Execution - Rule", "ESCU - Linux Change File Owner To Root - Rule", "ESCU - Linux Common Process For Elevation Control - Rule", "ESCU - Linux Doas Conf File Creation - Rule", "ESCU - Linux Doas Tool Execution - Rule", "ESCU - Linux Edit Cron Table Parameter - Rule", "ESCU - Linux File Created In Kernel Driver Directory - Rule", "ESCU - Linux File Creation In Init Boot Directory - Rule", "ESCU - Linux File Creation In Profile Directory - Rule", "ESCU - Linux Insert Kernel Module Using Insmod Utility - Rule", "ESCU - Linux Install Kernel Module Using Modprobe Utility - Rule", "ESCU - Linux NOPASSWD Entry In Sudoers File - Rule", "ESCU - Linux Persistence and Privilege Escalation Risk Behavior - Rule", "ESCU - Linux Possible Access Or Modification Of sshd Config File - Rule", "ESCU - Linux Possible Access To Credential Files - Rule", "ESCU - Linux Possible Access To Sudoers File - Rule", "ESCU - Linux Possible Append Command To At Allow Config File - Rule", "ESCU - Linux Possible Append Command To Profile Config File - Rule", "ESCU - Linux Possible Append Cronjob Entry on Existing Cronjob File - Rule", "ESCU - Linux Possible Cronjob Modification With Editor - Rule", "ESCU - Linux Possible Ssh Key File Creation - Rule", "ESCU - Linux Preload Hijack Library Calls - Rule", "ESCU - Linux Service File Created In Systemd Directory - Rule", "ESCU - Linux Service Restarted - Rule", "ESCU - Linux Service Started Or Enabled - Rule", "ESCU - Linux Setuid Using Chmod Utility - Rule", "ESCU - Linux Setuid Using Setcap Utility - Rule", "ESCU - Linux Shred Overwrite Command - Rule", "ESCU - Linux Sudo OR Su Execution - Rule", "ESCU - Linux Sudoers Tmp File Creation - Rule", "ESCU - Linux Visudo Utility Execution - Rule"] description = Monitor for activities and techniques associated with maintaining persistence on a Linux system--a sign that an adversary may have compromised your environment. narrative = Maintaining persistence is one of the first steps taken by attackers after the initial compromise. Attackers leverage various custom and built-in tools to ensure survivability and persistent access within a compromised enterprise. This Analytic Story provides searches to help you identify various behaviors used by attackers to maintain persistent access to a Linux environment. @@ -10534,10 +10821,21 @@ version = 1 references = ["https://attack.mitre.org/tactics/TA0004/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Teoderick Contreras"}] spec_version = 3 -searches = ["ESCU - Linux Add Files In Known Crontab Directories - Rule", "ESCU - Linux Add User Account - Rule", "ESCU - Linux Adding Crontab Using List Parameter - Rule", "ESCU - Linux At Allow Config File Creation - Rule", "ESCU - Linux At Application Execution - Rule", "ESCU - Linux Change File Owner To Root - Rule", "ESCU - Linux Common Process For Elevation Control - Rule", "ESCU - Linux Doas Conf File Creation - Rule", "ESCU - Linux Doas Tool Execution - Rule", "ESCU - Linux Edit Cron Table Parameter - Rule", "ESCU - Linux File Created In Kernel Driver Directory - Rule", "ESCU - Linux File Creation In Init Boot Directory - Rule", "ESCU - Linux File Creation In Profile Directory - Rule", "ESCU - Linux Insert Kernel Module Using Insmod Utility - Rule", "ESCU - Linux Install Kernel Module Using Modprobe Utility - Rule", "ESCU - Linux NOPASSWD Entry In Sudoers File - Rule", "ESCU - Linux pkexec Privilege Escalation - Rule", "ESCU - Linux Possible Access Or Modification Of sshd Config File - Rule", "ESCU - Linux Possible Access To Credential Files - Rule", "ESCU - Linux Possible Access To Sudoers File - Rule", "ESCU - Linux Possible Append Command To At Allow Config File - Rule", "ESCU - Linux Possible Append Command To Profile Config File - Rule", "ESCU - Linux Possible Append Cronjob Entry on Existing Cronjob File - Rule", "ESCU - Linux Possible Cronjob Modification With Editor - Rule", "ESCU - Linux Possible Ssh Key File Creation - Rule", "ESCU - Linux Preload Hijack Library Calls - Rule", "ESCU - Linux Service File Created In Systemd Directory - Rule", "ESCU - Linux Service Restarted - Rule", "ESCU - Linux Service Started Or Enabled - Rule", "ESCU - Linux Setuid Using Chmod Utility - Rule", "ESCU - Linux Setuid Using Setcap Utility - Rule", "ESCU - Linux Shred Overwrite Command - Rule", "ESCU - Linux Sudo OR Su Execution - Rule", "ESCU - Linux Sudoers Tmp File Creation - Rule", "ESCU - Linux Visudo Utility Execution - Rule"] +searches = ["ESCU - Linux Add Files In Known Crontab Directories - Rule", "ESCU - Linux Add User Account - Rule", "ESCU - Linux Adding Crontab Using List Parameter - Rule", "ESCU - Linux At Allow Config File Creation - Rule", "ESCU - Linux At Application Execution - Rule", "ESCU - Linux Change File Owner To Root - Rule", "ESCU - Linux Common Process For Elevation Control - Rule", "ESCU - Linux Doas Conf File Creation - Rule", "ESCU - Linux Doas Tool Execution - Rule", "ESCU - Linux Edit Cron Table Parameter - Rule", "ESCU - Linux File Created In Kernel Driver Directory - Rule", "ESCU - Linux File Creation In Init Boot Directory - Rule", "ESCU - Linux File Creation In Profile Directory - Rule", "ESCU - Linux Insert Kernel Module Using Insmod Utility - Rule", "ESCU - Linux Install Kernel Module Using Modprobe Utility - Rule", "ESCU - Linux NOPASSWD Entry In Sudoers File - Rule", "ESCU - Linux Persistence and Privilege Escalation Risk Behavior - Rule", "ESCU - Linux pkexec Privilege Escalation - Rule", "ESCU - Linux Possible Access Or Modification Of sshd Config File - Rule", "ESCU - Linux Possible Access To Credential Files - Rule", "ESCU - Linux Possible Access To Sudoers File - Rule", "ESCU - Linux Possible Append Command To At Allow Config File - Rule", "ESCU - Linux Possible Append Command To Profile Config File - Rule", "ESCU - Linux Possible Append Cronjob Entry on Existing Cronjob File - Rule", "ESCU - Linux Possible Cronjob Modification With Editor - Rule", "ESCU - Linux Possible Ssh Key File Creation - Rule", "ESCU - Linux Preload Hijack Library Calls - Rule", "ESCU - Linux Service File Created In Systemd Directory - Rule", "ESCU - Linux Service Restarted - Rule", "ESCU - Linux Service Started Or Enabled - Rule", "ESCU - Linux Setuid Using Chmod Utility - Rule", "ESCU - Linux Setuid Using Setcap Utility - Rule", "ESCU - Linux Shred Overwrite Command - Rule", "ESCU - Linux Sudo OR Su Execution - Rule", "ESCU - Linux Sudoers Tmp File Creation - Rule", "ESCU - Linux Visudo Utility Execution - Rule"] description = Monitor for and investigate activities that may be associated with a Linux privilege-escalation attack, including unusual processes running on endpoints, schedule task, services, setuid, root execution and more. narrative = Privilege escalation is a "land-and-expand" technique, wherein an adversary gains an initial foothold on a host and then exploits its weaknesses to increase his privileges. The motivation is simple: certain actions on a Linux machine--such as installing software--may require higher-level privileges than those the attacker initially acquired. By increasing his privilege level, the attacker can gain the control required to carry out his malicious ends. This Analytic Story provides searches to detect and investigate behaviors that attackers may use to elevate their privileges in your environment. +[analytic_story://Linux Rootkit] +category = Adversary Tactics +last_updated = 2022-07-27 +version = 1 +references = ["https://attack.mitre.org/techniques/T1014/", "https://content.fireeye.com/apt-41/rpt-apt41", "https://medium.com/chronicle-blog/winnti-more-than-just-windows-and-gates-e4f03436031a"] +maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] +spec_version = 3 +searches = ["ESCU - Linux File Created In Kernel Driver Directory - Rule", "ESCU - Linux Insert Kernel Module Using Insmod Utility - Rule", "ESCU - Linux Install Kernel Module Using Modprobe Utility - Rule", "ESCU - Linux Kernel Module Enumeration - Rule"] +description = Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information. +narrative = Rootkits or rootkit enabling functionality may reside at the user or kernel level in the operating system or lower, to include a hypervisor, Master Boot Record, or System Firmware. Rootkits have been seen for Windows, Linux, and Mac OS X systems. Linux rootkits may not standout as much as a Windows rootkit, therefore understanding what kernel modules are installed today and monitoring for new is important. As with any rootkit, it may blend in using a common kernel name or variation of legitimate names. + [analytic_story://Living Off The Land] category = Adversary Tactics last_updated = 2022-03-16 diff --git a/dist/escu/default/app.conf b/dist/escu/default/app.conf index 99106908db..338b252bfe 100644 --- a/dist/escu/default/app.conf +++ b/dist/escu/default/app.conf @@ -4,7 +4,7 @@ is_configured = false state = enabled state_change_requires_restart = false -build = 9041 +build = 9209 [triggers] reload.analytic_stories = simple @@ -20,7 +20,7 @@ reload.es_investigations = simple [launcher] author = Splunk -version = 3.45.0 +version = 3.46.0 description = Explore the Analytic Stories included with ES Content Updates. [ui] diff --git a/dist/escu/default/collections.conf b/dist/escu/default/collections.conf index 1a53a08c84..d2c62ab6a0 100644 --- a/dist/escu/default/collections.conf +++ b/dist/escu/default/collections.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2022-07-19T21:28:12 UTC +# On Date: 2022-07-28T22:42:05 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/dist/escu/default/content-version.conf b/dist/escu/default/content-version.conf index 82ced8506f..1d6dd1c1af 100644 --- a/dist/escu/default/content-version.conf +++ b/dist/escu/default/content-version.conf @@ -1,2 +1,2 @@ [content-version] -version = 3.45.0 +version = 3.46.0 diff --git a/dist/escu/default/es_investigations.conf b/dist/escu/default/es_investigations.conf index 3e7f5e012d..11ad9fa87d 100644 --- a/dist/escu/default/es_investigations.conf +++ b/dist/escu/default/es_investigations.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2022-07-19T21:28:12 UTC +# On Date: 2022-07-28T22:42:05 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/dist/escu/default/macros.conf b/dist/escu/default/macros.conf index 45e6da488c..05e82828b6 100644 --- a/dist/escu/default/macros.conf +++ b/dist/escu/default/macros.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2022-07-19T21:28:12 UTC +# On Date: 2022-07-28T22:42:05 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# @@ -85,6 +85,30 @@ description = Update this macro to limit the output results to filter out false definition = search * description = Update this macro to limit the output results to filter out false positives. +[aws_defense_evasion_delete_cloudtrail_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[aws_defense_evasion_delete_cloudwatch_log_group_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[aws_defense_evasion_impair_security_services_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[aws_defense_evasion_putbucketlifecycle_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[aws_defense_evasion_stop_logging_cloudtrail_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[aws_defense_evasion_update_cloudtrail_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [aws_detect_users_creating_keys_with_encrypt_policy_without_mfa_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. @@ -165,6 +189,30 @@ description = Update this macro to limit the output results to filter out false definition = search * description = Update this macro to limit the output results to filter out false positives. +[azure_active_directory_high_risk_sign_in_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[azure_ad_authentication_failed_during_mfa_challenge_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[azure_ad_multiple_users_failing_to_authenticate_from_ip_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[azure_ad_successful_powershell_authentication_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[azure_ad_successful_single_factor_authentication_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[azure_ad_unusual_number_of_failed_authentications_from_ip_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [circle_ci_disable_security_job_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. @@ -1669,6 +1717,10 @@ description = Update this macro to limit the output results to filter out false definition = search * description = Update this macro to limit the output results to filter out false positives. +[linux_clipboard_data_copy_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [linux_common_process_for_elevation_control_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. @@ -1677,6 +1729,10 @@ description = Update this macro to limit the output results to filter out false definition = search * description = Update this macro to limit the output results to filter out false positives. +[linux_decode_base64_to_shell_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [linux_deleting_critical_directory_using_rm_command_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. @@ -1749,6 +1805,10 @@ description = Update this macro to limit the output results to filter out false definition = search * description = Update this macro to limit the output results to filter out false positives. +[linux_kernel_module_enumeration_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [linux_kworker_process_in_writable_process_path_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. @@ -1757,6 +1817,14 @@ description = Update this macro to limit the output results to filter out false definition = search * description = Update this macro to limit the output results to filter out false positives. +[linux_obfuscated_files_or_information_base64_decode_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[linux_persistence_and_privilege_escalation_risk_behavior_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [linux_pkexec_privilege_escalation_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. @@ -1821,6 +1889,14 @@ description = Update this macro to limit the output results to filter out false definition = search * description = Update this macro to limit the output results to filter out false positives. +[linux_ssh_authorized_keys_modification_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[linux_ssh_remote_services_script_execute_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [linux_stop_services_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. @@ -2797,6 +2873,10 @@ description = Update this macro to limit the output results to filter out false definition = search * description = Update this macro to limit the output results to filter out false positives. +[windows_command_shell_dcrat_forkbomb_payload_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [windows_computer_account_created_by_computer_account_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. @@ -3217,6 +3297,22 @@ description = Update this macro to limit the output results to filter out false definition = search * description = Update this macro to limit the output results to filter out false positives. +[windows_system_logoff_commandline_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[windows_system_reboot_commandline_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[windows_system_shutdown_commandline_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[windows_system_time_discovery_w32tm_delay_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [windows_terminating_lsass_process_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. @@ -3798,6 +3894,10 @@ description = customer specific splunk configurations(eg- index, source, sourcet definition = sourcetype="aws:securityhub:firehose" description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. +[azuread] +definition = sourcetype=mscs:azure:eventhub +description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. + [brand_abuse_dns] definition = lookup update=true brandMonitoring_lookup domain as query OUTPUT domain_abuse | search domain_abuse=true description = This macro limits the output to only domains that are in the brand monitoring lookup file diff --git a/dist/escu/default/savedsearches.conf b/dist/escu/default/savedsearches.conf index 739ac56e52..bb55d44464 100644 --- a/dist/escu/default/savedsearches.conf +++ b/dist/escu/default/savedsearches.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2022-07-19T21:28:12 UTC +# On Date: 2022-07-28T22:42:05 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# @@ -842,6 +842,270 @@ realtime_schedule = 0 is_visible = false search = | tstats min(_time) as firstTime max(_time) as lastTime from datamodel=Authentication where Authentication.signature=AssumeRole by Authentication.vendor_account Authentication.user Authentication.src Authentication.user_role | `drop_dm_object_name(Authentication)` | rex field=user_role "arn:aws:sts:*:(?.*):" | where vendor_account != dest_account | rename vendor_account as requestingAccountId dest_account as requestedAccountId | lookup previously_seen_aws_cross_account_activity requestingAccountId, requestedAccountId, OUTPUTNEW firstTime | eval status = if(firstTime > relative_time(now(), "-24h@h"),"New Cross Account Activity","Previously Seen") | where status = "New Cross Account Activity" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `aws_cross_account_activity_from_previously_unseen_account_filter` +[ESCU - AWS Defense Evasion Delete Cloudtrail - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = This analytic identifies AWS `DeleteTrail` events within CloudTrail logs. Adversaries often try to impair their target's defenses by stopping their malicious activity from being logged, so that they may operate with stealth and avoid detection. When the adversary has the right type of permissions in the compromised AWS environment, they may delete the the entire cloudtrail that is logging activities in the environment. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562.008", "T1562"], "nist": ["DE.CM"]} +action.escu.data_models = [] +action.escu.eli5 = This analytic identifies AWS `DeleteTrail` events within CloudTrail logs. Adversaries often try to impair their target's defenses by stopping their malicious activity from being logged, so that they may operate with stealth and avoid detection. When the adversary has the right type of permissions in the compromised AWS environment, they may delete the the entire cloudtrail that is logging activities in the environment. +action.escu.how_to_implement = You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. +action.escu.known_false_positives = While this search has no known false positives, it is possible that an AWS admin has stopped cloudTrail logging. Please investigate this activity. +action.escu.creation_date = 2022-07-13 +action.escu.modification_date = 2022-07-13 +action.escu.confidence = high +action.escu.full_search_name = ESCU - AWS Defense Evasion Delete Cloudtrail - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = ["Amazon Web Services - Cloudtrail"] +action.escu.analytic_story = ["AWS Defense Evasion"] +action.risk = 1 +action.risk.param._risk_message = User $user_arn$ has delete a CloudTrail logging for account id $aws_account_id$ from IP $src$ +action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 90}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 90}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - AWS Defense Evasion Delete Cloudtrail - Rule +action.correlationsearch.annotations = {"analytic_story": ["AWS Defense Evasion"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 90, "context": ["Source:Cloud Data"], "impact": 100, "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562.008", "T1562"], "nist": ["DE.CM"], "observable": [{"name": "src", "role": ["Attacker"], "type": "IP Address"}, {"name": "user_arn", "role": ["Victim"], "type": "User"}]} +schedule_window = auto +action.notable = 1 +action.notable.param.nes_fields = user,dest +action.notable.param.rule_description = This analytic identifies AWS `DeleteTrail` events within CloudTrail logs. Adversaries often try to impair their target's defenses by stopping their malicious activity from being logged, so that they may operate with stealth and avoid detection. When the adversary has the right type of permissions in the compromised AWS environment, they may delete the the entire cloudtrail that is logging activities in the environment. +action.notable.param.rule_title = AWS Defense Evasion Delete Cloudtrail +action.notable.param.security_domain = threat +action.notable.param.severity = high +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `cloudtrail` eventName = DeleteTrail eventSource = cloudtrail.amazonaws.com userAgent !=console.amazonaws.com errorCode = success| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.name) as deleted_cloudtrail_name by src region eventName userAgent user_arn aws_account_id | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `aws_defense_evasion_delete_cloudtrail_filter` + +[ESCU - AWS Defense Evasion Delete CloudWatch Log Group - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = This analytic identifies AWS `DeleteLogGroup` events in CloudTrail logs. Attackers may evade the logging capability by deleting the log group in CloudWatch. This will stop sending the logs and metrics to CloudWatch. When the adversary has the right type of permissions within the compromised AWS environment, they may delete the CloudWatch log group that is logging activities in the environment. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562", "T1562.008"], "nist": ["DE.CM"]} +action.escu.data_models = [] +action.escu.eli5 = This analytic identifies AWS `DeleteLogGroup` events in CloudTrail logs. Attackers may evade the logging capability by deleting the log group in CloudWatch. This will stop sending the logs and metrics to CloudWatch. When the adversary has the right type of permissions within the compromised AWS environment, they may delete the CloudWatch log group that is logging activities in the environment. +action.escu.how_to_implement = You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. +action.escu.known_false_positives = While this search has no known false positives, it is possible that an AWS admin has deleted CloudWatch logging. Please investigate this activity. +action.escu.creation_date = 2022-07-17 +action.escu.modification_date = 2022-07-17 +action.escu.confidence = high +action.escu.full_search_name = ESCU - AWS Defense Evasion Delete CloudWatch Log Group - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = ["Amazon Web Services - Cloudtrail"] +action.escu.analytic_story = ["AWS Defense Evasion"] +action.risk = 1 +action.risk.param._risk_message = User $user_arn$ has deleted a CloudWatch logging group for account id $aws_account_id$ from IP $src$ +action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 90}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 90}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - AWS Defense Evasion Delete CloudWatch Log Group - Rule +action.correlationsearch.annotations = {"analytic_story": ["AWS Defense Evasion"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 90, "context": ["Source:Cloud Data"], "impact": 100, "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562", "T1562.008"], "nist": ["DE.CM"], "observable": [{"name": "src", "role": ["Attacker"], "type": "IP Address"}, {"name": "user_arn", "role": ["Victim"], "type": "User"}]} +schedule_window = auto +action.notable = 1 +action.notable.param.nes_fields = user,dest +action.notable.param.rule_description = This analytic identifies AWS `DeleteLogGroup` events in CloudTrail logs. Attackers may evade the logging capability by deleting the log group in CloudWatch. This will stop sending the logs and metrics to CloudWatch. When the adversary has the right type of permissions within the compromised AWS environment, they may delete the CloudWatch log group that is logging activities in the environment. +action.notable.param.rule_title = AWS Defense Evasion Delete CloudWatch Log Group +action.notable.param.security_domain = threat +action.notable.param.severity = high +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `cloudtrail` eventName = DeleteLogGroup eventSource = logs.amazonaws.com userAgent !=console.amazonaws.com errorCode = success| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.logGroupName) as log_group_name by src region eventName userAgent user_arn aws_account_id | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `aws_defense_evasion_delete_cloudwatch_log_group_filter` + +[ESCU - AWS Defense Evasion Impair Security Services - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = This analytic looks for several delete specific API calls made to AWS Security Services like CloudWatch, GuardDuty and Web Application Firewalls. These API calls are often leveraged by adversaries to weaken existing security defenses by deleting logging configurations in the CloudWatch alarm, delete a set of detectors from your Guardduty environment or simply delete a bunch of CloudWatch alarms to remain stealthy and avoid detection. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562.008", "T1562"], "nist": ["DE.CM"]} +action.escu.data_models = [] +action.escu.eli5 = This analytic looks for several delete specific API calls made to AWS Security Services like CloudWatch, GuardDuty and Web Application Firewalls. These API calls are often leveraged by adversaries to weaken existing security defenses by deleting logging configurations in the CloudWatch alarm, delete a set of detectors from your Guardduty environment or simply delete a bunch of CloudWatch alarms to remain stealthy and avoid detection. +action.escu.how_to_implement = You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. +action.escu.known_false_positives = While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names. +action.escu.creation_date = 2022-07-26 +action.escu.modification_date = 2022-07-26 +action.escu.confidence = high +action.escu.full_search_name = ESCU - AWS Defense Evasion Impair Security Services - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = ["Amazon Web Services - Cloudtrail"] +action.escu.analytic_story = ["AWS Defense Evasion"] +action.risk = 1 +action.risk.param._risk_message = User $user_arn$ has made potentially risky api calls $eventName$ that could impair AWS security services for account id $aws_account_id$ +action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 42}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 42}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - AWS Defense Evasion Impair Security Services - Rule +action.correlationsearch.annotations = {"analytic_story": ["AWS Defense Evasion"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 60, "context": ["Source:Cloud Data"], "impact": 70, "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562.008", "T1562"], "nist": ["DE.CM"], "observable": [{"name": "src", "role": ["Attacker"], "type": "IP Address"}, {"name": "user_arn", "role": ["Attacker"], "type": "User"}]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `cloudtrail` eventName IN ("DeleteLogStream","DeleteDetector","DeleteIPSet","DeleteWebACL","DeleteRule","DeleteRuleGroup","DeleteLoggingConfiguration","DeleteAlarms") | stats count min(_time) as firstTime max(_time) as lastTime values(eventName) as eventName values(eventSource) as eventSource values(requestParameters.*) as * by src region user_arn aws_account_id user_type user_agent errorCode| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `aws_defense_evasion_impair_security_services_filter` + +[ESCU - AWS Defense Evasion PutBucketLifecycle - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = This analytic identifies `PutBucketLifecycle` events in CloudTrail logs where a user has created a new lifecycle rule for an S3 bucket with a short expiration period. Attackers may use this API call to impair the CloudTrail logging by removing logs from the S3 bucket by changing the object expiration day to 1 day, in which case the CloudTrail logs will be deleted. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562.008", "T1562"], "nist": ["DE.CM"]} +action.escu.data_models = [] +action.escu.eli5 = This analytic identifies `PutBucketLifecycle` events in CloudTrail logs where a user has created a new lifecycle rule for an S3 bucket with a short expiration period. Attackers may use this API call to impair the CloudTrail logging by removing logs from the S3 bucket by changing the object expiration day to 1 day, in which case the CloudTrail logs will be deleted. +action.escu.how_to_implement = You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. We recommend our users to set the expiration days value according to your company's log retention policies. +action.escu.known_false_positives = While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names. +action.escu.creation_date = 2022-07-25 +action.escu.modification_date = 2022-07-25 +action.escu.confidence = high +action.escu.full_search_name = ESCU - AWS Defense Evasion PutBucketLifecycle - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = ["Amazon Web Services - Cloudtrail"] +action.escu.analytic_story = ["AWS Defense Evasion"] +action.risk = 1 +action.risk.param._risk_message = User $user_arn$ has created a new rule to on an S3 bucket $bucket_name$ with short expiration days +action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 20}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 20}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - AWS Defense Evasion PutBucketLifecycle - Rule +action.correlationsearch.annotations = {"analytic_story": ["AWS Defense Evasion"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 40, "context": ["Source:Cloud Data"], "impact": 50, "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562.008", "T1562"], "nist": ["DE.CM"], "observable": [{"name": "src", "role": ["Attacker"], "type": "IP Address"}, {"name": "user_arn", "role": ["Attacker"], "type": "User"}]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `cloudtrail` eventName=PutBucketLifecycle user_type=IAMUser errorCode=success | spath path=requestParameters{}.LifecycleConfiguration{}.Rule{}.Expiration{}.Days output=expiration_days | spath path=requestParameters{}.bucketName output=bucket_name | stats count min(_time) as firstTime max(_time) as lastTime by src region eventName userAgent user_arn aws_account_id expiration_days bucket_name user_type| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | where expiration_days < 3 | `aws_defense_evasion_putbucketlifecycle_filter` + +[ESCU - AWS Defense Evasion Stop Logging Cloudtrail - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = This analytic identifies `StopLogging` events in CloudTrail logs. Adversaries often try to impair their target's defenses by stopping their macliious activity from being logged, so that they may operate with stealth and avoid detection. When the adversary has the right type of permissions in the compromised AWS environment, they may easily stop logging. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562.008", "T1562"], "nist": ["DE.CM"]} +action.escu.data_models = [] +action.escu.eli5 = This analytic identifies `StopLogging` events in CloudTrail logs. Adversaries often try to impair their target's defenses by stopping their macliious activity from being logged, so that they may operate with stealth and avoid detection. When the adversary has the right type of permissions in the compromised AWS environment, they may easily stop logging. +action.escu.how_to_implement = You must install Splunk AWS Add on and enable Cloudtrail logs in your AWS Environment. +action.escu.known_false_positives = While this search has no known false positives, it is possible that an AWS admin has stopped cloudtrail logging. Please investigate this activity. +action.escu.creation_date = 2022-07-12 +action.escu.modification_date = 2022-07-12 +action.escu.confidence = high +action.escu.full_search_name = ESCU - AWS Defense Evasion Stop Logging Cloudtrail - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = ["Amazon Web Services - Cloudtrail"] +action.escu.analytic_story = ["AWS Defense Evasion"] +action.risk = 1 +action.risk.param._risk_message = User $user_arn$ has stopped Cloudtrail logging for account id $aws_account_id$ from IP $src$ +action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 90}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 90}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - AWS Defense Evasion Stop Logging Cloudtrail - Rule +action.correlationsearch.annotations = {"analytic_story": ["AWS Defense Evasion"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 90, "context": ["Source:Cloud Data"], "impact": 100, "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562.008", "T1562"], "nist": ["DE.CM"], "observable": [{"name": "src", "role": ["Attacker"], "type": "IP Address"}, {"name": "user_arn", "role": ["Victim"], "type": "User"}]} +schedule_window = auto +action.notable = 1 +action.notable.param.nes_fields = user,dest +action.notable.param.rule_description = This analytic identifies `StopLogging` events in CloudTrail logs. Adversaries often try to impair their target's defenses by stopping their macliious activity from being logged, so that they may operate with stealth and avoid detection. When the adversary has the right type of permissions in the compromised AWS environment, they may easily stop logging. +action.notable.param.rule_title = AWS Defense Evasion Stop Logging Cloudtrail +action.notable.param.security_domain = threat +action.notable.param.severity = high +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `cloudtrail` eventName = StopLogging eventSource = cloudtrail.amazonaws.com userAgent !=console.amazonaws.com errorCode = success| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.name) as stopped_cloudtrail_name by src region eventName userAgent user_arn aws_account_id | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `aws_defense_evasion_stop_logging_cloudtrail_filter` + +[ESCU - AWS Defense Evasion Update Cloudtrail - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = This analytic identifies `UpdateTrail` events in CloudTrail logs. Attackers may evade the logging capability by updating the settings and impairing them with wrong parameters. For example, Attackers may change the multi-regional log into a single region logs, which evades the logging for other regions. When the adversary has the right type of permissions in the compromised AWS environment, they may update the CloudTrail settings that is logging activities in your environment. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562", "T1562.008"], "nist": ["DE.CM"]} +action.escu.data_models = [] +action.escu.eli5 = This analytic identifies `UpdateTrail` events in CloudTrail logs. Attackers may evade the logging capability by updating the settings and impairing them with wrong parameters. For example, Attackers may change the multi-regional log into a single region logs, which evades the logging for other regions. When the adversary has the right type of permissions in the compromised AWS environment, they may update the CloudTrail settings that is logging activities in your environment. +action.escu.how_to_implement = You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. +action.escu.known_false_positives = While this search has no known false positives, it is possible that an AWS admin has updated cloudtrail logging. Please investigate this activity. +action.escu.creation_date = 2022-07-17 +action.escu.modification_date = 2022-07-17 +action.escu.confidence = high +action.escu.full_search_name = ESCU - AWS Defense Evasion Update Cloudtrail - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = ["Amazon Web Services - Cloudtrail"] +action.escu.analytic_story = ["AWS Defense Evasion"] +action.risk = 1 +action.risk.param._risk_message = User $user_arn$ has updated a cloudtrail logging for account id $aws_account_id$ from IP $src$ +action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 90}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 90}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - AWS Defense Evasion Update Cloudtrail - Rule +action.correlationsearch.annotations = {"analytic_story": ["AWS Defense Evasion"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 90, "context": ["Source:Cloud Data"], "impact": 100, "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562", "T1562.008"], "nist": ["DE.CM"], "observable": [{"name": "src", "role": ["Attacker"], "type": "IP Address"}, {"name": "user_arn", "role": ["Victim"], "type": "User"}]} +schedule_window = auto +action.notable = 1 +action.notable.param.nes_fields = user,dest +action.notable.param.rule_description = This analytic identifies `UpdateTrail` events in CloudTrail logs. Attackers may evade the logging capability by updating the settings and impairing them with wrong parameters. For example, Attackers may change the multi-regional log into a single region logs, which evades the logging for other regions. When the adversary has the right type of permissions in the compromised AWS environment, they may update the CloudTrail settings that is logging activities in your environment. +action.notable.param.rule_title = AWS Defense Evasion Update Cloudtrail +action.notable.param.security_domain = threat +action.notable.param.severity = high +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `cloudtrail` eventName = UpdateTrail eventSource = cloudtrail.amazonaws.com userAgent !=console.amazonaws.com errorCode = success| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.name) as cloudtrail_name by src region eventName userAgent user_arn aws_account_id | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `aws_defense_evasion_update_cloudtrail_filter` + [ESCU - AWS Detect Users creating keys with encrypt policy without MFA - Rule] action.escu = 0 action.escu.enabled = 1 @@ -1690,6 +1954,276 @@ realtime_schedule = 0 is_visible = false search = `cloudtrail` eventName = UpdateLoginProfile userAgent !=console.amazonaws.com errorCode = success | eval match=if(match(userIdentity.userName,requestParameters.userName), 1,0) | search match=0 | stats count min(_time) as firstTime max(_time) as lastTime by requestParameters.userName src eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.userName user_arn | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_updateloginprofile_filter` +[ESCU - Azure Active Directory High Risk Sign-in - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytic triggers on a high risk sign-in against Azure Active Directory identified by Azure Identity Protection. Identity Protection monitors sign-in events using heuristics and machine learning to identify potentially malicious events and categorizes them in three categories high, medium and low. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1110", "T1110.003"], "nist": ["DE.CM"]} +action.escu.data_models = [] +action.escu.eli5 = The following analytic triggers on a high risk sign-in against Azure Active Directory identified by Azure Identity Protection. Identity Protection monitors sign-in events using heuristics and machine learning to identify potentially malicious events and categorizes them in three categories high, medium and low. +action.escu.how_to_implement = You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase (https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the RiskyUsers and UserRiskEvents log category. +action.escu.known_false_positives = Details for the risk calculation algorithm used by Identity Protection are unknown and may be prone to false positives. +action.escu.creation_date = 2022-07-11 +action.escu.modification_date = 2022-07-11 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Azure Active Directory High Risk Sign-in - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = null +action.escu.analytic_story = ["Azure Active Directory Account Takeover"] +action.risk = 1 +action.risk.param._risk_message = A high risk event was identified by Identify Protection for user $body.properties.userPrincipalName$ +action.risk.param._risk = [{"risk_object_field": "userPrincipalName", "risk_object_type": "user", "risk_score": 54}, {"risk_object_field": "ipAddress", "risk_object_type": "system", "risk_score": 54}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Azure Active Directory High Risk Sign-in - Rule +action.correlationsearch.annotations = {"analytic_story": ["Azure Active Directory Account Takeover"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 90, "context": ["Source:Cloud Data", "Stage:Initial Access"], "impact": 60, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1110", "T1110.003"], "nist": ["DE.CM"], "observable": [{"name": "userPrincipalName", "role": ["Victim"], "type": "User"}, {"name": "ipAddress", "role": ["Attacker"], "type": "IP Address"}]} +schedule_window = auto +action.notable = 1 +action.notable.param.nes_fields = user,dest +action.notable.param.rule_description = The following analytic triggers on a high risk sign-in against Azure Active Directory identified by Azure Identity Protection. Identity Protection monitors sign-in events using heuristics and machine learning to identify potentially malicious events and categorizes them in three categories high, medium and low. +action.notable.param.rule_title = Azure Active Directory High Risk Sign-in +action.notable.param.security_domain = identity +action.notable.param.severity = high +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `azuread` body.category=UserRiskEvents body.properties.riskLevel=high | rename body.properties.* as * | stats values(userPrincipalName) by _time, ipAddress, activity, riskLevel, riskEventType, additionalInfo | `azure_active_directory_high_risk_sign_in_filter` + +[ESCU - Azure AD Authentication Failed During MFA Challenge - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytic identifies an authentication attempt event against an Azure AD tenant that fails during the Multi Factor Authentication challenge. This behavior may represent an adversary trying to authenticate with compromised credentials. In some cases, adversaries may continuously repeat login attempts in order to bombard users with MFA push notifications, SMS messages, and phone calls, potentially resulting in the user finally accepting the authentication request. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1078", "T1078.004", "T1621"], "nist": ["DE.CM"]} +action.escu.data_models = [] +action.escu.eli5 = The following analytic identifies an authentication attempt event against an Azure AD tenant that fails during the Multi Factor Authentication challenge. This behavior may represent an adversary trying to authenticate with compromised credentials. In some cases, adversaries may continuously repeat login attempts in order to bombard users with MFA push notifications, SMS messages, and phone calls, potentially resulting in the user finally accepting the authentication request. +action.escu.how_to_implement = You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the RiskyUsers and UserRiskEvents log category. +action.escu.known_false_positives = Legitimate users may miss to reply the MFA challenge within the time window or deny it by mistake. +action.escu.creation_date = 2022-07-14 +action.escu.modification_date = 2022-07-14 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Azure AD Authentication Failed During MFA Challenge - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = null +action.escu.analytic_story = ["Azure Active Directory Account Takeover"] +action.risk = 1 +action.risk.param._risk_message = User $body.properties.userPrincipalName$ failed to pass MFA challenge +action.risk.param._risk = [{"risk_object_field": "userPrincipalName", "risk_object_type": "user", "risk_score": 54}, {"risk_object_field": "ipAddress", "risk_object_type": "system", "risk_score": 54}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Azure AD Authentication Failed During MFA Challenge - Rule +action.correlationsearch.annotations = {"analytic_story": ["Azure Active Directory Account Takeover"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 90, "context": ["Source:Cloud Data", "Stage:Initial Access"], "impact": 60, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1078", "T1078.004", "T1621"], "nist": ["DE.CM"], "observable": [{"name": "userPrincipalName", "role": ["Victim"], "type": "User"}, {"name": "ipAddress", "role": ["Attacker"], "type": "IP Address"}]} +schedule_window = auto +action.notable = 1 +action.notable.param.nes_fields = user,dest +action.notable.param.rule_description = The following analytic identifies an authentication attempt event against an Azure AD tenant that fails during the Multi Factor Authentication challenge. This behavior may represent an adversary trying to authenticate with compromised credentials. In some cases, adversaries may continuously repeat login attempts in order to bombard users with MFA push notifications, SMS messages, and phone calls, potentially resulting in the user finally accepting the authentication request. +action.notable.param.rule_title = Azure AD Authentication Failed During MFA Challenge +action.notable.param.security_domain = identity +action.notable.param.severity = high +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `azuread` body.category=SignInLogs body.properties.status.errorCode=500121 | rename body.properties.* as * | stats values(userPrincipalName) by _time, ipAddress, status.additionalDetails, appDisplayName, userAgent | `azure_ad_authentication_failed_during_mfa_challenge_filter` + +[ESCU - Azure AD Multiple Users Failing To Authenticate From Ip - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytic identifies one source Ip failing to authenticate with 30 unique valid users within 5 minutes. This behavior could represent an adversary performing a Password Spraying attack against an Azure Active Directory tenant to obtain initial access or elevate privileges. Error Code 50126 represents an invalid password. This logic can be used for real time security monitoring as well as threat hunting exercises.\ +Azure AD tenants can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold if needed. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1110", "T1110.003"], "nist": ["DE.CM"]} +action.escu.data_models = [] +action.escu.eli5 = The following analytic identifies one source Ip failing to authenticate with 30 unique valid users within 5 minutes. This behavior could represent an adversary performing a Password Spraying attack against an Azure Active Directory tenant to obtain initial access or elevate privileges. Error Code 50126 represents an invalid password. This logic can be used for real time security monitoring as well as threat hunting exercises.\ +Azure AD tenants can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold if needed. +action.escu.how_to_implement = You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the SignInLogs log category. +action.escu.known_false_positives = A source Ip failing to authenticate with multiple users is not a common for legitimate behavior. +action.escu.creation_date = 2022-07-12 +action.escu.modification_date = 2022-07-12 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Azure AD Multiple Users Failing To Authenticate From Ip - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = null +action.escu.analytic_story = ["Azure Active Directory Account Takeover"] +action.risk = 1 +action.risk.param._risk_message = Source Ip $body.properties.ipAddress$ failed to authenticate with 30 users within 5 minutes. +action.risk.param._risk = [{"risk_object_field": "userPrincipalName", "risk_object_type": "user", "risk_score": 63}, {"risk_object_field": "ipAddress", "risk_object_type": "system", "risk_score": 63}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Azure AD Multiple Users Failing To Authenticate From Ip - Rule +action.correlationsearch.annotations = {"analytic_story": ["Azure Active Directory Account Takeover"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 90, "context": ["Source:Cloud Data", "Stage:Initial Access"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1110", "T1110.003"], "nist": ["DE.CM"], "observable": [{"name": "userPrincipalName", "role": ["Victim"], "type": "User"}, {"name": "ipAddress", "role": ["Attacker"], "type": "IP Address"}]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `azuread` body.properties.status.errorCode= 50126 body.category= SignInLogs body.properties.authenticationDetails{}.succeeded= false | rename body.properties.* as * | bucket span=5m _time | stats dc(userPrincipalName) AS unique_accounts values(userPrincipalName) as tried_accounts by _time, ipAddress | where unique_accounts > 30 | `azure_ad_multiple_users_failing_to_authenticate_from_ip_filter` + +[ESCU - Azure AD Successful PowerShell Authentication - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytic identifies a successful authentication event against an Azure AD tenant using PowerShell commandlets. This behavior is not common for regular, non administrative users. After compromising an account in Azure AD, attackers and red teams alike will perform enumeration and discovery techniques. One method of executing these techniques is leveraging the native PowerShell modules. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1078", "T1078.004"], "nist": ["DE.CM"]} +action.escu.data_models = [] +action.escu.eli5 = The following analytic identifies a successful authentication event against an Azure AD tenant using PowerShell commandlets. This behavior is not common for regular, non administrative users. After compromising an account in Azure AD, attackers and red teams alike will perform enumeration and discovery techniques. One method of executing these techniques is leveraging the native PowerShell modules. +action.escu.how_to_implement = You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the SignInLogs log category. +action.escu.known_false_positives = Administrative users will likely use PowerShell commandlets to troubleshoot and maintain the environment. Filter as needed. +action.escu.creation_date = 2022-07-13 +action.escu.modification_date = 2022-07-13 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Azure AD Successful PowerShell Authentication - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = null +action.escu.analytic_story = ["Azure Active Directory Account Takeover"] +action.risk = 1 +action.risk.param._risk_message = Successful authentication for user $body.properties.userPrincipalName$ using PowerShell. +action.risk.param._risk = [{"risk_object_field": "userPrincipalName", "risk_object_type": "user", "risk_score": 54}, {"risk_object_field": "ipAddress", "risk_object_type": "system", "risk_score": 54}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Azure AD Successful PowerShell Authentication - Rule +action.correlationsearch.annotations = {"analytic_story": ["Azure Active Directory Account Takeover"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 90, "context": ["Source:Cloud Data", "Stage:Initial Access"], "impact": 60, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1078", "T1078.004"], "nist": ["DE.CM"], "observable": [{"name": "userPrincipalName", "role": ["Victim"], "type": "User"}, {"name": "ipAddress", "role": ["Attacker"], "type": "IP Address"}]} +schedule_window = auto +action.notable = 1 +action.notable.param.nes_fields = user,dest +action.notable.param.rule_description = The following analytic identifies a successful authentication event against an Azure AD tenant using PowerShell commandlets. This behavior is not common for regular, non administrative users. After compromising an account in Azure AD, attackers and red teams alike will perform enumeration and discovery techniques. One method of executing these techniques is leveraging the native PowerShell modules. +action.notable.param.rule_title = Azure AD Successful PowerShell Authentication +action.notable.param.security_domain = identity +action.notable.param.severity = high +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `azuread` body.category=SignInLogs body.properties.authenticationDetails{}.succeeded=true body.properties.appDisplayName="Azure Active Directory PowerShell" | rename body.properties.* as * | stats values(userPrincipalName) by _time, ipAddress, appDisplayName, userAgent | `azure_ad_successful_powershell_authentication_filter` + +[ESCU - Azure AD Successful Single-Factor Authentication - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytic identifies a successful authentication event against Azure Active Directory for an account without Multi-Factor Authentication enabled. This could be evidence of a missconfiguration, a policy violation or an account take over attempt that should be investigated +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1003.002"], "nist": ["DE.CM"]} +action.escu.data_models = [] +action.escu.eli5 = The following analytic identifies a successful authentication event against Azure Active Directory for an account without Multi-Factor Authentication enabled. This could be evidence of a missconfiguration, a policy violation or an account take over attempt that should be investigated +action.escu.how_to_implement = You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the SignInLogs log category. +action.escu.known_false_positives = Although not recommended, certain users may be required without multi-factor authentication. Filter as needed +action.escu.creation_date = 2022-07-12 +action.escu.modification_date = 2022-07-12 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Azure AD Successful Single-Factor Authentication - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = null +action.escu.analytic_story = ["Azure Active Directory Account Takeover"] +action.risk = 1 +action.risk.param._risk_message = Successful authentication for user $body.properties.userPrincipalName$ without MFA +action.risk.param._risk = [{"risk_object_field": "userPrincipalName", "risk_object_type": "user", "risk_score": 50}, {"risk_object_field": "ipAddress", "risk_object_type": "system", "risk_score": 50}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Azure AD Successful Single-Factor Authentication - Rule +action.correlationsearch.annotations = {"analytic_story": ["Azure Active Directory Account Takeover"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 100, "context": ["Source:Cloud Data", "Stage:Initial Access"], "impact": 50, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1003.002"], "nist": ["DE.CM"], "observable": [{"name": "userPrincipalName", "role": ["Victim"], "type": "User"}, {"name": "ipAddress", "role": ["Attacker"], "type": "IP Address"}]} +schedule_window = auto +action.notable = 1 +action.notable.param.nes_fields = user,dest +action.notable.param.rule_description = The following analytic identifies a successful authentication event against Azure Active Directory for an account without Multi-Factor Authentication enabled. This could be evidence of a missconfiguration, a policy violation or an account take over attempt that should be investigated +action.notable.param.rule_title = Azure AD Successful Single-Factor Authentication +action.notable.param.security_domain = identity +action.notable.param.severity = high +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `azuread` body.category=SignInLogs body.properties.authenticationRequirement=singleFactorAuthentication body.properties.authenticationDetails{}.succeeded=true | rename body.properties.* as * | stats values(userPrincipalName) by _time, ipAddress, appDisplayName, authenticationRequirement | `azure_ad_successful_single_factor_authentication_filter` + +[ESCU - Azure AD Unusual Number of Failed Authentications From Ip - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytic identifies one source Ip failing to authenticate with multiple valid users. This behavior could represent an adversary performing a Password Spraying attack against an Azure Active Directory tenant to obtain initial access or elevate privileges. Error Code 50126 represents an invalid password.\ +The detection calculates the standard deviation for source Ip and leverages the 3-sigma statistical rule to identify an unusual number of failed authentication attempts. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ +While looking for anomalies using statistical methods like the standard deviation can have benefits, we also recommend using threshold-based detections to complement coverage. A similar analytic following the threshold model is `Azure AD Multiple Users Failing To Authenticate From Ip`. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1110", "T1110.003"], "nist": ["DE.CM"]} +action.escu.data_models = [] +action.escu.eli5 = The following analytic identifies one source Ip failing to authenticate with multiple valid users. This behavior could represent an adversary performing a Password Spraying attack against an Azure Active Directory tenant to obtain initial access or elevate privileges. Error Code 50126 represents an invalid password.\ +The detection calculates the standard deviation for source Ip and leverages the 3-sigma statistical rule to identify an unusual number of failed authentication attempts. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ +While looking for anomalies using statistical methods like the standard deviation can have benefits, we also recommend using threshold-based detections to complement coverage. A similar analytic following the threshold model is `Azure AD Multiple Users Failing To Authenticate From Ip`. +action.escu.how_to_implement = You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the SignInLogs log category. +action.escu.known_false_positives = A source Ip failing to authenticate with multiple users is not a common for legitimate behavior. +action.escu.creation_date = 2022-07-11 +action.escu.modification_date = 2022-07-11 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Azure AD Unusual Number of Failed Authentications From Ip - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = null +action.escu.analytic_story = ["Azure Active Directory Account Takeover"] +action.risk = 1 +action.risk.param._risk_message = Possible Password Spraying attack against Azure AD from source ip $body.properties.ipAddress$ +action.risk.param._risk = [{"risk_object_field": "userPrincipalName", "risk_object_type": "user", "risk_score": 54}, {"risk_object_field": "ipAddress", "risk_object_type": "system", "risk_score": 54}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Azure AD Unusual Number of Failed Authentications From Ip - Rule +action.correlationsearch.annotations = {"analytic_story": ["Azure Active Directory Account Takeover"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 90, "context": ["Source:Cloud Data", "Stage:Initial Access"], "impact": 60, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1110", "T1110.003"], "nist": ["DE.CM"], "observable": [{"name": "userPrincipalName", "role": ["Victim"], "type": "User"}, {"name": "ipAddress", "role": ["Attacker"], "type": "IP Address"}]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `azuread` body.properties.status.errorCode= 50126 body.category= SignInLogs body.properties.authenticationDetails{}.succeeded= false | rename body.properties.* as * | bucket span=5m _time | stats dc(userPrincipalName) AS unique_accounts values(userPrincipalName) as tried_accounts by _time, ipAddress | eventstats avg(unique_accounts) as ip_avg , stdev(unique_accounts) as ip_std by ipAddress | eval upperBound=(ip_avg+ip_std*3) | eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) | `azure_ad_unusual_number_of_failed_authentications_from_ip_filter` + [ESCU - Circle CI Disable Security Job - Rule] action.escu = 0 action.escu.enabled = 1 @@ -7735,7 +8269,7 @@ action.escu.full_search_name = ESCU - Any Powershell DownloadFile - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Hermetic Wiper", "Malicious PowerShell", "Ingress Tool Transfer", "Log4Shell CVE-2021-44228"] +action.escu.analytic_story = ["Hermetic Wiper", "Malicious PowerShell", "Ingress Tool Transfer", "Log4Shell CVE-2021-44228", "DarkCrystal RAT"] action.risk = 1 action.risk.param._risk_message = An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$. This behavior identifies the use of DownloadFile within PowerShell. action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 56}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 56}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] @@ -7746,7 +8280,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Any Powershell DownloadFile - Rule -action.correlationsearch.annotations = {"analytic_story": ["Hermetic Wiper", "Malicious PowerShell", "Ingress Tool Transfer", "Log4Shell CVE-2021-44228"], "confidence": 70, "context": ["Source:Endpoint", "Stage:Execution"], "cve": ["CVE-2021-44228"], "impact": 80, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1059", "T1059.001", "T1105"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}, {"name": "parent_process_name", "role": ["Parent Process"], "type": "Process"}, {"name": "process_name", "role": ["Child Process"], "type": "Process"}]} +action.correlationsearch.annotations = {"analytic_story": ["Hermetic Wiper", "Malicious PowerShell", "Ingress Tool Transfer", "Log4Shell CVE-2021-44228", "DarkCrystal RAT"], "confidence": 70, "context": ["Source:Endpoint", "Stage:Execution"], "cve": ["CVE-2021-44228"], "impact": 80, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1059", "T1059.001", "T1105"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}, {"name": "parent_process_name", "role": ["Parent Process"], "type": "Process"}, {"name": "process_name", "role": ["Child Process"], "type": "Process"}]} schedule_window = auto action.notable = 1 action.notable.param.nes_fields = user,dest @@ -8793,7 +9327,7 @@ action.escu.full_search_name = ESCU - CMD Carry Out String Command Parameter - R action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Data Destruction", "IcedID", "Log4Shell CVE-2021-44228", "WhisperGate", "Hermetic Wiper", "Living Off The Land", "Azorult"] +action.escu.analytic_story = ["Data Destruction", "IcedID", "Log4Shell CVE-2021-44228", "WhisperGate", "Hermetic Wiper", "Living Off The Land", "Azorult", "DarkCrystal RAT"] action.risk = 1 action.risk.param._risk_message = An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting spawn a new process. action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 30}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 30}] @@ -8804,7 +9338,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - CMD Carry Out String Command Parameter - Rule -action.correlationsearch.annotations = {"analytic_story": ["Data Destruction", "IcedID", "Log4Shell CVE-2021-44228", "WhisperGate", "Hermetic Wiper", "Living Off The Land", "Azorult"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Execution"], "cve": ["CVE-2021-44228"], "impact": 60, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1059.003", "T1059"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}, {"name": "user", "role": ["Victim"], "type": "User"}]} +action.correlationsearch.annotations = {"analytic_story": ["Data Destruction", "IcedID", "Log4Shell CVE-2021-44228", "WhisperGate", "Hermetic Wiper", "Living Off The Land", "Azorult", "DarkCrystal RAT"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Execution"], "cve": ["CVE-2021-44228"], "impact": 60, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1059.003", "T1059"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}, {"name": "user", "role": ["Victim"], "type": "User"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -9650,7 +10184,7 @@ action.escu.full_search_name = ESCU - Curl Download and Bash Execution - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Ingress Tool Transfer", "Log4Shell CVE-2021-44228"] +action.escu.analytic_story = ["Ingress Tool Transfer", "Log4Shell CVE-2021-44228", "Linux Living Off The Land"] action.risk = 1 action.risk.param._risk_message = An instance of $process_name$ was identified on endpoint $dest$ attempting to download a remote file and run it with bash. action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 80}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 80}, {"threat_object_field": "process_name", "threat_object_type": "process"}] @@ -9661,7 +10195,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Curl Download and Bash Execution - Rule -action.correlationsearch.annotations = {"analytic_story": ["Ingress Tool Transfer", "Log4Shell CVE-2021-44228"], "confidence": 100, "context": ["Source:Endpoint", "Stage:Defense Evasion"], "cve": ["CVE-2021-44228"], "impact": 80, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1105"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}, {"name": "process_name", "role": ["Child Process"], "type": "Process"}]} +action.correlationsearch.annotations = {"analytic_story": ["Ingress Tool Transfer", "Log4Shell CVE-2021-44228", "Linux Living Off The Land"], "confidence": 100, "context": ["Source:Endpoint", "Stage:Defense Evasion"], "cve": ["CVE-2021-44228"], "impact": 80, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1105"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}, {"name": "process_name", "role": ["Child Process"], "type": "Process"}]} schedule_window = auto action.notable = 1 action.notable.param.nes_fields = user,dest @@ -14882,7 +15416,7 @@ action.escu.full_search_name = ESCU - Executables Or Script Creation In Suspicio action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Double Zero Destructor", "Data Destruction", "XMRig", "Remcos", "WhisperGate", "Hermetic Wiper", "Industroyer2", "Azorult"] +action.escu.analytic_story = ["Double Zero Destructor", "Data Destruction", "XMRig", "Remcos", "WhisperGate", "Hermetic Wiper", "Industroyer2", "Azorult", "DarkCrystal RAT"] action.risk = 1 action.risk.param._risk_message = Suspicious executable or scripts with file name $file_name$, $file_path$ and process_id $process_id$ executed in suspicious file path in Windows by $user$ action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 56}, {"threat_object_field": "process_id", "threat_object_type": "process"}, {"threat_object_field": "file_name", "threat_object_type": "file name"}] @@ -14893,7 +15427,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Executables Or Script Creation In Suspicious Path - Rule -action.correlationsearch.annotations = {"analytic_story": ["Double Zero Destructor", "Data Destruction", "XMRig", "Remcos", "WhisperGate", "Hermetic Wiper", "Industroyer2", "Azorult"], "confidence": 70, "context": ["Source:Endpoint", "Stage:Execution"], "impact": 80, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1036"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "process_id", "role": ["Attacker"], "type": "Process"}, {"name": "file_name", "role": ["Other", "Attacker"], "type": "File Name"}]} +action.correlationsearch.annotations = {"analytic_story": ["Double Zero Destructor", "Data Destruction", "XMRig", "Remcos", "WhisperGate", "Hermetic Wiper", "Industroyer2", "Azorult", "DarkCrystal RAT"], "confidence": 70, "context": ["Source:Endpoint", "Stage:Execution"], "impact": 80, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1036"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "process_id", "role": ["Attacker"], "type": "Process"}, {"name": "file_name", "role": ["Other", "Attacker"], "type": "File Name"}]} schedule_window = auto action.notable = 1 action.notable.param.nes_fields = user,dest @@ -17994,7 +18528,7 @@ action.escu.full_search_name = ESCU - Linux Add Files In Known Crontab Directori action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] +action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] action.risk = 1 action.risk.param._risk_message = a file $file_name$ is created in $file_path$ on $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}] @@ -18005,7 +18539,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Linux Add Files In Known Crontab Directories - Rule -action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 50, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.003", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 50, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.003", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -18074,7 +18608,7 @@ action.escu.full_search_name = ESCU - Linux Adding Crontab Using List Parameter action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Industroyer2", "Linux Privilege Escalation", "Linux Persistence Techniques"] +action.escu.analytic_story = ["Industroyer2", "Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] action.risk = 1 action.risk.param._risk_message = A possible crontab list command $process$ executed on $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}] @@ -18085,7 +18619,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Linux Adding Crontab Using List Parameter - Rule -action.correlationsearch.annotations = {"analytic_story": ["Industroyer2", "Linux Privilege Escalation", "Linux Persistence Techniques"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 50, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.003", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +action.correlationsearch.annotations = {"analytic_story": ["Industroyer2", "Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 50, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.003", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -18114,7 +18648,7 @@ action.escu.full_search_name = ESCU - Linux At Allow Config File Creation - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] +action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] action.risk = 1 action.risk.param._risk_message = A file $file_name$ is created in $file_path$ on $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}] @@ -18125,7 +18659,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Linux At Allow Config File Creation - Rule -action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 50, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.003", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 50, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.003", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -18154,7 +18688,7 @@ action.escu.full_search_name = ESCU - Linux At Application Execution - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] +action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] action.risk = 1 action.risk.param._risk_message = At application was executed in $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 9}] @@ -18165,7 +18699,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Linux At Application Execution - Rule -action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 30, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 30, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.002", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 30, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 30, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.002", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -18194,7 +18728,7 @@ action.escu.full_search_name = ESCU - Linux Change File Owner To Root - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] +action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] action.risk = 1 action.risk.param._risk_message = A commandline $process$ that may change ownership to root on $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 64}] @@ -18205,7 +18739,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Linux Change File Owner To Root - Rule -action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 80, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 80, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1222.002", "T1222"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 80, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 80, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1222.002", "T1222"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -18218,6 +18752,46 @@ realtime_schedule = 0 is_visible = false search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = chown OR Processes.process = "*chown *") AND Processes.process = "* root *" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `linux_change_file_owner_to_root_filter` +[ESCU - Linux Clipboard Data Copy - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytic identifies the use of Linux Xclip copying data out of the clipboard. Adversaries have utilized this technique to capture passwords, IP addresses, or store payloads. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1115"], "nist": ["DE.CM"]} +action.escu.data_models = ["Endpoint"] +action.escu.eli5 = The following analytic identifies the use of Linux Xclip copying data out of the clipboard. Adversaries have utilized this technique to capture passwords, IP addresses, or store payloads. +action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +action.escu.known_false_positives = False positives may be present on Linux desktop as it may commonly be used by administrators or end users. Filter as needed. +action.escu.creation_date = 2022-07-28 +action.escu.modification_date = 2022-07-28 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Linux Clipboard Data Copy - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] +action.escu.analytic_story = ["Linux Living Off The Land"] +action.risk = 1 +action.risk.param._risk_message = An instance of $process_name$ was identified on endpoint $dest$ by user $user$ adding or removing content from the clipboard. +action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 16}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 16}, {"threat_object_field": "process_name", "threat_object_type": "process"}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Linux Clipboard Data Copy - Rule +action.correlationsearch.annotations = {"analytic_story": ["Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 40, "context": ["Source:Endpoint", "Stage:Discovery"], "impact": 40, "kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1115"], "nist": ["DE.CM"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}, {"name": "process_name", "role": ["Child Process"], "type": "Process"}]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=xclip Processes.process IN ("*-o *", "*-sel *", "*-selection *", "*clip *","*clipboard*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `linux_clipboard_data_copy_filter` + [ESCU - Linux Common Process For Elevation Control - Rule] action.escu = 0 action.escu.enabled = 1 @@ -18234,7 +18808,7 @@ action.escu.full_search_name = ESCU - Linux Common Process For Elevation Control action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] +action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] action.risk = 1 action.risk.param._risk_message = A commandline $process$ with process $process_name$ on $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 9}] @@ -18245,7 +18819,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Linux Common Process For Elevation Control - Rule -action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 30, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 30, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.001", "T1548"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 30, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 30, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.001", "T1548"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -18304,6 +18878,52 @@ realtime_schedule = 0 is_visible = false search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "dd" AND Processes.process = "*of=*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `linux_dd_file_overwrite_filter` +[ESCU - Linux Decode Base64 to Shell - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytic identifies base64 being decoded and passed to a Linux shell. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Delivery", "Exploitation"], "mitre_attack": ["T1027", "T1059.004"], "nist": ["DE.CM"]} +action.escu.data_models = ["Endpoint"] +action.escu.eli5 = The following analytic identifies base64 being decoded and passed to a Linux shell. +action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +action.escu.known_false_positives = False positives may be present based on legitimate software being utilized. Filter as needed. +action.escu.creation_date = 2022-07-27 +action.escu.modification_date = 2022-07-27 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Linux Decode Base64 to Shell - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] +action.escu.analytic_story = ["Linux Living Off The Land"] +action.risk = 1 +action.risk.param._risk_message = An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ decoding base64 and passing it to a shell. +action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Linux Decode Base64 to Shell - Rule +action.correlationsearch.annotations = {"analytic_story": ["Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Defense Evasion"], "impact": 50, "kill_chain_phases": ["Delivery", "Exploitation"], "mitre_attack": ["T1027", "T1059.004"], "nist": ["DE.CM"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}, {"name": "parent_process_name", "role": ["Parent Process"], "type": "Process"}, {"name": "process_name", "role": ["Child Process"], "type": "Process"}]} +schedule_window = auto +action.notable = 1 +action.notable.param.nes_fields = user,dest +action.notable.param.rule_description = The following analytic identifies base64 being decoded and passed to a Linux shell. +action.notable.param.rule_title = Linux Decode Base64 to Shell +action.notable.param.security_domain = endpoint +action.notable.param.severity = high +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process IN ("*base64 -d*","*base64 --decode*") AND Processes.process="*|*" `linux_shells` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `linux_decode_base64_to_shell_filter` + [ESCU - Linux Deleting Critical Directory Using RM Command - Rule] action.escu = 0 action.escu.enabled = 1 @@ -18664,7 +19284,7 @@ action.escu.full_search_name = ESCU - Linux Edit Cron Table Parameter - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] +action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] action.risk = 1 action.risk.param._risk_message = A possible crontab edit command $process$ executed on $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 9}] @@ -18675,7 +19295,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Linux Edit Cron Table Parameter - Rule -action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 30, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 30, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.003", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 30, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 30, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.003", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -18704,7 +19324,7 @@ action.escu.full_search_name = ESCU - Linux File Created In Kernel Driver Direct action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] +action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Rootkit"] action.risk = 1 action.risk.param._risk_message = A file $file_name$ is created in $file_path$ on $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 72}] @@ -18715,7 +19335,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Linux File Created In Kernel Driver Directory - Rule -action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 90, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 80, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1547.006", "T1547"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Rootkit"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 90, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 80, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1547.006", "T1547"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -18910,7 +19530,7 @@ action.escu.full_search_name = ESCU - Linux Insert Kernel Module Using Insmod Ut action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] +action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Rootkit"] action.risk = 1 action.risk.param._risk_message = A commandline $process$ that may install kernel module on $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 64}] @@ -18921,7 +19541,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Linux Insert Kernel Module Using Insmod Utility - Rule -action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 80, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 80, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1547.006", "T1547"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Rootkit"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 80, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 80, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1547.006", "T1547"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -18950,7 +19570,7 @@ action.escu.full_search_name = ESCU - Linux Install Kernel Module Using Modprobe action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] +action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Rootkit"] action.risk = 1 action.risk.param._risk_message = A commandline $process$ that may install kernel module on $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 64}] @@ -18961,7 +19581,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Linux Install Kernel Module Using Modprobe Utility - Rule -action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 80, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 80, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1547.006", "T1547"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Rootkit"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 80, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 80, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1547.006", "T1547"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -19060,6 +19680,46 @@ realtime_schedule = 0 is_visible = false search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=java OR Processes.parent_process_name=apache OR Processes.parent_process_name=tomcat `linux_shells` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `linux_java_spawning_shell_filter` +[ESCU - Linux Kernel Module Enumeration - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytic identifies the process kmod being utilized to list kernel modules in use. Typically, this is not seen as malicious, however it may be a precurser to the use of insmod to install a module. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1082", "T1014"], "nist": ["DE.CM"]} +action.escu.data_models = ["Endpoint"] +action.escu.eli5 = The following analytic identifies the process kmod being utilized to list kernel modules in use. Typically, this is not seen as malicious, however it may be a precurser to the use of insmod to install a module. +action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +action.escu.known_false_positives = False positives are present based on automated tooling or system administrative usage. Filter as needed. +action.escu.creation_date = 2022-07-27 +action.escu.modification_date = 2022-07-27 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Linux Kernel Module Enumeration - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] +action.escu.analytic_story = ["Linux Rootkit"] +action.risk = 1 +action.risk.param._risk_message = An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ enumeration kernel modules. +action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 15}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Linux Kernel Module Enumeration - Rule +action.correlationsearch.annotations = {"analytic_story": ["Linux Rootkit"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Discovery"], "impact": 30, "kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1082", "T1014"], "nist": ["DE.CM"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}, {"name": "parent_process_name", "role": ["Parent Process"], "type": "Process"}, {"name": "process_name", "role": ["Child Process"], "type": "Process"}]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=kmod Processes.process IN ("*lsmod*", "*list*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `linux_kernel_module_enumeration_filter` + [ESCU - Linux Kworker Process In Writable Process Path - Rule] action.escu = 0 action.escu.enabled = 1 @@ -19140,6 +19800,92 @@ realtime_schedule = 0 is_visible = false search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*NOPASSWD:*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `linux_nopasswd_entry_in_sudoers_file_filter` +[ESCU - Linux Obfuscated Files or Information Base64 Decode - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytic identifies the use of base64 decode on Linux being utilized to deobfuscate a file. Identify the source of the file and determine if legitimate. Review parallel processes for further behavior before and after. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Delivery", "Exploitation"], "mitre_attack": ["T1027"], "nist": ["DE.CM"]} +action.escu.data_models = ["Endpoint"] +action.escu.eli5 = The following analytic identifies the use of base64 decode on Linux being utilized to deobfuscate a file. Identify the source of the file and determine if legitimate. Review parallel processes for further behavior before and after. +action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +action.escu.known_false_positives = False positives may be present and will require some tuning based on processes. Filter as needed. +action.escu.creation_date = 2022-07-27 +action.escu.modification_date = 2022-07-27 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Linux Obfuscated Files or Information Base64 Decode - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] +action.escu.analytic_story = ["Linux Living Off The Land"] +action.risk = 1 +action.risk.param._risk_message = An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ decoding base64. +action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 15}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Linux Obfuscated Files or Information Base64 Decode - Rule +action.correlationsearch.annotations = {"analytic_story": ["Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Defense Evasion"], "impact": 30, "kill_chain_phases": ["Delivery", "Exploitation"], "mitre_attack": ["T1027"], "nist": ["DE.CM"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}, {"name": "parent_process_name", "role": ["Parent Process"], "type": "Process"}, {"name": "process_name", "role": ["Child Process"], "type": "Process"}]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process IN ("*base64 -d*","*base64 --decode*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `linux_obfuscated_files_or_information_base64_decode_filter` + +[ESCU - Linux Persistence and Privilege Escalation Risk Behavior - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following correlation is specific to Linux persistence and privilege escalation tactics and is tied to two analytic stories and any Linux analytic tied to persistence and privilege escalation. These techniques often overlap with Persistence techniques, as OS features that let an adversary persist can execute in an elevated context. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548"], "nist": ["DE.CM"]} +action.escu.data_models = ["Risk"] +action.escu.eli5 = The following correlation is specific to Linux persistence and privilege escalation tactics and is tied to two analytic stories and any Linux analytic tied to persistence and privilege escalation. These techniques often overlap with Persistence techniques, as OS features that let an adversary persist can execute in an elevated context. +action.escu.how_to_implement = Ensure Linux anomaly and TTP analytics are enabled. TTP may be set to Notables for point detections, anomaly should not be notables but risk generators. The correlation relies on more than x amount of distict detection names generated before generating a notable. Modify the value as needed. Default value is set to 4. This value may need to be increased based on activity in your environment. +action.escu.known_false_positives = False positives will be present based on many factors. Tune the correlation as needed to reduce too many triggers. +action.escu.creation_date = 2022-07-20 +action.escu.modification_date = 2022-07-20 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Linux Persistence and Privilege Escalation Risk Behavior - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = null +action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] +action.risk = 1 +action.risk.param._risk_message = Privilege escalation and persistence behaviors have been identified on $risk_object$. +action.risk.param._risk = [{"risk_object_field": "risk_object", "risk_object_type": "system", "risk_score": 56}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Linux Persistence and Privilege Escalation Risk Behavior - Rule +action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 80, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548"], "nist": ["DE.CM"], "observable": [{"name": "risk_object", "role": ["Victim"], "type": "Hostname"}]} +schedule_window = auto +action.notable = 1 +action.notable.param.nes_fields = user,dest +action.notable.param.rule_description = The following correlation is specific to Linux persistence and privilege escalation tactics and is tied to two analytic stories and any Linux analytic tied to persistence and privilege escalation. These techniques often overlap with Persistence techniques, as OS features that let an adversary persist can execute in an elevated context. +action.notable.param.rule_title = Linux Persistence and Privilege Escalation Risk Behavior +action.notable.param.security_domain = audit +action.notable.param.severity = high +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Risk.All_Risk where (All_Risk.analyticstories IN ("Linux Privilege Escalation", "Linux Persistence Techniques") OR source = "*Linux*") All_Risk.annotations.mitre_attack.mitre_tactic IN ("persistence", "privilege-escalation") All_Risk.risk_object_type="system" by All_Risk.risk_object All_Risk.annotations.mitre_attack.mitre_tactic source All_Risk.description | `drop_dm_object_name(All_Risk)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | stats values(source) as detection_name values(annotations.mitre_attack.mitre_tactic) as tactics values(firstTime) as firstTime values(lastTime) as lastTime dc(annotations.mitre_attack.mitre_tactic) as distinct_tactics dc(source) as distinct_detection_name by risk_object | where distinct_detection_name >= 4 | `linux_persistence_and_privilege_escalation_risk_behavior_filter` + [ESCU - Linux pkexec Privilege Escalation - Rule] action.escu = 0 action.escu.enabled = 1 @@ -19156,7 +19902,7 @@ action.escu.full_search_name = ESCU - Linux pkexec Privilege Escalation - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Linux Privilege Escalation"] +action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Living Off The Land"] action.risk = 1 action.risk.param._risk_message = An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ related to a local privilege escalation in polkit pkexec. action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 56}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 56}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] @@ -19167,7 +19913,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Linux pkexec Privilege Escalation - Rule -action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation"], "confidence": 70, "context": ["Source:Endpoint", "Stage:Defense Evasion"], "cve": ["CVE-2021-4034"], "impact": 80, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1068"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}, {"name": "parent_process_name", "role": ["Parent Process"], "type": "Process"}, {"name": "process_name", "role": ["Child Process"], "type": "Process"}]} +action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Living Off The Land"], "confidence": 70, "context": ["Source:Endpoint", "Stage:Defense Evasion"], "cve": ["CVE-2021-4034"], "impact": 80, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1068"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}, {"name": "parent_process_name", "role": ["Parent Process"], "type": "Process"}, {"name": "process_name", "role": ["Child Process"], "type": "Process"}]} schedule_window = auto action.notable = 1 action.notable.param.nes_fields = user,dest @@ -19202,7 +19948,7 @@ action.escu.full_search_name = ESCU - Linux Possible Access Or Modification Of s action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] +action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] action.risk = 1 action.risk.param._risk_message = a commandline $process$ executed on $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}] @@ -19213,7 +19959,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Linux Possible Access Or Modification Of sshd Config File - Rule -action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 50, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1098.004", "T1098"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 50, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1098.004", "T1098"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -19402,7 +20148,7 @@ action.escu.full_search_name = ESCU - Linux Possible Append Cronjob Entry on Exi action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] +action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] action.risk = 1 action.risk.param._risk_message = A commandline $process$ that may modify cronjob file in $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 49}] @@ -19413,7 +20159,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Linux Possible Append Cronjob Entry on Existing Cronjob File - Rule -action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 70, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.003", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 70, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.003", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -19442,7 +20188,7 @@ action.escu.full_search_name = ESCU - Linux Possible Cronjob Modification With E action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] +action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] action.risk = 1 action.risk.param._risk_message = A commandline $process$ that may modify cronjob file using editor in $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 6}] @@ -19453,7 +20199,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Linux Possible Cronjob Modification With Editor - Rule -action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 30, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 20, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.003", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 30, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 20, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.003", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -19482,7 +20228,7 @@ action.escu.full_search_name = ESCU - Linux Possible Ssh Key File Creation - Rul action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] +action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] action.risk = 1 action.risk.param._risk_message = A file $file_name$ is created in $file_path$ on $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 36}] @@ -19493,7 +20239,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Linux Possible Ssh Key File Creation - Rule -action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 60, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 60, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1098.004", "T1098"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 60, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 60, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1098.004", "T1098"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -19568,7 +20314,7 @@ action.escu.full_search_name = ESCU - Linux Service File Created In Systemd Dire action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] +action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] action.risk = 1 action.risk.param._risk_message = A service file named as $file_path$ is created in systemd folder on $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 64}] @@ -19579,7 +20325,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Linux Service File Created In Systemd Directory - Rule -action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 80, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 80, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.006", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 80, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 80, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.006", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -19608,7 +20354,7 @@ action.escu.full_search_name = ESCU - Linux Service Restarted - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] +action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] action.risk = 1 action.risk.param._risk_message = A commandline $process$ that may create or start a service on $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}] @@ -19619,7 +20365,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Linux Service Restarted - Rule -action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 50, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.006", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 50, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.006", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -19648,7 +20394,7 @@ action.escu.full_search_name = ESCU - Linux Service Started Or Enabled - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] +action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] action.risk = 1 action.risk.param._risk_message = a commandline $process$ that may create or start a service on $dest action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 42}] @@ -19659,7 +20405,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Linux Service Started Or Enabled - Rule -action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 70, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 60, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.006", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 70, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 60, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.006", "T1053"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -19688,7 +20434,7 @@ action.escu.full_search_name = ESCU - Linux Setuid Using Chmod Utility - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] +action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] action.risk = 1 action.risk.param._risk_message = a commandline $process$ that may set suid or sgid on $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 49}] @@ -19699,7 +20445,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Linux Setuid Using Chmod Utility - Rule -action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 70, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.001", "T1548"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +action.correlationsearch.annotations = {"analytic_story": ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 70, "context": ["Source:Endpoint", "Stage:Privilege Escalation", "Stage:Persistence"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.001", "T1548"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -19798,6 +20544,92 @@ realtime_schedule = 0 is_visible = false search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name =shred AND Processes.process IN ("*-n*", "*-u*", "*-z*", "*-s*") by Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `linux_shred_overwrite_command_filter` +[ESCU - Linux SSH Authorized Keys Modification - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytic identifies based on process execution the modification of SSH Authorized Keys. Adversaries perform this behavior to persist on endpoints. During triage, review parallel processes and capture any additional file modifications for review. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Installation"], "mitre_attack": ["T1098.004"], "nist": ["DE.CM"]} +action.escu.data_models = ["Endpoint"] +action.escu.eli5 = The following analytic identifies based on process execution the modification of SSH Authorized Keys. Adversaries perform this behavior to persist on endpoints. During triage, review parallel processes and capture any additional file modifications for review. +action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +action.escu.known_false_positives = Filtering will be required as system administrators will add and remove. One way to filter query is to add "echo". +action.escu.creation_date = 2022-07-27 +action.escu.modification_date = 2022-07-27 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Linux SSH Authorized Keys Modification - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] +action.escu.analytic_story = ["Linux Living Off The Land"] +action.risk = 1 +action.risk.param._risk_message = An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ modifying SSH Authorized Keys. +action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 15}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Linux SSH Authorized Keys Modification - Rule +action.correlationsearch.annotations = {"analytic_story": ["Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Persistence"], "impact": 30, "kill_chain_phases": ["Installation"], "mitre_attack": ["T1098.004"], "nist": ["DE.CM"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}, {"name": "parent_process_name", "role": ["Parent Process"], "type": "Process"}, {"name": "process_name", "role": ["Child Process"], "type": "Process"}]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN ("bash","cat") Processes.process IN ("*/authorized_keys*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `linux_ssh_authorized_keys_modification_filter` + +[ESCU - Linux SSH Remote Services Script Execute - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytic identifies SSH being utilized to move laterally and execute a script or file on the remote host. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1021.004"], "nist": ["DE.CM"]} +action.escu.data_models = ["Endpoint"] +action.escu.eli5 = The following analytic identifies SSH being utilized to move laterally and execute a script or file on the remote host. +action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +action.escu.known_false_positives = This is not a common command to be executed. Filter as needed. +action.escu.creation_date = 2022-07-27 +action.escu.modification_date = 2022-07-27 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Linux SSH Remote Services Script Execute - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] +action.escu.analytic_story = ["Linux Living Off The Land"] +action.risk = 1 +action.risk.param._risk_message = An instance of $process_name$ was identified on endpoint $dest$ by user $user$ attempting to move laterally and download a file. +action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 56}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 56}, {"threat_object_field": "process_name", "threat_object_type": "process"}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Linux SSH Remote Services Script Execute - Rule +action.correlationsearch.annotations = {"analytic_story": ["Linux Living Off The Land"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 70, "context": ["Source:Endpoint", "Stage:Lateral Movement"], "impact": 80, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1021.004"], "nist": ["DE.CM"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}, {"name": "process_name", "role": ["Child Process"], "type": "Process"}]} +schedule_window = auto +action.notable = 1 +action.notable.param.nes_fields = user,dest +action.notable.param.rule_description = The following analytic identifies SSH being utilized to move laterally and execute a script or file on the remote host. +action.notable.param.rule_title = Linux SSH Remote Services Script Execute +action.notable.param.security_domain = endpoint +action.notable.param.severity = high +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=ssh Processes.process IN ("*oStrictHostKeyChecking*", "*oConnectTimeout*", "*oBatchMode*") AND CommandLine IN ("*http:*","*https:*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `linux_ssh_remote_services_script_execute_filter` + [ESCU - Linux Stop Services - Rule] action.escu = 0 action.escu.enabled = 1 @@ -20520,7 +21352,7 @@ action.escu.full_search_name = ESCU - Malicious PowerShell Process - Encoded Com action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Hermetic Wiper", "Malicious PowerShell", "NOBELIUM Group", "WhisperGate"] +action.escu.analytic_story = ["Hermetic Wiper", "Malicious PowerShell", "NOBELIUM Group", "WhisperGate", "DarkCrystal RAT"] action.risk = 1 action.risk.param._risk_message = Powershell.exe running potentially malicious encodede commands on $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 35}] @@ -20531,7 +21363,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Malicious PowerShell Process - Encoded Command - Rule -action.correlationsearch.annotations = {"analytic_story": ["Hermetic Wiper", "Malicious PowerShell", "NOBELIUM Group", "WhisperGate"], "cis20": ["CIS 3", "CIS 7", "CIS 8"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Initial Access", "Stage:Execution", "Stage:Defense Evasion"], "impact": 70, "kill_chain_phases": ["Command \u0026 Control", "Actions on Objectives"], "mitre_attack": ["T1027"], "nist": ["PR.PT", "DE.CM", "PR.IP"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}]} +action.correlationsearch.annotations = {"analytic_story": ["Hermetic Wiper", "Malicious PowerShell", "NOBELIUM Group", "WhisperGate", "DarkCrystal RAT"], "cis20": ["CIS 3", "CIS 7", "CIS 8"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Initial Access", "Stage:Execution", "Stage:Defense Evasion"], "impact": 70, "kill_chain_phases": ["Command \u0026 Control", "Actions on Objectives"], "mitre_attack": ["T1027"], "nist": ["PR.PT", "DE.CM", "PR.IP"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -20560,7 +21392,7 @@ action.escu.full_search_name = ESCU - Malicious PowerShell Process - Execution P action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["DHS Report TA18-074A", "HAFNIUM Group"] +action.escu.analytic_story = ["DHS Report TA18-074A", "HAFNIUM Group", "DarkCrystal RAT"] action.risk = 1 action.risk.param._risk_message = PowerShell local execution policy bypass attempt on $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 42}] @@ -20571,7 +21403,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule -action.correlationsearch.annotations = {"analytic_story": ["DHS Report TA18-074A", "HAFNIUM Group"], "cis20": ["CIS 3", "CIS 7", "CIS 8"], "confidence": 60, "context": ["Source:Endpoint", "Stage:Initial Access", "Stage:Execution", "Stage:Defense Evasion"], "impact": 70, "kill_chain_phases": ["Command \u0026 Control", "Actions on Objectives"], "mitre_attack": ["T1059", "T1059.001"], "nist": ["PR.PT", "DE.CM", "PR.IP"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}]} +action.correlationsearch.annotations = {"analytic_story": ["DHS Report TA18-074A", "HAFNIUM Group", "DarkCrystal RAT"], "cis20": ["CIS 3", "CIS 7", "CIS 8"], "confidence": 60, "context": ["Source:Endpoint", "Stage:Initial Access", "Stage:Execution", "Stage:Defense Evasion"], "impact": 70, "kill_chain_phases": ["Command \u0026 Control", "Actions on Objectives"], "mitre_attack": ["T1059", "T1059.001"], "nist": ["PR.PT", "DE.CM", "PR.IP"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}]} schedule_window = auto action.notable = 1 action.notable.param.nes_fields = user,dest @@ -22074,7 +22906,7 @@ action.escu.full_search_name = ESCU - Office Document Executing Macro Code - Rul action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Spearphishing Attachments", "Trickbot", "IcedID"] +action.escu.analytic_story = ["Spearphishing Attachments", "Trickbot", "IcedID", "DarkCrystal RAT"] action.risk = 1 action.risk.param._risk_message = Office document executing a macro on $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 35}] @@ -22085,7 +22917,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Office Document Executing Macro Code - Rule -action.correlationsearch.annotations = {"analytic_story": ["Spearphishing Attachments", "Trickbot", "IcedID"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Execution"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1566", "T1566.001"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}]} +action.correlationsearch.annotations = {"analytic_story": ["Spearphishing Attachments", "Trickbot", "IcedID", "DarkCrystal RAT"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Execution"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1566", "T1566.001"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}]} schedule_window = auto action.notable = 1 action.notable.param.nes_fields = user,dest @@ -22166,7 +22998,7 @@ action.escu.full_search_name = ESCU - Office Product Spawn CMD Process - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Trickbot"] +action.escu.analytic_story = ["Trickbot", "DarkCrystal RAT"] action.risk = 1 action.risk.param._risk_message = an office product parent process $parent_process_name$ spawn child process $process_name$ in host $dest$ action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 56}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 56}] @@ -22177,7 +23009,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Office Product Spawn CMD Process - Rule -action.correlationsearch.annotations = {"analytic_story": ["Trickbot"], "confidence": 80, "context": ["Source:Endpoint", "Stage:Execution"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1218", "T1218.005"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}, {"name": "user", "role": ["Victim"], "type": "User"}]} +action.correlationsearch.annotations = {"analytic_story": ["Trickbot", "DarkCrystal RAT"], "confidence": 80, "context": ["Source:Endpoint", "Stage:Execution"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1218", "T1218.005"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}, {"name": "user", "role": ["Victim"], "type": "User"}]} schedule_window = auto action.notable = 1 action.notable.param.nes_fields = user,dest @@ -24543,8 +25375,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = The search looks for modifications to registry keys that can be used to launch an application or service at system startup. action.escu.how_to_implement = To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. action.escu.known_false_positives = There are many legitimate applications that must execute on system startup and will use these registry keys to accomplish that task. -action.escu.creation_date = 2022-01-26 -action.escu.modification_date = 2022-01-26 +action.escu.creation_date = 2022-07-20 +action.escu.modification_date = 2022-07-20 action.escu.confidence = high action.escu.full_search_name = ESCU - Registry Keys Used For Persistence - Rule action.escu.search_type = detection @@ -24578,7 +25410,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce OR Registry.registry_path=*\\currentversion\\run* OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices* OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*" AND Registry.registry_key_name=Debugger) OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\*") OR (Registry.registry_path="*currentVersion\\Windows" AND Registry.registry_key_name="Load") OR (Registry.registry_path="*\\CurrentVersion" AND Registry.registry_key_name="Svchost") OR (Registry.registry_path="*\\CurrentControlSet\Control\Session Manager"AND Registry.registry_key_name="BootExecute") OR (Registry.registry_path="*\\Software\\Run" AND Registry.registry_key_name="auto_update")) by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.registry_key_name | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `registry_keys_used_for_persistence_filter` +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce OR Registry.registry_path=*\\currentversion\\run* OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices* OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*" AND Registry.registry_key_name=Debugger) OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\*") OR (Registry.registry_path="*currentVersion\\Windows" AND Registry.registry_key_name="Load") OR (Registry.registry_path="*\\CurrentVersion" AND Registry.registry_key_name="Svchost") OR (Registry.registry_path="*\\CurrentControlSet\Control\Session Manager"AND Registry.registry_key_name="BootExecute") OR (Registry.registry_path="*\\Software\\Run" AND Registry.registry_key_name="auto_update")) by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.registry_key_name | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `registry_keys_used_for_persistence_filter` [ESCU - Registry Keys Used For Privilege Escalation - Rule] action.escu = 0 @@ -28752,7 +29584,7 @@ action.escu.full_search_name = ESCU - Suspicious Process File Path - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Data Destruction", "Double Zero Destructor", "XMRig", "Remcos", "WhisperGate", "Hermetic Wiper", "Industroyer2"] +action.escu.analytic_story = ["Data Destruction", "Double Zero Destructor", "XMRig", "Remcos", "WhisperGate", "Hermetic Wiper", "Industroyer2", "DarkCrystal RAT"] action.risk = 1 action.risk.param._risk_message = Suspicioues process $Processes.process_path.file_path$ running from suspicious location action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 35}, {"threat_object_field": "Processes.process_path.file_path", "threat_object_type": "file name"}] @@ -28763,7 +29595,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Suspicious Process File Path - Rule -action.correlationsearch.annotations = {"analytic_story": ["Data Destruction", "Double Zero Destructor", "XMRig", "Remcos", "WhisperGate", "Hermetic Wiper", "Industroyer2"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Execution", "Stage:Initial Access"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1543"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}, {"name": "Processes.process_path.file_path", "role": ["Attacker"], "type": "File Name"}]} +action.correlationsearch.annotations = {"analytic_story": ["Data Destruction", "Double Zero Destructor", "XMRig", "Remcos", "WhisperGate", "Hermetic Wiper", "Industroyer2", "DarkCrystal RAT"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Execution", "Stage:Initial Access"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1543"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}, {"name": "Processes.process_path.file_path", "role": ["Attacker"], "type": "File Name"}]} schedule_window = auto action.notable = 1 action.notable.param.nes_fields = user,dest @@ -30846,6 +31678,52 @@ realtime_schedule = 0 is_visible = false search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.process="*\/..\/..\/..\/*" OR Processes.process="*\\..\\..\\..\\*" OR Processes.process="*\/\/..\/\/..\/\/..\/\/*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id Processes.process_hash | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_command_and_scripting_interpreter_path_traversal_exec_filter` +[ESCU - Windows Command Shell DCRat ForkBomb Payload - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytic identifies DCRat "forkbomb" payload feature. This technique was seen in dark crystal RAT backdoor capabilities where it will execute several cmd child process executing "notepad.exe & pause". This analytic detects the multiple cmd.exe and child process notepad.exe execution using batch script in the targeted host within 30s timeframe. this TTP can be a good pivot to check DCRat infection. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1059.003", "T1059"], "nist": ["DE.CM"]} +action.escu.data_models = ["Endpoint"] +action.escu.eli5 = The following analytic identifies DCRat "forkbomb" payload feature. This technique was seen in dark crystal RAT backdoor capabilities where it will execute several cmd child process executing "notepad.exe & pause". This analytic detects the multiple cmd.exe and child process notepad.exe execution using batch script in the targeted host within 30s timeframe. this TTP can be a good pivot to check DCRat infection. +action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of wermgr.exe may be used. +action.escu.known_false_positives = unknown +action.escu.creation_date = 2022-07-28 +action.escu.modification_date = 2022-07-28 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Windows Command Shell DCRat ForkBomb Payload - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] +action.escu.analytic_story = ["DarkCrystal RAT"] +action.risk = 1 +action.risk.param._risk_message = Multiple cmd.exe processes with child process of notepad.exe executed on $dest$ +action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 81}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Windows Command Shell DCRat ForkBomb Payload - Rule +action.correlationsearch.annotations = {"analytic_story": ["DarkCrystal RAT"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 90, "context": ["Source:Endpoint", "Stage:Execution"], "impact": 90, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1059.003", "T1059"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +schedule_window = auto +action.notable = 1 +action.notable.param.nes_fields = user,dest +action.notable.param.rule_description = The following analytic identifies DCRat "forkbomb" payload feature. This technique was seen in dark crystal RAT backdoor capabilities where it will execute several cmd child process executing "notepad.exe & pause". This analytic detects the multiple cmd.exe and child process notepad.exe execution using batch script in the targeted host within 30s timeframe. this TTP can be a good pivot to check DCRat infection. +action.notable.param.rule_title = Windows Command Shell DCRat ForkBomb Payload +action.notable.param.security_domain = endpoint +action.notable.param.severity = high +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = | tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.parent_process_id) as parent_process_id values(Processes.process_id) as process_id dc(Processes.parent_process_id) as parent_process_id_count dc(Processes.process_id) as process_id_count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name= "cmd.exe" (Processes.process_name = "notepad.exe" OR Processes.original_file_name= "notepad.exe") Processes.parent_process = "*.bat*" by Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.parent_process Processes.dest Processes.user _time span=30s | where parent_process_id_count>= 10 AND process_id_count >=10 | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_command_shell_dcrat_forkbomb_payload_filter` + [ESCU - Windows Computer Account Created by Computer Account - Rule] action.escu = 0 action.escu.enabled = 1 @@ -32062,7 +32940,7 @@ action.escu.full_search_name = ESCU - Windows Gather Victim Network Info Through action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Azorult"] +action.escu.analytic_story = ["Azorult", "DarkCrystal RAT"] action.risk = 1 action.risk.param._risk_message = process connecting IP location web services on $Computer$ action.risk.param._risk = [{"risk_object_field": "Computer", "risk_object_type": "system", "risk_score": 25}] @@ -32073,7 +32951,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Windows Gather Victim Network Info Through Ip Check Web Services - Rule -action.correlationsearch.annotations = {"analytic_story": ["Azorult"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Initial Access", "Stage:Execution"], "impact": 50, "kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1590.005", "T1590"], "nist": ["DE.CM"], "observable": [{"name": "Computer", "role": ["Victim"], "type": "Endpoint"}]} +action.correlationsearch.annotations = {"analytic_story": ["Azorult", "DarkCrystal RAT"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Initial Access", "Stage:Execution"], "impact": 50, "kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1590.005", "T1590"], "nist": ["DE.CM"], "observable": [{"name": "Computer", "role": ["Victim"], "type": "Endpoint"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -32234,7 +33112,7 @@ action.escu.full_search_name = ESCU - Windows High File Deletion Frequency - Rul action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Clop Ransomware", "WhisperGate"] +action.escu.analytic_story = ["Clop Ransomware", "WhisperGate", "DarkCrystal RAT"] action.risk = 1 action.risk.param._risk_message = High frequency file deletion activity detected on host $Computer$ action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 72}, {"risk_object_field": "Computer", "risk_object_type": "system", "risk_score": 72}, {"threat_object_field": "deleted_files", "threat_object_type": "file name"}] @@ -32245,7 +33123,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Windows High File Deletion Frequency - Rule -action.correlationsearch.annotations = {"analytic_story": ["Clop Ransomware", "WhisperGate"], "confidence": 80, "context": ["Source:Endpoint", "Stage:Execution"], "impact": 90, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1485"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "Computer", "role": ["Victim"], "type": "Endpoint"}, {"name": "deleted_files", "role": ["Target"], "type": "File Name"}]} +action.correlationsearch.annotations = {"analytic_story": ["Clop Ransomware", "WhisperGate", "DarkCrystal RAT"], "confidence": 80, "context": ["Source:Endpoint", "Stage:Execution"], "impact": 90, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1485"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "Computer", "role": ["Victim"], "type": "Endpoint"}, {"name": "deleted_files", "role": ["Target"], "type": "File Name"}]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -32256,7 +33134,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = `sysmon` EventCode=23 TargetFilename IN ("*.cmd", "*.ini","*.gif", "*.jpg", "*.jpeg", "*.db", "*.ps1", "*.doc*", "*.xls*", "*.ppt*", "*.bmp","*.zip", "*.rar", "*.7z", "*.chm", "*.png", "*.log", "*.vbs", "*.js", "*.vhd", "*.bak", "*.wbcat", "*.bkf" , "*.backup*", "*.dsk", , "*.win") | stats values(TargetFilename) as deleted_files min(_time) as firstTime max(_time) as lastTime count by Computer user EventCode Image ProcessID |where count >=100 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_high_file_deletion_frequency_filter` +search = `sysmon` EventCode=23 TargetFilename IN ("*.cmd", "*.ini","*.gif", "*.jpg", "*.jpeg", "*.db", "*.ps1", "*.doc*", "*.xls*", "*.ppt*", "*.bmp","*.zip", "*.rar", "*.7z", "*.chm", "*.png", "*.log", "*.vbs", "*.js", "*.vhd", "*.bak", "*.wbcat", "*.bkf" , "*.backup*", "*.dsk", "*.win") | stats values(TargetFilename) as deleted_files min(_time) as firstTime max(_time) as lastTime count by Computer user EventCode Image ProcessID |where count >=100 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_high_file_deletion_frequency_filter` [ESCU - Windows Hunting System Account Targeting Lsass - Rule] action.escu = 0 @@ -35547,6 +36425,166 @@ realtime_schedule = 0 is_visible = false search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name="*.sys*" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.file_hash | `drop_dm_object_name(Filesystem)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `windows_system_file_on_disk_filter` +[ESCU - Windows System LogOff Commandline - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytic identifies Windows commandlined to logoff a windows host machine. This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact, interrupt access, aid destruction of the system like wiping disk or inhibit system recovery. This TTP is a good pivot to check why application trigger this commandline which is not so common way to logoff a machine. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1529"], "nist": ["DE.CM"]} +action.escu.data_models = ["Endpoint"] +action.escu.eli5 = The following analytic identifies Windows commandlined to logoff a windows host machine. This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact, interrupt access, aid destruction of the system like wiping disk or inhibit system recovery. This TTP is a good pivot to check why application trigger this commandline which is not so common way to logoff a machine. +action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +action.escu.known_false_positives = Administrator may execute this commandline to trigger shutdown, logoff or restart the host machine. +action.escu.creation_date = 2022-07-27 +action.escu.modification_date = 2022-07-27 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Windows System LogOff Commandline - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] +action.escu.analytic_story = ["DarkCrystal RAT"] +action.risk = 1 +action.risk.param._risk_message = Process name $process_name$ is seen to execute logoff commandline on $dest$ +action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 56}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Windows System LogOff Commandline - Rule +action.correlationsearch.annotations = {"analytic_story": ["DarkCrystal RAT"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 80, "context": ["Source:Endpoint", "Stage:Execution"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1529"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = | tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe) Processes.process="*shutdown*" Processes.process="* /l*" Processes.process="* /t*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_system_logoff_commandline_filter` + +[ESCU - Windows System Reboot CommandLine - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytic identifies Windows commandlined to reboot a windows host machine. This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact, interrupt access, aid destruction of the system like wiping disk or inhibit system recovery. This TTP is a good pivot to check why application trigger this commandline which is not so common way to reboot a machine. Compare to shutdown and logoff shutdown.exe feature, reboot seen in some automation script like ansible to reboot the machine. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1529"], "nist": ["DE.CM"]} +action.escu.data_models = ["Endpoint"] +action.escu.eli5 = The following analytic identifies Windows commandlined to reboot a windows host machine. This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact, interrupt access, aid destruction of the system like wiping disk or inhibit system recovery. This TTP is a good pivot to check why application trigger this commandline which is not so common way to reboot a machine. Compare to shutdown and logoff shutdown.exe feature, reboot seen in some automation script like ansible to reboot the machine. +action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +action.escu.known_false_positives = Administrator may execute this commandline to trigger shutdown or restart the host machine. +action.escu.creation_date = 2022-07-27 +action.escu.modification_date = 2022-07-27 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Windows System Reboot CommandLine - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] +action.escu.analytic_story = ["DarkCrystal RAT"] +action.risk = 1 +action.risk.param._risk_message = Process $process_name$ that executed reboot via commandline on $dest$ +action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 30}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Windows System Reboot CommandLine - Rule +action.correlationsearch.annotations = {"analytic_story": ["DarkCrystal RAT"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Execution"], "impact": 60, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1529"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = | tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe) Processes.process="*shutdown*" Processes.process="* /r*" Processes.process="* /t*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_system_reboot_commandline_filter` + +[ESCU - Windows System Shutdown CommandLine - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytic identifies Windows commandlined to shutdown a windows host machine. This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact, interrupt access, aid destruction of the system like wiping disk or inhibit system recovery. This TTP is a good pivot to check why application trigger this commandline which is not so common way to shutdown a machine. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1529"], "nist": ["DE.CM"]} +action.escu.data_models = ["Endpoint"] +action.escu.eli5 = The following analytic identifies Windows commandlined to shutdown a windows host machine. This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact, interrupt access, aid destruction of the system like wiping disk or inhibit system recovery. This TTP is a good pivot to check why application trigger this commandline which is not so common way to shutdown a machine. +action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +action.escu.known_false_positives = Administrator may execute this commandline to trigger shutdown or restart the host machine. +action.escu.creation_date = 2022-07-27 +action.escu.modification_date = 2022-07-27 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Windows System Shutdown CommandLine - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] +action.escu.analytic_story = ["DarkCrystal RAT"] +action.risk = 1 +action.risk.param._risk_message = Process $process_name$ seen to execute shutdown via commandline on $dest$ +action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 49}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Windows System Shutdown CommandLine - Rule +action.correlationsearch.annotations = {"analytic_story": ["DarkCrystal RAT"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 70, "context": ["Source:Endpoint", "Stage:Execution"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1529"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = | tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe) Processes.process="*shutdown*" Processes.process="* /s*" Processes.process="* /t*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_system_shutdown_commandline_filter` + +[ESCU - Windows System Time Discovery W32tm Delay - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytic identifies DCRat delay time tactics using w32tm. This technique was seen in DCRAT malware where it uses stripchart function of w32tm.exe application to delay the execution of its payload like c2 communication , beaconing and execution. This anomaly detection may help the analyst to check other possible event like the process who execute this command that may lead to DCRat attack. +action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1124"], "nist": ["DE.CM"]} +action.escu.data_models = ["Endpoint"] +action.escu.eli5 = The following analytic identifies DCRat delay time tactics using w32tm. This technique was seen in DCRAT malware where it uses stripchart function of w32tm.exe application to delay the execution of its payload like c2 communication , beaconing and execution. This anomaly detection may help the analyst to check other possible event like the process who execute this command that may lead to DCRat attack. +action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of wermgr.exe may be used. +action.escu.known_false_positives = unknown +action.escu.creation_date = 2022-07-28 +action.escu.modification_date = 2022-07-28 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Windows System Time Discovery W32tm Delay - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] +action.escu.analytic_story = ["DarkCrystal RAT"] +action.risk = 1 +action.risk.param._risk_message = Process name w32tm.exe is using suspcicious command line arguments $process$ on host $dest$. +action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 36}] +action.risk.param._risk_score = 0 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Windows System Time Discovery W32tm Delay - Rule +action.correlationsearch.annotations = {"analytic_story": ["DarkCrystal RAT"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 60, "context": ["Source:Endpoint", "Stage:Execution"], "impact": 60, "kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1124"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = | tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = w32tm.exe Processes.process= "* /stripchart *" Processes.process= "* /computer:localhost *" Processes.process= "* /period:*" Processes.process= "* /dataonly *" Processes.process= "* /samples:*" by Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_system_time_discovery_w32tm_delay_filter` + [ESCU - Windows Terminating Lsass Process - Rule] action.escu = 0 action.escu.enabled = 1 @@ -35937,7 +36975,7 @@ action.escu.full_search_name = ESCU - Winword Spawning Cmd - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Spearphishing Attachments"] +action.escu.analytic_story = ["Spearphishing Attachments", "DarkCrystal RAT"] action.risk = 1 action.risk.param._risk_message = $parent_process_name$ on $dest$ by $user$ launched command: $process_name$ which is very common in spearphishing attacks. action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 70}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 70}, {"threat_object_field": "process_name", "threat_object_type": "process"}] @@ -35948,7 +36986,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Winword Spawning Cmd - Rule -action.correlationsearch.annotations = {"analytic_story": ["Spearphishing Attachments"], "confidence": 100, "context": ["Source:Endpoint", "Stage:Initial Access"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1566", "T1566.001"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}, {"name": "user", "role": ["Victim"], "type": "User"}, {"name": "process_name", "role": ["Target"], "type": "Process"}]} +action.correlationsearch.annotations = {"analytic_story": ["Spearphishing Attachments", "DarkCrystal RAT"], "confidence": 100, "context": ["Source:Endpoint", "Stage:Initial Access"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1566", "T1566.001"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}, {"name": "user", "role": ["Victim"], "type": "User"}, {"name": "process_name", "role": ["Target"], "type": "Process"}]} schedule_window = auto action.notable = 1 action.notable.param.nes_fields = user,dest @@ -35983,7 +37021,7 @@ action.escu.full_search_name = ESCU - Winword Spawning PowerShell - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Spearphishing Attachments"] +action.escu.analytic_story = ["Spearphishing Attachments", "DarkCrystal RAT"] action.risk = 1 action.risk.param._risk_message = $parent_process_name$ on $dest$ by $user$ launched the following powershell process: $process_name$ which is very common in spearphishing attacks action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 70}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 70}, {"threat_object_field": "process_name", "threat_object_type": "process"}] @@ -35994,7 +37032,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Winword Spawning PowerShell - Rule -action.correlationsearch.annotations = {"analytic_story": ["Spearphishing Attachments"], "confidence": 100, "context": ["Source:Endpoint", "Stage:Initial Access"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1566", "T1566.001"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}, {"name": "user", "role": ["Victim"], "type": "User"}, {"name": "process_name", "role": ["Target"], "type": "Process"}]} +action.correlationsearch.annotations = {"analytic_story": ["Spearphishing Attachments", "DarkCrystal RAT"], "confidence": 100, "context": ["Source:Endpoint", "Stage:Initial Access"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1566", "T1566.001"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}, {"name": "user", "role": ["Victim"], "type": "User"}, {"name": "process_name", "role": ["Target"], "type": "Process"}]} schedule_window = auto action.notable = 1 action.notable.param.nes_fields = user,dest @@ -38973,7 +40011,7 @@ action.escu.full_search_name = ESCU - Suspicious Curl Network Connection - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] -action.escu.analytic_story = ["Silver Sparrow", "Ingress Tool Transfer"] +action.escu.analytic_story = ["Silver Sparrow", "Ingress Tool Transfer", "Linux Living Off The Land"] action.risk = 1 action.risk.param._risk_message = tbd action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}] @@ -38984,7 +40022,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Suspicious Curl Network Connection - Rule -action.correlationsearch.annotations = {"analytic_story": ["Silver Sparrow", "Ingress Tool Transfer"], "confidence": 50, "impact": 50, "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1105"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}]} +action.correlationsearch.annotations = {"analytic_story": ["Silver Sparrow", "Ingress Tool Transfer", "Linux Living Off The Land"], "confidence": 50, "impact": 50, "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1105"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto action.notable = 1 action.notable.param.nes_fields = user,dest diff --git a/dist/escu/default/transforms.conf b/dist/escu/default/transforms.conf index 59d49d5004..8cf9582b48 100644 --- a/dist/escu/default/transforms.conf +++ b/dist/escu/default/transforms.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2022-07-19T21:28:12 UTC +# On Date: 2022-07-28T22:42:05 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/dist/escu/default/workflow_actions.conf b/dist/escu/default/workflow_actions.conf index 256e1a8073..c55c2599a1 100644 --- a/dist/escu/default/workflow_actions.conf +++ b/dist/escu/default/workflow_actions.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2022-07-19T21:28:12 UTC +# On Date: 2022-07-28T22:42:05 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/docs/_pages/detections.md b/docs/_pages/detections.md index 34d700ec51..4064f6c8c6 100644 --- a/docs/_pages/detections.md +++ b/docs/_pages/detections.md @@ -19,6 +19,12 @@ sidebar: | [AWS CreateAccessKey](/cloud/aws_createaccesskey/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [AWS CreateLoginProfile](/cloud/aws_createloginprofile/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [AWS Cross Account Activity From Previously Unseen Account](/cloud/aws_cross_account_activity_from_previously_unseen_account/) | None | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [AWS Defense Evasion Delete CloudWatch Log Group](/cloud/aws_defense_evasion_delete_cloudwatch_log_group/) | [Impair Defenses](/tags/#impair-defenses), [Disable Cloud Logs](/tags/#disable-cloud-logs) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [AWS Defense Evasion Delete Cloudtrail](/cloud/aws_defense_evasion_delete_cloudtrail/) | [Disable Cloud Logs](/tags/#disable-cloud-logs), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [AWS Defense Evasion Impair Security Services](/cloud/aws_defense_evasion_impair_security_services/) | [Disable Cloud Logs](/tags/#disable-cloud-logs), [Impair Defenses](/tags/#impair-defenses) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [AWS Defense Evasion PutBucketLifecycle](/cloud/aws_defense_evasion_putbucketlifecycle/) | [Disable Cloud Logs](/tags/#disable-cloud-logs), [Impair Defenses](/tags/#impair-defenses) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [AWS Defense Evasion Stop Logging Cloudtrail](/cloud/aws_defense_evasion_stop_logging_cloudtrail/) | [Disable Cloud Logs](/tags/#disable-cloud-logs), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [AWS Defense Evasion Update Cloudtrail](/cloud/aws_defense_evasion_update_cloudtrail/) | [Impair Defenses](/tags/#impair-defenses), [Disable Cloud Logs](/tags/#disable-cloud-logs) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [AWS Detect Users creating keys with encrypt policy without MFA](/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [AWS Detect Users with KMS keys performing encryption S3](/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [AWS ECR Container Scanning Findings High](/cloud/aws_ecr_container_scanning_findings_high/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | @@ -69,6 +75,12 @@ sidebar: | [Attempt To Stop Security Service](/endpoint/attempt_to_stop_security_service/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Auto Admin Logon Registry Entry](/endpoint/auto_admin_logon_registry_entry/) | [Credentials in Registry](/tags/#credentials-in-registry), [Unsecured Credentials](/tags/#unsecured-credentials) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [Azure AD Authentication Failed During MFA Challenge](/cloud/azure_ad_authentication_failed_during_mfa_challenge/) | [Valid Accounts](/tags/#valid-accounts), [Cloud Accounts](/tags/#cloud-accounts), [Multi-Factor Authentication Request Generation](/tags/#multi-factor-authentication-request-generation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [Azure AD Multiple Users Failing To Authenticate From Ip](/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip/) | [Brute Force](/tags/#brute-force), [Password Spraying](/tags/#password-spraying) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [Azure AD Successful PowerShell Authentication](/cloud/azure_ad_successful_powershell_authentication/) | [Valid Accounts](/tags/#valid-accounts), [Cloud Accounts](/tags/#cloud-accounts) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [Azure AD Successful Single-Factor Authentication](/cloud/azure_ad_successful_single-factor_authentication/) | [Security Account Manager](/tags/#security-account-manager) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [Azure AD Unusual Number of Failed Authentications From Ip](/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip/) | [Brute Force](/tags/#brute-force), [Password Spraying](/tags/#password-spraying) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [Azure Active Directory High Risk Sign-in](/cloud/azure_active_directory_high_risk_sign-in/) | [Brute Force](/tags/#brute-force), [Password Spraying](/tags/#password-spraying) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [BCDEdit Failure Recovery Modification](/endpoint/bcdedit_failure_recovery_modification/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [BITS Job Persistence](/endpoint/bits_job_persistence/) | [BITS Jobs](/tags/#bits-jobs) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [BITSAdmin Download File](/endpoint/bitsadmin_download_file/) | [BITS Jobs](/tags/#bits-jobs), [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | @@ -434,8 +446,10 @@ sidebar: | [Linux At Allow Config File Creation](/endpoint/linux_at_allow_config_file_creation/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Linux At Application Execution](/endpoint/linux_at_application_execution/) | [At](/tags/#at), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Linux Change File Owner To Root](/endpoint/linux_change_file_owner_to_root/) | [Linux and Mac File and Directory Permissions Modification](/tags/#linux-and-mac-file-and-directory-permissions-modification), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [Linux Clipboard Data Copy](/endpoint/linux_clipboard_data_copy/) | [Clipboard Data](/tags/#clipboard-data) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Linux Common Process For Elevation Control](/endpoint/linux_common_process_for_elevation_control/) | [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Linux DD File Overwrite](/endpoint/linux_dd_file_overwrite/) | [Data Destruction](/tags/#data-destruction) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [Linux Decode Base64 to Shell](/endpoint/linux_decode_base64_to_shell/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Unix Shell](/tags/#unix-shell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Linux Deleting Critical Directory Using RM Command](/endpoint/linux_deleting_critical_directory_using_rm_command/) | [Data Destruction](/tags/#data-destruction) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Linux Deletion Of Cron Jobs](/endpoint/linux_deletion_of_cron_jobs/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Linux Deletion Of Init Daemon Script](/endpoint/linux_deletion_of_init_daemon_script/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | @@ -454,8 +468,11 @@ sidebar: | [Linux Install Kernel Module Using Modprobe Utility](/endpoint/linux_install_kernel_module_using_modprobe_utility/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Linux Iptables Firewall Modification](/endpoint/linux_iptables_firewall_modification/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Linux Java Spawning Shell](/endpoint/linux_java_spawning_shell/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [Linux Kernel Module Enumeration](/endpoint/linux_kernel_module_enumeration/) | [System Information Discovery](/tags/#system-information-discovery), [Rootkit](/tags/#rootkit) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Linux Kworker Process In Writable Process Path](/endpoint/linux_kworker_process_in_writable_process_path/) | [Masquerade Task or Service](/tags/#masquerade-task-or-service), [Masquerading](/tags/#masquerading) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Linux NOPASSWD Entry In Sudoers File](/endpoint/linux_nopasswd_entry_in_sudoers_file/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [Linux Obfuscated Files or Information Base64 Decode](/endpoint/linux_obfuscated_files_or_information_base64_decode/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [Linux Persistence and Privilege Escalation Risk Behavior](/endpoint/linux_persistence_and_privilege_escalation_risk_behavior/) | [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Correlation](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Linux Possible Access Or Modification Of sshd Config File](/endpoint/linux_possible_access_or_modification_of_sshd_config_file/) | [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Linux Possible Access To Credential Files](/endpoint/linux_possible_access_to_credential_files/) | [/etc/passwd and /etc/shadow](/tags/#/etc/passwd-and-/etc/shadow), [OS Credential Dumping](/tags/#os-credential-dumping) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Linux Possible Access To Sudoers File](/endpoint/linux_possible_access_to_sudoers_file/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | @@ -465,6 +482,8 @@ sidebar: | [Linux Possible Cronjob Modification With Editor](/endpoint/linux_possible_cronjob_modification_with_editor/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Linux Possible Ssh Key File Creation](/endpoint/linux_possible_ssh_key_file_creation/) | [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Linux Preload Hijack Library Calls](/endpoint/linux_preload_hijack_library_calls/) | [Dynamic Linker Hijacking](/tags/#dynamic-linker-hijacking), [Hijack Execution Flow](/tags/#hijack-execution-flow) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [Linux SSH Authorized Keys Modification](/endpoint/linux_ssh_authorized_keys_modification/) | [SSH Authorized Keys](/tags/#ssh-authorized-keys) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [Linux SSH Remote Services Script Execute](/endpoint/linux_ssh_remote_services_script_execute/) | [SSH](/tags/#ssh) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Linux Service File Created In Systemd Directory](/endpoint/linux_service_file_created_in_systemd_directory/) | [Systemd Timers](/tags/#systemd-timers), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Linux Service Restarted](/endpoint/linux_service_restarted/) | [Systemd Timers](/tags/#systemd-timers), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Linux Service Started Or Enabled](/endpoint/linux_service_started_or_enabled/) | [Systemd Timers](/tags/#systemd-timers), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | @@ -820,6 +839,7 @@ sidebar: | [Windows AdFind Exe](/endpoint/windows_adfind_exe/) | [Remote System Discovery](/tags/#remote-system-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Windows Application Layer Protocol RMS Radmin Tool Namedpipe](/endpoint/windows_application_layer_protocol_rms_radmin_tool_namedpipe/) | [Application Layer Protocol](/tags/#application-layer-protocol) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Windows Binary Proxy Execution Mavinject DLL Injection](/endpoint/windows_binary_proxy_execution_mavinject_dll_injection/) | [Mavinject](/tags/#mavinject), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [Windows Command Shell DCRat ForkBomb Payload](/endpoint/windows_command_shell_dcrat_forkbomb_payload/) | [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Windows Command and Scripting Interpreter Hunting Path Traversal](/endpoint/windows_command_and_scripting_interpreter_hunting_path_traversal/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Windows Command and Scripting Interpreter Path Traversal Exec](/endpoint/windows_command_and_scripting_interpreter_path_traversal_exec/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Windows Computer Account Created by Computer Account](/endpoint/windows_computer_account_created_by_computer_account/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | @@ -928,6 +948,10 @@ sidebar: | [Windows Service Initiation on Remote Endpoint](/endpoint/windows_service_initiation_on_remote_endpoint/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Windows Service Stop By Deletion](/endpoint/windows_service_stop_by_deletion/) | [Service Stop](/tags/#service-stop) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Windows System File on Disk](/endpoint/windows_system_file_on_disk/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [Windows System LogOff Commandline](/endpoint/windows_system_logoff_commandline/) | [System Shutdown/Reboot](/tags/#system-shutdown/reboot) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [Windows System Reboot CommandLine](/endpoint/windows_system_reboot_commandline/) | [System Shutdown/Reboot](/tags/#system-shutdown/reboot) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [Windows System Shutdown CommandLine](/endpoint/windows_system_shutdown_commandline/) | [System Shutdown/Reboot](/tags/#system-shutdown/reboot) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | +| [Windows System Time Discovery W32tm Delay](/endpoint/windows_system_time_discovery_w32tm_delay/) | [System Time Discovery](/tags/#system-time-discovery) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Windows Terminating Lsass Process](/endpoint/windows_terminating_lsass_process/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Windows Users Authenticate Using Explicit Credentials](/endpoint/windows_users_authenticate_using_explicit_credentials/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | | [Windows Valid Account With Never Expires Password](/endpoint/windows_valid_account_with_never_expires_password/) | [Service Stop](/tags/#service-stop) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | diff --git a/docs/_pages/stories.md b/docs/_pages/stories.md index 695c5a4275..477d0defa1 100644 --- a/docs/_pages/stories.md +++ b/docs/_pages/stories.md @@ -12,6 +12,7 @@ sidebar: | ----------- | ----------- |--------------| | [AWS Cross Account Activity](aws_cross_account_activity) | [Valid Accounts](/tags/#valid-accounts), [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material) | [Defense Evasion](/tags/#defense-evasion), [Initial Access](/tags/#initial-access), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | | [AWS Cryptomining](aws_cryptomining) | [Cloud Accounts](/tags/#cloud-accounts), [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | [Defense Evasion](/tags/#defense-evasion), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | +| [AWS Defense Evasion](aws_defense_evasion) | [Disable Cloud Logs](/tags/#disable-cloud-logs), [Impair Defenses](/tags/#impair-defenses) | [Defense Evasion](/tags/#defense-evasion) | | [AWS IAM Privilege Escalation](aws_iam_privilege_escalation) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts), [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account), [Cloud Infrastructure Discovery](/tags/#cloud-infrastructure-discovery), [Brute Force](/tags/#brute-force), [Account Manipulation](/tags/#account-manipulation), [Cloud Groups](/tags/#cloud-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | | [AWS Network ACL Activity](aws_network_acl_activity) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | [Defense Evasion](/tags/#defense-evasion) | | [AWS Security Hub Alerts](aws_security_hub_alerts) | None | None | @@ -26,6 +27,7 @@ sidebar: | [Asset Tracking](asset_tracking) | None | None | | [Atlassian Confluence Server and Data Center CVE-2022-26134](atlassian_confluence_server_and_data_center_cve-2022-26134) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application), [Server Software Component](/tags/#server-software-component) | [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence) | | [Azorult](azorult) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell), [Local Account](/tags/#local-account), [Create Account](/tags/#create-account), [Hidden Files and Directories](/tags/#hidden-files-and-directories), [Hide Artifacts](/tags/#hide-artifacts), [Bypass User Account Control](/tags/#bypass-user-account-control), [Service Stop](/tags/#service-stop), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Account Access Removal](/tags/#account-access-removal), [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution), [Masquerading](/tags/#masquerading), [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification), [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups), [System Network Connections Discovery](/tags/#system-network-connections-discovery), [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Credentials from Web Browsers](/tags/#credentials-from-web-browsers), [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job), [Application Layer Protocol](/tags/#application-layer-protocol), [IP Addresses](/tags/#ip-addresses), [Gather Victim Network Information](/tags/#gather-victim-network-information), [Modify Registry](/tags/#modify-registry), [PowerShell](/tags/#powershell), [Remote Access Software](/tags/#remote-access-software) | [Command And Control](/tags/#command-and-control), [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Impact](/tags/#impact), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation), [Reconnaissance](/tags/#reconnaissance) | +| [Azure Active Directory Account Takeover](azure_active_directory_account_takeover) | [Brute Force](/tags/#brute-force), [Password Spraying](/tags/#password-spraying), [Valid Accounts](/tags/#valid-accounts), [Cloud Accounts](/tags/#cloud-accounts), [Multi-Factor Authentication Request Generation](/tags/#multi-factor-authentication-request-generation), [Security Account Manager](/tags/#security-account-manager) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | | [BITS Jobs](bits_jobs) | [BITS Jobs](/tags/#bits-jobs), [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | [Command And Control](/tags/#command-and-control), [Defense Evasion](/tags/#defense-evasion), [Persistence](/tags/#persistence) | | [Baron Samedit CVE-2021-3156](baron_samedit_cve-2021-3156) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [Privilege Escalation](/tags/#privilege-escalation) | | [BlackMatter Ransomware](blackmatter_ransomware) | [Credentials in Registry](/tags/#credentials-in-registry), [Unsecured Credentials](/tags/#unsecured-credentials), [Inhibit System Recovery](/tags/#inhibit-system-recovery), [Defacement](/tags/#defacement), [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | [Credential Access](/tags/#credential-access), [Impact](/tags/#impact) | @@ -45,6 +47,7 @@ sidebar: | [DHS Report TA18-074A](dhs_report_ta18-074a) | [PowerShell](/tags/#powershell), [Windows Command Shell](/tags/#windows-command-shell), [Local Account](/tags/#local-account), [Create Account](/tags/#create-account), [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses), [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job), [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file), [Modify Registry](/tags/#modify-registry), [File Transfer Protocols](/tags/#file-transfer-protocols), [Application Layer Protocol](/tags/#application-layer-protocol) | [Command And Control](/tags/#command-and-control), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | | [DNS Amplification Attacks](dns_amplification_attacks) | [Network Denial of Service](/tags/#network-denial-of-service), [Reflection Amplification](/tags/#reflection-amplification) | [Impact](/tags/#impact) | | [DNS Hijacking](dns_hijacking) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [DNS](/tags/#dns), [Drive-by Compromise](/tags/#drive-by-compromise) | [Command And Control](/tags/#command-and-control), [Exfiltration](/tags/#exfiltration), [Initial Access](/tags/#initial-access) | +| [DarkCrystal RAT](darkcrystal_rat) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Windows Command Shell](/tags/#windows-command-shell), [Masquerading](/tags/#masquerading), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta), [Create or Modify System Process](/tags/#create-or-modify-system-process), [IP Addresses](/tags/#ip-addresses), [Gather Victim Network Information](/tags/#gather-victim-network-information), [Data Destruction](/tags/#data-destruction), [System Shutdown/Reboot](/tags/#system-shutdown/reboot), [System Time Discovery](/tags/#system-time-discovery) | [Command And Control](/tags/#command-and-control), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Impact](/tags/#impact), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation), [Reconnaissance](/tags/#reconnaissance) | | [DarkSide Ransomware](darkside_ransomware) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping), [BITS Jobs](/tags/#bits-jobs), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [CMSTP](/tags/#cmstp), [Process Injection](/tags/#process-injection), [Inhibit System Recovery](/tags/#inhibit-system-recovery), [LSASS Memory](/tags/#lsass-memory), [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Automated Exfiltration](/tags/#automated-exfiltration), [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution), [Data Encrypted for Impact](/tags/#data-encrypted-for-impact), [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Command And Control](/tags/#command-and-control), [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Exfiltration](/tags/#exfiltration), [Impact](/tags/#impact), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | | [Data Destruction](data_destruction) | [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Masquerading](/tags/#masquerading), [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Modify Registry](/tags/#modify-registry), [Disk Structure Wipe](/tags/#disk-structure-wipe), [Disk Wipe](/tags/#disk-wipe) | [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Impact](/tags/#impact), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | | [Data Exfiltration](data_exfiltration) | [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account), [Email Collection](/tags/#email-collection), [Email Forwarding Rule](/tags/#email-forwarding-rule), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol), [Local Email Collection](/tags/#local-email-collection), [Phishing](/tags/#phishing), [Exfiltration Over C2 Channel](/tags/#exfiltration-over-c2-channel), [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol) | [Collection](/tags/#collection), [Exfiltration](/tags/#exfiltration), [Initial Access](/tags/#initial-access) | @@ -74,9 +77,11 @@ sidebar: | [Kubernetes Scanning Activity](kubernetes_scanning_activity) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | [Discovery](/tags/#discovery) | | [Kubernetes Sensitive Object Access Activity](kubernetes_sensitive_object_access_activity) | None | None | | [Kubernetes Sensitive Role Activity](kubernetes_sensitive_role_activity) | None | None | +| [Linux Living Off The Land](linux_living_off_the_land) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job), [At](/tags/#at), [Linux and Mac File and Directory Permissions Modification](/tags/#linux-and-mac-file-and-directory-permissions-modification), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Clipboard Data](/tags/#clipboard-data), [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Unix Shell](/tags/#unix-shell), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation), [Systemd Timers](/tags/#systemd-timers), [SSH](/tags/#ssh) | [Collection](/tags/#collection), [Command And Control](/tags/#command-and-control), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | | [Linux Persistence Techniques](linux_persistence_techniques) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job), [Local Account](/tags/#local-account), [Create Account](/tags/#create-account), [At](/tags/#at), [Linux and Mac File and Directory Permissions Modification](/tags/#linux-and-mac-file-and-directory-permissions-modification), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [RC Scripts](/tags/#rc-scripts), [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Unix Shell Configuration Modification](/tags/#unix-shell-configuration-modification), [Event Triggered Execution](/tags/#event-triggered-execution), [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation), [/etc/passwd and /etc/shadow](/tags/#/etc/passwd-and-/etc/shadow), [OS Credential Dumping](/tags/#os-credential-dumping), [Dynamic Linker Hijacking](/tags/#dynamic-linker-hijacking), [Hijack Execution Flow](/tags/#hijack-execution-flow), [Systemd Timers](/tags/#systemd-timers), [Data Destruction](/tags/#data-destruction) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Impact](/tags/#impact), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | | [Linux Post-Exploitation](linux_post-exploitation) | [Unix Shell](/tags/#unix-shell) | [Execution](/tags/#execution) | | [Linux Privilege Escalation](linux_privilege_escalation) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job), [Local Account](/tags/#local-account), [Create Account](/tags/#create-account), [At](/tags/#at), [Linux and Mac File and Directory Permissions Modification](/tags/#linux-and-mac-file-and-directory-permissions-modification), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [RC Scripts](/tags/#rc-scripts), [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Unix Shell Configuration Modification](/tags/#unix-shell-configuration-modification), [Event Triggered Execution](/tags/#event-triggered-execution), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation), [/etc/passwd and /etc/shadow](/tags/#/etc/passwd-and-/etc/shadow), [OS Credential Dumping](/tags/#os-credential-dumping), [Dynamic Linker Hijacking](/tags/#dynamic-linker-hijacking), [Hijack Execution Flow](/tags/#hijack-execution-flow), [Systemd Timers](/tags/#systemd-timers), [Data Destruction](/tags/#data-destruction) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Impact](/tags/#impact), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | +| [Linux Rootkit](linux_rootkit) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [System Information Discovery](/tags/#system-information-discovery), [Rootkit](/tags/#rootkit) | [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | | [Living Off The Land](living_off_the_land) | [BITS Jobs](/tags/#bits-jobs), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Deobfuscate/Decode Files or Information](/tags/#deobfuscate/decode-files-or-information), [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Control Panel](/tags/#control-panel), [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping), [Compiled HTML File](/tags/#compiled-html-file), [Mshta](/tags/#mshta), [Regsvcs/Regasm](/tags/#regsvcs/regasm), [Regsvr32](/tags/#regsvr32), [Rundll32](/tags/#rundll32), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses), [LSASS Memory](/tags/#lsass-memory), [Security Account Manager](/tags/#security-account-manager), [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application), [Unix Shell](/tags/#unix-shell), [Plist File Modification](/tags/#plist-file-modification), [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model), [MMC](/tags/#mmc), [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness), [Hijack Execution Flow](/tags/#hijack-execution-flow), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Process Injection](/tags/#process-injection), [Modify Registry](/tags/#modify-registry), [Scheduled Task/Job](/tags/#scheduled-task/job), [At](/tags/#at), [Scheduled Task](/tags/#scheduled-task), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service), [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild), [Mavinject](/tags/#mavinject), [Indirect Command Execution](/tags/#indirect-command-execution), [InstallUtil](/tags/#installutil), [Windows Management Instrumentation Event Subscription](/tags/#windows-management-instrumentation-event-subscription), [Odbcconf](/tags/#odbcconf) | [Command And Control](/tags/#command-and-control), [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Initial Access](/tags/#initial-access), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | | [Local Privilege Escalation With KrbRelayUp](local_privilege_escalation_with_krbrelayup) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Windows Service](/tags/#windows-service) | [Credential Access](/tags/#credential-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | | [Log4Shell CVE-2021-44228](log4shell_cve-2021-44228) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Windows Command Shell](/tags/#windows-command-shell), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Command And Control](/tags/#command-and-control), [Execution](/tags/#execution), [Initial Access](/tags/#initial-access) | diff --git a/docs/_posts/2017-09-12-extended_period_without_successful_netbackup_backups.md b/docs/_posts/2017-09-12-extended_period_without_successful_netbackup_backups.md index d485eb70b4..64449b47a3 100644 --- a/docs/_posts/2017-09-12-extended_period_without_successful_netbackup_backups.md +++ b/docs/_posts/2017-09-12-extended_period_without_successful_netbackup_backups.md @@ -99,8 +99,8 @@ This search returns a list of hosts that have not successfully completed a backu #### Macros The SPL above uses the following Macros: -* [netbackup](https://github.com/splunk/security_content/blob/develop/macros/netbackup.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [netbackup](https://github.com/splunk/security_content/blob/develop/macros/netbackup.yml) > :information_source: > **extended_period_without_successful_netbackup_backups_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2017-09-12-unsuccessful_netbackup_backups.md b/docs/_posts/2017-09-12-unsuccessful_netbackup_backups.md index 31a66e2bfa..14cc93f2cc 100644 --- a/docs/_posts/2017-09-12-unsuccessful_netbackup_backups.md +++ b/docs/_posts/2017-09-12-unsuccessful_netbackup_backups.md @@ -98,8 +98,8 @@ This search gives you the hosts where a backup was attempted and then failed. #### Macros The SPL above uses the following Macros: -* [netbackup](https://github.com/splunk/security_content/blob/develop/macros/netbackup.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [netbackup](https://github.com/splunk/security_content/blob/develop/macros/netbackup.yml) > :information_source: > **unsuccessful_netbackup_backups_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2017-09-23-monitor_dns_for_brand_abuse.md b/docs/_posts/2017-09-23-monitor_dns_for_brand_abuse.md index 351df8d65f..5860da8991 100644 --- a/docs/_posts/2017-09-23-monitor_dns_for_brand_abuse.md +++ b/docs/_posts/2017-09-23-monitor_dns_for_brand_abuse.md @@ -95,8 +95,8 @@ This search looks for DNS requests for faux domains similar to the domains that #### Macros The SPL above uses the following Macros: -* [brand_abuse_dns](https://github.com/splunk/security_content/blob/develop/macros/brand_abuse_dns.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [brand_abuse_dns](https://github.com/splunk/security_content/blob/develop/macros/brand_abuse_dns.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md b/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md index e9ed6c984d..051f22e654 100644 --- a/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md +++ b/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md @@ -100,8 +100,8 @@ This search looks for Web requests to faux domains similar to the one that you w #### Macros The SPL above uses the following Macros: -* [brand_abuse_web](https://github.com/splunk/security_content/blob/develop/macros/brand_abuse_web.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [brand_abuse_web](https://github.com/splunk/security_content/blob/develop/macros/brand_abuse_web.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md b/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md index 5604b56488..7ddc9ec68b 100644 --- a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md +++ b/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md @@ -114,8 +114,8 @@ This search looks for the creation of WMI permanent event subscriptions. #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wmi](https://github.com/splunk/security_content/blob/develop/macros/wmi.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **wmi_permanent_event_subscription_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md b/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md index 71d6f444e4..02ca8ce578 100644 --- a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md +++ b/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md @@ -113,8 +113,8 @@ This search looks for the creation of WMI temporary event subscriptions. #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wmi](https://github.com/splunk/security_content/blob/develop/macros/wmi.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **wmi_temporary_event_subscription_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2018-12-03-remote_wmi_command_attempt.md b/docs/_posts/2018-12-03-remote_wmi_command_attempt.md index e330d0107c..cc8964e565 100644 --- a/docs/_posts/2018-12-03-remote_wmi_command_attempt.md +++ b/docs/_posts/2018-12-03-remote_wmi_command_attempt.md @@ -110,9 +110,9 @@ The following analytic identifies usage of `wmic.exe` spawning a local or remote #### Macros The SPL above uses the following Macros: -* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) > :information_source: > **remote_wmi_command_attempt_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2018-12-06-suspicious_java_classes.md b/docs/_posts/2018-12-06-suspicious_java_classes.md index 6fa26f2d66..3e1d527e90 100644 --- a/docs/_posts/2018-12-06-suspicious_java_classes.md +++ b/docs/_posts/2018-12-06-suspicious_java_classes.md @@ -102,8 +102,8 @@ This search looks for suspicious Java classes that are often used to exploit rem #### Macros The SPL above uses the following Macros: -* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) > :information_source: > **suspicious_java_classes_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2019-02-27-detect_mimikatz_via_powershell_and_eventcode_4703.md b/docs/_posts/2019-02-27-detect_mimikatz_via_powershell_and_eventcode_4703.md index 47ee78a2f2..dae186beec 100644 --- a/docs/_posts/2019-02-27-detect_mimikatz_via_powershell_and_eventcode_4703.md +++ b/docs/_posts/2019-02-27-detect_mimikatz_via_powershell_and_eventcode_4703.md @@ -112,8 +112,8 @@ This search looks for PowerShell requesting privileges consistent with credentia #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **detect_mimikatz_via_powershell_and_eventcode_4703_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2019-04-25-suspicious_file_write.md b/docs/_posts/2019-04-25-suspicious_file_write.md index d7830d2ff0..dd9f2854a8 100644 --- a/docs/_posts/2019-04-25-suspicious_file_write.md +++ b/docs/_posts/2019-04-25-suspicious_file_write.md @@ -99,9 +99,9 @@ The search looks for files created with names that have been linked to malicious #### Macros The SPL above uses the following Macros: -* [suspicious_writes](https://github.com/splunk/security_content/blob/develop/macros/suspicious_writes.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [suspicious_writes](https://github.com/splunk/security_content/blob/develop/macros/suspicious_writes.yml) > :information_source: > **suspicious_file_write_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md b/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md index 9f92f7ce49..6a0338fdad 100644 --- a/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md +++ b/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md @@ -113,8 +113,8 @@ Detect the usage of comsvcs.dll for dumping the lsass process. #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md index f8e8536bb0..1309557b22 100644 --- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md +++ b/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md @@ -103,8 +103,8 @@ This search provides information of unauthenticated requests via user agent, and #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [aws_cloudwatchlogs_eks](https://github.com/splunk/security_content/blob/develop/macros/aws_cloudwatchlogs_eks.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **amazon_eks_kubernetes_cluster_scan_detection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md index a963f0417f..881939da87 100644 --- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md +++ b/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md @@ -103,8 +103,8 @@ This search provides detection information on unauthenticated requests against K #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [aws_cloudwatchlogs_eks](https://github.com/splunk/security_content/blob/develop/macros/aws_cloudwatchlogs_eks.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **amazon_eks_kubernetes_pod_scan_detection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-04-15-gcp_kubernetes_cluster_scan_detection.md b/docs/_posts/2020-04-15-gcp_kubernetes_cluster_scan_detection.md index fb4a709347..3937632e2a 100644 --- a/docs/_posts/2020-04-15-gcp_kubernetes_cluster_scan_detection.md +++ b/docs/_posts/2020-04-15-gcp_kubernetes_cluster_scan_detection.md @@ -102,8 +102,8 @@ This search provides information of unauthenticated requests via user agent, and #### Macros The SPL above uses the following Macros: -* [google_gcp_pubsub_message](https://github.com/splunk/security_content/blob/develop/macros/google_gcp_pubsub_message.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [google_gcp_pubsub_message](https://github.com/splunk/security_content/blob/develop/macros/google_gcp_pubsub_message.yml) > :information_source: > **gcp_kubernetes_cluster_scan_detection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md index 6314c7448b..1164dc80d2 100644 --- a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md +++ b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md @@ -113,8 +113,8 @@ This search looks for child processes spawned by zoom.exe or zoom.us that has no #### Macros The SPL above uses the following Macros: -* [previously_seen_zoom_child_processes_window](https://github.com/splunk/security_content/blob/develop/macros/previously_seen_zoom_child_processes_window.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [previously_seen_zoom_child_processes_window](https://github.com/splunk/security_content/blob/develop/macros/previously_seen_zoom_child_processes_window.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2020-07-06-windows_event_log_cleared.md b/docs/_posts/2020-07-06-windows_event_log_cleared.md index 57187c0ff4..e77d0c4535 100644 --- a/docs/_posts/2020-07-06-windows_event_log_cleared.md +++ b/docs/_posts/2020-07-06-windows_event_log_cleared.md @@ -115,9 +115,9 @@ The following analytic utilizes Windows Security Event ID 1102 or System log eve #### Macros The SPL above uses the following Macros: -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) > :information_source: > **windows_event_log_cleared_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-07-08-detect_new_local_admin_account.md b/docs/_posts/2020-07-08-detect_new_local_admin_account.md index 3e6512d9d8..b14f43e277 100644 --- a/docs/_posts/2020-07-08-detect_new_local_admin_account.md +++ b/docs/_posts/2020-07-08-detect_new_local_admin_account.md @@ -113,8 +113,8 @@ This search looks for newly created accounts that have been elevated to local ad #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **detect_new_local_admin_account_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-07-21-detect_dns_requests_to_phishing_sites_leveraging_evilginx2.md b/docs/_posts/2020-07-21-detect_dns_requests_to_phishing_sites_leveraging_evilginx2.md index 1a5dc12da3..680f315e32 100644 --- a/docs/_posts/2020-07-21-detect_dns_requests_to_phishing_sites_leveraging_evilginx2.md +++ b/docs/_posts/2020-07-21-detect_dns_requests_to_phishing_sites_leveraging_evilginx2.md @@ -123,14 +123,14 @@ This search looks for DNS requests for phishing domains that are leveraging Evil #### Macros The SPL above uses the following Macros: -* [evilginx_phishlets_google](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_google.yml) -* [evilginx_phishlets_github](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_github.yml) * [evilginx_phishlets_facebook](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_facebook.yml) +* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) * [evilginx_phishlets_0365](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_0365.yml) * [evilginx_phishlets_aws](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_aws.yml) -* [evilginx_phishlets_amazon](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_amazon.yml) * [evilginx_phishlets_outlook](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_outlook.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [evilginx_phishlets_github](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_github.yml) +* [evilginx_phishlets_google](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_google.yml) +* [evilginx_phishlets_amazon](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_amazon.yml) > :information_source: > **detect_dns_requests_to_phishing_sites_leveraging_evilginx2_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-07-21-ec2_instance_modified_with_previously_unseen_user.md b/docs/_posts/2020-07-21-ec2_instance_modified_with_previously_unseen_user.md index 7706e0d302..be6ba9b32f 100644 --- a/docs/_posts/2020-07-21-ec2_instance_modified_with_previously_unseen_user.md +++ b/docs/_posts/2020-07-21-ec2_instance_modified_with_previously_unseen_user.md @@ -119,8 +119,8 @@ This search looks for EC2 instances being modified by users who have not previou #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [ec2_modification_api_calls](https://github.com/splunk/security_content/blob/develop/macros/ec2_modification_api_calls.yml) * [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) +* [ec2_modification_api_calls](https://github.com/splunk/security_content/blob/develop/macros/ec2_modification_api_calls.yml) > :information_source: > **ec2_instance_modified_with_previously_unseen_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md b/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md index 3f454963e2..97977c0cfd 100644 --- a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md +++ b/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md @@ -118,8 +118,8 @@ This search looks for the first and last time a Windows service is seen running #### Macros The SPL above uses the following Macros: -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) * [previously_seen_windows_services_window](https://github.com/splunk/security_content/blob/develop/macros/previously_seen_windows_services_window.yml) +* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) > :information_source: > **first_time_seen_running_windows_service_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md b/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md index d5e6c456dc..6ae13fd45b 100644 --- a/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md +++ b/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md @@ -117,8 +117,8 @@ This search looks for PowerShell processes started with parameters used to bypas #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) > :information_source: > **malicious_powershell_process_-_execution_policy_bypass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. @@ -147,6 +147,7 @@ There may be legitimate reasons to bypass the PowerShell execution policy. The P #### Associated Analytic story * [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) * [HAFNIUM Group](/stories/hafnium_group) +* [DarkCrystal RAT](/stories/darkcrystal_rat) diff --git a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md index 85c2cd05e5..ca52418ecb 100644 --- a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md +++ b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md @@ -119,8 +119,8 @@ This search detects Okta login failures due to bad credentials for multiple user #### Macros The SPL above uses the following Macros: -* [okta](https://github.com/splunk/security_content/blob/develop/macros/okta.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [okta](https://github.com/splunk/security_content/blob/develop/macros/okta.yml) > :information_source: > **multiple_okta_users_with_invalid_credentials_from_the_same_ip_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md index caa4fab851..6df573f907 100644 --- a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md +++ b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md @@ -117,8 +117,8 @@ Detect failed Okta SSO events #### Macros The SPL above uses the following Macros: -* [okta](https://github.com/splunk/security_content/blob/develop/macros/okta.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [okta](https://github.com/splunk/security_content/blob/develop/macros/okta.yml) > :information_source: > **okta_failed_sso_attempts_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md index 212ff4ee2b..b931e0738d 100644 --- a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md +++ b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md @@ -118,8 +118,8 @@ This search detects logins from the same user from different cities in a 24 hour #### Macros The SPL above uses the following Macros: -* [okta](https://github.com/splunk/security_content/blob/develop/macros/okta.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [okta](https://github.com/splunk/security_content/blob/develop/macros/okta.yml) > :information_source: > **okta_user_logins_from_multiple_cities_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md index a9d2a15203..7032505da1 100644 --- a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md +++ b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md @@ -117,8 +117,8 @@ This search looks for emails that have attachments with suspicious file extensio #### Macros The SPL above uses the following Macros: -* [suspicious_email_attachments](https://github.com/splunk/security_content/blob/develop/macros/suspicious_email_attachments.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [suspicious_email_attachments](https://github.com/splunk/security_content/blob/develop/macros/suspicious_email_attachments.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md index ed73e8c274..906d51e1ca 100644 --- a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md +++ b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md @@ -117,8 +117,8 @@ This search detects SIGRed via Splunk Stream. #### Macros The SPL above uses the following Macros: -* [stream_dns](https://github.com/splunk/security_content/blob/develop/macros/stream_dns.yml) * [stream_tcp](https://github.com/splunk/security_content/blob/develop/macros/stream_tcp.yml) +* [stream_dns](https://github.com/splunk/security_content/blob/develop/macros/stream_dns.yml) > :information_source: > **detect_windows_dns_sigred_via_splunk_stream_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md b/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md index f2146c230c..5d755ac2d1 100644 --- a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md +++ b/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md @@ -114,8 +114,8 @@ This search looks for cloud provisioning activities from previously unseen IP ad #### Macros The SPL above uses the following Macros: -* [previously_unseen_cloud_provisioning_activity_window](https://github.com/splunk/security_content/blob/develop/macros/previously_unseen_cloud_provisioning_activity_window.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [previously_unseen_cloud_provisioning_activity_window](https://github.com/splunk/security_content/blob/develop/macros/previously_unseen_cloud_provisioning_activity_window.yml) > :information_source: > **cloud_provisioning_activity_from_previously_unseen_ip_address_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md b/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md index b1d3ffc094..ec5531bf28 100644 --- a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md +++ b/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md @@ -116,8 +116,8 @@ This search looks for cloud provisioning activities from previously unseen regio #### Macros The SPL above uses the following Macros: -* [previously_unseen_cloud_provisioning_activity_window](https://github.com/splunk/security_content/blob/develop/macros/previously_unseen_cloud_provisioning_activity_window.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [previously_unseen_cloud_provisioning_activity_window](https://github.com/splunk/security_content/blob/develop/macros/previously_unseen_cloud_provisioning_activity_window.yml) > :information_source: > **cloud_provisioning_activity_from_previously_unseen_region_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md b/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md index c8a6f3ff8c..f0a1718ed9 100644 --- a/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md +++ b/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md @@ -116,8 +116,8 @@ This search looks for cloud provisioning activities from previously unseen citie #### Macros The SPL above uses the following Macros: -* [previously_unseen_cloud_provisioning_activity_window](https://github.com/splunk/security_content/blob/develop/macros/previously_unseen_cloud_provisioning_activity_window.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [previously_unseen_cloud_provisioning_activity_window](https://github.com/splunk/security_content/blob/develop/macros/previously_unseen_cloud_provisioning_activity_window.yml) > :information_source: > **cloud_provisioning_activity_from_previously_unseen_city_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md b/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md index 8afe9011b3..d7016c612e 100644 --- a/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md +++ b/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md @@ -117,8 +117,8 @@ This search looks for specific authentication events from the Windows Security E #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **detect_activity_related_to_pass_the_hash_attacks_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-11-09-common_ransomware_extensions.md b/docs/_posts/2020-11-09-common_ransomware_extensions.md index 875e9afa63..dc37dca253 100644 --- a/docs/_posts/2020-11-09-common_ransomware_extensions.md +++ b/docs/_posts/2020-11-09-common_ransomware_extensions.md @@ -109,9 +109,9 @@ The search looks for file modifications with extensions commonly used by Ransomw #### Macros The SPL above uses the following Macros: -* [ransomware_extensions](https://github.com/splunk/security_content/blob/develop/macros/ransomware_extensions.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [ransomware_extensions](https://github.com/splunk/security_content/blob/develop/macros/ransomware_extensions.yml) > :information_source: > **common_ransomware_extensions_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-11-09-common_ransomware_notes.md b/docs/_posts/2020-11-09-common_ransomware_notes.md index 9aa515ac82..02e4d5a45d 100644 --- a/docs/_posts/2020-11-09-common_ransomware_notes.md +++ b/docs/_posts/2020-11-09-common_ransomware_notes.md @@ -108,8 +108,8 @@ The search looks for files created with names matching those typically used in r #### Macros The SPL above uses the following Macros: -* [ransomware_notes](https://github.com/splunk/security_content/blob/develop/macros/ransomware_notes.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [ransomware_notes](https://github.com/splunk/security_content/blob/develop/macros/ransomware_notes.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md b/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md index c0b41eca2c..f3728f515c 100644 --- a/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md +++ b/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md @@ -113,8 +113,8 @@ This search looks for fast execution of processes used for system network config #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [system_network_configuration_discovery_tools](https://github.com/splunk/security_content/blob/develop/macros/system_network_configuration_discovery_tools.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md b/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md index 67a0109b7f..e8b58d02a8 100644 --- a/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md +++ b/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md @@ -113,10 +113,10 @@ This search looks for executions of cmd.exe spawned by a process that is often a #### Macros The SPL above uses the following Macros: -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) * [prohibited_apps_launching_cmd](https://github.com/splunk/security_content/blob/develop/macros/prohibited_apps_launching_cmd.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) > :information_source: > **detect_prohibited_applications_spawning_cmd_exe_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md b/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md index 8857789a74..ee30a723f2 100644 --- a/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md +++ b/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md @@ -113,8 +113,8 @@ This search detects the assignment of rights to accesss content from another mai #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **o365_suspicious_rights_delegation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-12-16-o365_pst_export_alert.md b/docs/_posts/2020-12-16-o365_pst_export_alert.md index 972953b60e..4037093153 100644 --- a/docs/_posts/2020-12-16-o365_pst_export_alert.md +++ b/docs/_posts/2020-12-16-o365_pst_export_alert.md @@ -100,8 +100,8 @@ This search detects when a user has performed an Ediscovery search or exported a #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **o365_pst_export_alert_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md b/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md index 15bbb80cd2..24a14ff406 100644 --- a/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md +++ b/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md @@ -114,8 +114,8 @@ This search detects when an admin configured a forwarding rule for multiple mail #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **o365_suspicious_admin_email_forwarding_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md b/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md index a6fd025871..46ed9198f8 100644 --- a/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md +++ b/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md @@ -114,8 +114,8 @@ This search detects when multiple user configured a forwarding rule to the same #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **o365_suspicious_user_email_forwarding_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md b/docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md index 3bd6804b8d..a9eda9f12e 100644 --- a/docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md +++ b/docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md @@ -107,8 +107,8 @@ The following analytic identifies microsoft.workflow.compiler.exe usage. microso #### Macros The SPL above uses the following Macros: -* [process_microsoftworkflowcompiler](https://github.com/splunk/security_content/blob/develop/macros/process_microsoftworkflowcompiler.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [process_microsoftworkflowcompiler](https://github.com/splunk/security_content/blob/develop/macros/process_microsoftworkflowcompiler.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md b/docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md index 72437922ef..acb9fc9e9c 100644 --- a/docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md +++ b/docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md @@ -112,8 +112,8 @@ Malicious actors often abuse legitimate Dynamic DNS services to host malicious p #### Macros The SPL above uses the following Macros: -* [dynamic_dns_providers](https://github.com/splunk/security_content/blob/develop/macros/dynamic_dns_providers.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [dynamic_dns_providers](https://github.com/splunk/security_content/blob/develop/macros/dynamic_dns_providers.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md b/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md index c255a85d26..d264511cc0 100644 --- a/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md +++ b/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md @@ -119,8 +119,8 @@ This search looks for PowerShell processes launched with arguments that have cha #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) > :information_source: > **malicious_powershell_process_with_obfuscation_techniques_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md b/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md index 76b85517e1..9dd8f0fe7a 100644 --- a/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md +++ b/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md @@ -112,8 +112,8 @@ The following analytic identifies "rundll32.exe" execution with inline protocol #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-01-20-suspicious_mshta_spawn.md b/docs/_posts/2021-01-20-suspicious_mshta_spawn.md index c1aa23acd7..7c5c6ff72c 100644 --- a/docs/_posts/2021-01-20-suspicious_mshta_spawn.md +++ b/docs/_posts/2021-01-20-suspicious_mshta_spawn.md @@ -112,8 +112,8 @@ The following analytic identifies wmiprvse.exe spawning mshta.exe. This behavior #### Macros The SPL above uses the following Macros: -* [process_mshta](https://github.com/splunk/security_content/blob/develop/macros/process_mshta.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [process_mshta](https://github.com/splunk/security_content/blob/develop/macros/process_mshta.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md b/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md index a2c30d39d5..aa6b09ec66 100644 --- a/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md +++ b/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md @@ -105,8 +105,8 @@ This search detects the creation of a new Federation setting by alerting about a #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **o365_add_app_role_assignment_grant_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md b/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md index 27ebda9129..d5a0cd0982 100644 --- a/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md +++ b/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md @@ -103,8 +103,8 @@ This search detects accounts with high number of Single Sign ON (SSO) logon erro #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **o365_excessive_sso_logon_errors_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-01-26-o365_new_federated_domain_added.md b/docs/_posts/2021-01-26-o365_new_federated_domain_added.md index 104fad167f..2fb2c1f106 100644 --- a/docs/_posts/2021-01-26-o365_new_federated_domain_added.md +++ b/docs/_posts/2021-01-26-o365_new_federated_domain_added.md @@ -105,8 +105,8 @@ This search detects the addition of a new Federated domain. #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **o365_new_federated_domain_added_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md b/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md index bf8e91a006..6c37af2788 100644 --- a/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md +++ b/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md @@ -113,8 +113,8 @@ Upon investigating, look for network connections to remote destinations (interna #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md b/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md index 67902820ae..f9cf1a3efd 100644 --- a/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md +++ b/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md @@ -112,8 +112,8 @@ Adversaries may abuse Regsvr32.exe to proxy execution of malicious code by using #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md index 8c91ad0ac3..4009f62681 100644 --- a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md +++ b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md @@ -112,8 +112,8 @@ The following analytic identifies rundll32.exe loading advpack.dll and ieadvpack #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md index 51c0ba4071..5d9e885e5e 100644 --- a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md +++ b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md @@ -112,8 +112,8 @@ The following analytic identifies rundll32.exe loading setupapi.dll and iesetupa #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md index b157c01edb..ed46a9baab 100644 --- a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md +++ b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md @@ -112,8 +112,8 @@ The following analytic identifies rundll32.exe loading syssetup.dll by calling t #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-02-04-suspicious_rundll32_startw.md b/docs/_posts/2021-02-04-suspicious_rundll32_startw.md index e6450c2428..ffe1328049 100644 --- a/docs/_posts/2021-02-04-suspicious_rundll32_startw.md +++ b/docs/_posts/2021-02-04-suspicious_rundll32_startw.md @@ -112,8 +112,8 @@ The following analytic identifies rundll32.exe executing a DLL function name, St #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md b/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md index ac7a1c4a6d..4cececf02b 100644 --- a/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md +++ b/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md @@ -112,8 +112,8 @@ The following analytic identifies rundll32.exe using dllregisterserver on the co #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-02-22-suspicious_curl_network_connection.md b/docs/_posts/2021-02-22-suspicious_curl_network_connection.md index df0c99103c..27ede70c64 100644 --- a/docs/_posts/2021-02-22-suspicious_curl_network_connection.md +++ b/docs/_posts/2021-02-22-suspicious_curl_network_connection.md @@ -130,6 +130,7 @@ Unknown. Filter as needed. #### Associated Analytic story * [Silver Sparrow](/stories/silver_sparrow) * [Ingress Tool Transfer](/stories/ingress_tool_transfer) +* [Linux Living Off The Land](/stories/linux_living_off_the_land) diff --git a/docs/_posts/2021-03-03-nishang_powershelltcponeline.md b/docs/_posts/2021-03-03-nishang_powershelltcponeline.md index 54aa9d9e45..fe914f3b97 100644 --- a/docs/_posts/2021-03-03-nishang_powershelltcponeline.md +++ b/docs/_posts/2021-03-03-nishang_powershelltcponeline.md @@ -108,8 +108,8 @@ This query detects the Nishang Invoke-PowerShellTCPOneLine utility that spawns a #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) > :information_source: > **nishang_powershelltcponeline_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-03-03-w3wp_spawning_shell.md b/docs/_posts/2021-03-03-w3wp_spawning_shell.md index ddd9eedfd9..7e2da03840 100644 --- a/docs/_posts/2021-03-03-w3wp_spawning_shell.md +++ b/docs/_posts/2021-03-03-w3wp_spawning_shell.md @@ -116,10 +116,10 @@ This query identifies a shell, PowerShell.exe or Cmd.exe, spawning from W3WP.exe #### Macros The SPL above uses the following Macros: -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) > :information_source: > **w3wp_spawning_shell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-03-16-windows_high_file_deletion_frequency.md b/docs/_posts/2021-03-16-windows_high_file_deletion_frequency.md index 92265d67b6..1de6dea794 100644 --- a/docs/_posts/2021-03-16-windows_high_file_deletion_frequency.md +++ b/docs/_posts/2021-03-16-windows_high_file_deletion_frequency.md @@ -28,7 +28,7 @@ This search looks for high frequency of file deletion relative to process name a - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) - **Last Updated**: 2021-03-16 -- **Author**: Teoderick Contreras +- **Author**: Teoderick Contreras, Splunk - **ID**: 45b125c4-866f-11eb-a95a-acde48001122 @@ -92,7 +92,7 @@ This search looks for high frequency of file deletion relative to process name a #### Search ``` -`sysmon` EventCode=23 TargetFilename IN ("*.cmd", "*.ini","*.gif", "*.jpg", "*.jpeg", "*.db", "*.ps1", "*.doc*", "*.xls*", "*.ppt*", "*.bmp","*.zip", "*.rar", "*.7z", "*.chm", "*.png", "*.log", "*.vbs", "*.js", "*.vhd", "*.bak", "*.wbcat", "*.bkf" , "*.backup*", "*.dsk", , "*.win") +`sysmon` EventCode=23 TargetFilename IN ("*.cmd", "*.ini","*.gif", "*.jpg", "*.jpeg", "*.db", "*.ps1", "*.doc*", "*.xls*", "*.ppt*", "*.bmp","*.zip", "*.rar", "*.7z", "*.chm", "*.png", "*.log", "*.vbs", "*.js", "*.vhd", "*.bak", "*.wbcat", "*.bkf" , "*.backup*", "*.dsk", "*.win") | stats values(TargetFilename) as deleted_files min(_time) as firstTime max(_time) as lastTime count by Computer user EventCode Image ProcessID |where count >=100 | `security_content_ctime(firstTime)` @@ -127,6 +127,7 @@ user may delete bunch of pictures or files in a folder. #### Associated Analytic story * [Clop Ransomware](/stories/clop_ransomware) * [WhisperGate](/stories/whispergate) +* [DarkCrystal RAT](/stories/darkcrystal_rat) diff --git a/docs/_posts/2021-03-17-clop_ransomware_known_service_name.md b/docs/_posts/2021-03-17-clop_ransomware_known_service_name.md index 4a83e65fdc..ad22032eb1 100644 --- a/docs/_posts/2021-03-17-clop_ransomware_known_service_name.md +++ b/docs/_posts/2021-03-17-clop_ransomware_known_service_name.md @@ -102,8 +102,8 @@ This detection is to identify the common service name created by the CLOP ransom #### Macros The SPL above uses the following Macros: -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) > :information_source: > **clop_ransomware_known_service_name_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-03-29-powershell_start-bitstransfer.md b/docs/_posts/2021-03-29-powershell_start-bitstransfer.md index 9db397178f..5583fced4f 100644 --- a/docs/_posts/2021-03-29-powershell_start-bitstransfer.md +++ b/docs/_posts/2021-03-29-powershell_start-bitstransfer.md @@ -104,8 +104,8 @@ Start-BitsTransfer is the PowerShell "version" of BitsAdmin.exe. Similar functio #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) > :information_source: > **powershell_start-bitstransfer_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md b/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md index 70a4adb637..f10537d8e5 100644 --- a/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md +++ b/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md @@ -107,8 +107,8 @@ This search is to identifies suspicious firewall disabling using netsh applicati #### Macros The SPL above uses the following Macros: -* [process_netsh](https://github.com/splunk/security_content/blob/develop/macros/process_netsh.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [process_netsh](https://github.com/splunk/security_content/blob/develop/macros/process_netsh.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md b/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md index ab261f4d7d..ebd16db17c 100644 --- a/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md +++ b/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md @@ -115,8 +115,8 @@ This detection is to identify the abuse the Windows SC.exe to execute malicious #### Macros The SPL above uses the following Macros: -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) > :information_source: > **malicious_powershell_executed_as_a_service_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md b/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md index 6809b34a14..8298ca7fc7 100644 --- a/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md +++ b/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md @@ -115,8 +115,8 @@ Upon triage, identify the task scheduled source. Was it schtasks.exe or was it v #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **winevent_scheduled_task_created_within_public_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-12-excel_spawning_powershell.md b/docs/_posts/2021-04-12-excel_spawning_powershell.md index 6ecfb6fed8..a7a8420e93 100644 --- a/docs/_posts/2021-04-12-excel_spawning_powershell.md +++ b/docs/_posts/2021-04-12-excel_spawning_powershell.md @@ -108,8 +108,8 @@ The following detection identifies Microsoft Excel spawning PowerShell. Typicall #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) > :information_source: > **excel_spawning_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md b/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md index fa288d86e1..5ff4bdb821 100644 --- a/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md +++ b/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md @@ -115,8 +115,8 @@ Upon triage, identify the task scheduled source. Was it schtasks.exe or via Task #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **winevent_scheduled_task_created_to_spawn_shell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-12-winword_spawning_powershell.md b/docs/_posts/2021-04-12-winword_spawning_powershell.md index a6e3b2fd4f..043a43314d 100644 --- a/docs/_posts/2021-04-12-winword_spawning_powershell.md +++ b/docs/_posts/2021-04-12-winword_spawning_powershell.md @@ -108,8 +108,8 @@ The following detection identifies Microsoft Word spawning PowerShell. Typically #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) > :information_source: > **winword_spawning_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. @@ -137,6 +137,7 @@ False positives should be limited, but if any are present, filter as needed. #### Associated Analytic story * [Spearphishing Attachments](/stories/spearphishing_attachments) +* [DarkCrystal RAT](/stories/darkcrystal_rat) diff --git a/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md b/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md index 395cc1b89a..75a6897250 100644 --- a/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md +++ b/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md @@ -107,8 +107,8 @@ this detection was designed to identifies suspicious spawned process of known MS #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-04-14-office_document_executing_macro_code.md b/docs/_posts/2021-04-14-office_document_executing_macro_code.md index 036ae99d5e..eae4be613d 100644 --- a/docs/_posts/2021-04-14-office_document_executing_macro_code.md +++ b/docs/_posts/2021-04-14-office_document_executing_macro_code.md @@ -134,6 +134,7 @@ Normal Office Document macro use for automation * [Spearphishing Attachments](/stories/spearphishing_attachments) * [Trickbot](/stories/trickbot) * [IcedID](/stories/icedid) +* [DarkCrystal RAT](/stories/darkcrystal_rat) diff --git a/docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md b/docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md index 3518e5e547..b297562c89 100644 --- a/docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md +++ b/docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md @@ -105,8 +105,8 @@ The following query utilizes Windows Security EventCode 4698, `A scheduled task #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **schedule_task_with_http_command_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md b/docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md index 6ca813b619..2831b2bc73 100644 --- a/docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md +++ b/docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md @@ -105,8 +105,8 @@ The following query utilizes Windows Security EventCode 4698, `A scheduled task #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **schedule_task_with_rundll32_command_trigger_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md b/docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md index 0a6a55d2cd..4ca443cc29 100644 --- a/docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md +++ b/docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md @@ -102,10 +102,10 @@ This search is designed to detect suspicious cmd and powershell process spawned #### Macros The SPL above uses the following Macros: -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) > :information_source: > **wermgr_process_spawned_cmd_or_powershell_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md b/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md index 89ed66a32e..b431df4985 100644 --- a/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md +++ b/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md @@ -109,8 +109,8 @@ This search is designed to detect high frequency of archive files data exfiltrat #### Macros The SPL above uses the following Macros: -* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) > :information_source: > **multiple_archive_files_http_post_traffic_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md b/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md index c40ab2bb31..e0ae691ef6 100644 --- a/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md +++ b/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md @@ -107,8 +107,8 @@ The following detection identifies the latest behavior utilized by IcedID malwar #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md b/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md index 8b9810d35a..2f4662d6e8 100644 --- a/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md +++ b/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md @@ -106,8 +106,8 @@ This search is to detect potential plain HTTP POST method data exfiltration. Thi #### Macros The SPL above uses the following Macros: -* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) > :information_source: > **plain_http_post_exfiltrated_data_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-22-winword_spawning_cmd.md b/docs/_posts/2021-04-22-winword_spawning_cmd.md index cd8bc91dff..b2ee8054fa 100644 --- a/docs/_posts/2021-04-22-winword_spawning_cmd.md +++ b/docs/_posts/2021-04-22-winword_spawning_cmd.md @@ -107,9 +107,9 @@ The following detection identifies Microsoft Word spawning `cmd.exe`. Typically, #### Macros The SPL above uses the following Macros: -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) > :information_source: > **winword_spawning_cmd_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. @@ -137,6 +137,7 @@ False positives should be limited, but if any are present, filter as needed. #### Associated Analytic story * [Spearphishing Attachments](/stories/spearphishing_attachments) +* [DarkCrystal RAT](/stories/darkcrystal_rat) diff --git a/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md b/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md index 1678be0cca..83ac9784e0 100644 --- a/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md +++ b/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md @@ -108,8 +108,8 @@ The following detection identifies the latest behavior utilized by different mal #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_bitsadmin](https://github.com/splunk/security_content/blob/develop/macros/process_bitsadmin.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_bitsadmin](https://github.com/splunk/security_content/blob/develop/macros/process_bitsadmin.yml) > :information_source: > **office_product_spawning_bitsadmin_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-26-office_product_spawning_mshta.md b/docs/_posts/2021-04-26-office_product_spawning_mshta.md index 5fda55ea06..23dc5d2084 100644 --- a/docs/_posts/2021-04-26-office_product_spawning_mshta.md +++ b/docs/_posts/2021-04-26-office_product_spawning_mshta.md @@ -107,8 +107,8 @@ The following detection identifies the latest behavior utilized by different mal #### Macros The SPL above uses the following Macros: -* [process_mshta](https://github.com/splunk/security_content/blob/develop/macros/process_mshta.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [process_mshta](https://github.com/splunk/security_content/blob/develop/macros/process_mshta.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-05-04-process_kill_base_on_file_path.md b/docs/_posts/2021-05-04-process_kill_base_on_file_path.md index 2991a72568..bbecb9975f 100644 --- a/docs/_posts/2021-05-04-process_kill_base_on_file_path.md +++ b/docs/_posts/2021-05-04-process_kill_base_on_file_path.md @@ -107,9 +107,9 @@ The following analytic identifies the use of `wmic.exe` using `delete` to remove #### Macros The SPL above uses the following Macros: -* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) > :information_source: > **process_kill_base_on_file_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-05-05-suspicious_process_file_path.md b/docs/_posts/2021-05-05-suspicious_process_file_path.md index aea34adffa..2fbb5278a8 100644 --- a/docs/_posts/2021-05-05-suspicious_process_file_path.md +++ b/docs/_posts/2021-05-05-suspicious_process_file_path.md @@ -134,6 +134,7 @@ Administrators may allow execution of specific binaries in non-standard paths. F * [WhisperGate](/stories/whispergate) * [Hermetic Wiper](/stories/hermetic_wiper) * [Industroyer2](/stories/industroyer2) +* [DarkCrystal RAT](/stories/darkcrystal_rat) diff --git a/docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md b/docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md index 04879af5f4..2283e7d33e 100644 --- a/docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md +++ b/docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md @@ -101,8 +101,8 @@ This analytic will detect a suspicious Telegram process enumerating all network #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **enumerate_users_local_group_using_telegram_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md b/docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md index ce7b6312f2..c6c40096fe 100644 --- a/docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md +++ b/docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md @@ -132,6 +132,7 @@ Administrators may allow creation of script or exe in the paths specified. Filte * [Hermetic Wiper](/stories/hermetic_wiper) * [Industroyer2](/stories/industroyer2) * [Azorult](/stories/azorult) +* [DarkCrystal RAT](/stories/darkcrystal_rat) diff --git a/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md b/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md index f8d18f858e..9f0639ec6f 100644 --- a/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md +++ b/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md @@ -106,8 +106,8 @@ The following analytic identifies suspicious PowerShell command to allow inbound #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **allow_inbound_traffic_in_firewall_rule_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md b/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md index c32f863108..1ed5f0e08d 100644 --- a/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md +++ b/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md @@ -119,9 +119,9 @@ This analytic identifies a common behavior by Cobalt Strike and other frameworks #### Macros The SPL above uses the following Macros: -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) > :information_source: > **cmd_echo_pipe_-_escalation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-06-04-known_services_killed_by_ransomware.md b/docs/_posts/2021-06-04-known_services_killed_by_ransomware.md index 3c01acc3b9..e87879902a 100644 --- a/docs/_posts/2021-06-04-known_services_killed_by_ransomware.md +++ b/docs/_posts/2021-06-04-known_services_killed_by_ransomware.md @@ -101,8 +101,8 @@ This search detects a suspicioous termination of known services killed by ransom #### Macros The SPL above uses the following Macros: -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) > :information_source: > **known_services_killed_by_ransomware_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-06-09-unloading_amsi_via_reflection.md b/docs/_posts/2021-06-09-unloading_amsi_via_reflection.md index 900b792ef2..b3fe0480ab 100644 --- a/docs/_posts/2021-06-09-unloading_amsi_via_reflection.md +++ b/docs/_posts/2021-06-09-unloading_amsi_via_reflection.md @@ -112,8 +112,8 @@ During triage, review parallel processes using an EDR product or 4688 events. It #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **unloading_amsi_via_reflection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md b/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md index ff2ea0cea2..f638d3f37f 100644 --- a/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md +++ b/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md @@ -115,8 +115,8 @@ The following analytic utilizes Windows Event ID 1100 to identify when Windows e #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **suspicious_event_log_service_behavior_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md b/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md index eb65981ea1..a11edd86b5 100644 --- a/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md +++ b/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md @@ -107,9 +107,9 @@ This search is to detect a suspicious commandline designed to delete files or di #### Macros The SPL above uses the following Macros: -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) > :information_source: > **recursive_delete_of_directory_in_batch_cmd_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md b/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md index bd72e6e9a8..bd7d3c9fd1 100644 --- a/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md +++ b/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md @@ -107,8 +107,8 @@ This search is to detect a suspicious modification of firewall to allow file and #### Macros The SPL above uses the following Macros: -* [process_netsh](https://github.com/splunk/security_content/blob/develop/macros/process_netsh.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [process_netsh](https://github.com/splunk/security_content/blob/develop/macros/process_netsh.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md b/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md index b5759a2471..d1aafee343 100644 --- a/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md +++ b/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md @@ -107,8 +107,8 @@ This search is to detect a suspicious modification to the firewall to allow netw #### Macros The SPL above uses the following Macros: -* [process_netsh](https://github.com/splunk/security_content/blob/develop/macros/process_netsh.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [process_netsh](https://github.com/splunk/security_content/blob/develop/macros/process_netsh.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md b/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md index 7551eff4e1..608519e66a 100644 --- a/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md +++ b/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md @@ -117,8 +117,8 @@ During triage, isolate the endpoint and review for source of exploitation. Captu #### Macros The SPL above uses the following Macros: -* [printservice](https://github.com/splunk/security_content/blob/develop/macros/printservice.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [printservice](https://github.com/splunk/security_content/blob/develop/macros/printservice.yml) > :information_source: > **print_spooler_adding_a_printer_driver_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md b/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md index da242bf198..420a89ebda 100644 --- a/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md +++ b/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md @@ -118,8 +118,8 @@ During triage, isolate the endpoint and review for source of exploitation. Captu #### Macros The SPL above uses the following Macros: -* [printservice](https://github.com/splunk/security_content/blob/develop/macros/printservice.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [printservice](https://github.com/splunk/security_content/blob/develop/macros/printservice.yml) > :information_source: > **print_spooler_failed_to_load_a_plug-in_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md b/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md index 0715b23fe2..afc087cf40 100644 --- a/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md +++ b/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md @@ -114,8 +114,8 @@ The following analytic identifies a suspicious child process, `rundll32.exe`, wi #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md b/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md index 4d3b8451a5..5ce445a8c1 100644 --- a/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md +++ b/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md @@ -107,9 +107,9 @@ This search is to detect a suspicious mshta.exe process that spawn rundll32 or r #### Macros The SPL above uses the following Macros: +* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml) -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md b/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md index 1a8abd0c7d..fa75660590 100644 --- a/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md +++ b/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md @@ -107,9 +107,9 @@ this search is to detect a suspicious office product process that spawn cmd chil #### Macros The SPL above uses the following Macros: -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) > :information_source: > **office_product_spawn_cmd_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. @@ -137,6 +137,7 @@ IT or network admin may create an document automation that will run shell script #### Associated Analytic story * [Trickbot](/stories/trickbot) +* [DarkCrystal RAT](/stories/darkcrystal_rat) diff --git a/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md b/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md index 1f08a24b4d..ba50bfd6fb 100644 --- a/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md +++ b/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md @@ -112,8 +112,8 @@ During triage, review parallel processes using an EDR product or 4688 events. It #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **detect_copy_of_shadowcopy_with_script_block_logging_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md b/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md index e574e6f691..fa9fa4b335 100644 --- a/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md +++ b/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md @@ -107,8 +107,8 @@ This search is to detect a suspicious rundll32.exe commandline to execute dll fi #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md b/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md index 2c4448604c..14846a2e0e 100644 --- a/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md +++ b/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md @@ -107,8 +107,8 @@ This search is to detect a suspicious rundll32.exe process with plugininit param #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-07-27-regsvr32_with_known_silent_switch_cmdline.md b/docs/_posts/2021-07-27-regsvr32_with_known_silent_switch_cmdline.md index 27cbb5c585..a70a85e8c3 100644 --- a/docs/_posts/2021-07-27-regsvr32_with_known_silent_switch_cmdline.md +++ b/docs/_posts/2021-07-27-regsvr32_with_known_silent_switch_cmdline.md @@ -109,8 +109,8 @@ The following analytic identifies Regsvr32.exe utilizing the silent switch to lo #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md b/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md index ae7b48391d..d478b8a1dc 100644 --- a/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md +++ b/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md @@ -107,8 +107,8 @@ this detection was designed to identifies suspicious spawned process of known MS #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md b/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md index 9503d402ab..3c41a25ed8 100644 --- a/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md +++ b/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md @@ -107,8 +107,8 @@ This search is to detect a suspicious attachment file extension in Gsuite email #### Macros The SPL above uses the following Macros: -* [gsuite_gmail](https://github.com/splunk/security_content/blob/develop/macros/gsuite_gmail.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [gsuite_gmail](https://github.com/splunk/security_content/blob/develop/macros/gsuite_gmail.yml) > :information_source: > **gsuite_email_suspicious_attachment_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md b/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md index c869495b9b..a5d581a73a 100644 --- a/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md +++ b/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md @@ -112,8 +112,8 @@ This search is to detect a suspicious outbound e-mail from internal email to ext #### Macros The SPL above uses the following Macros: -* [gsuite_gmail](https://github.com/splunk/security_content/blob/develop/macros/gsuite_gmail.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [gsuite_gmail](https://github.com/splunk/security_content/blob/develop/macros/gsuite_gmail.yml) > :information_source: > **gsuite_outbound_email_with_attachment_to_external_domain_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md b/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md index c53734cb79..cc02548366 100644 --- a/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md +++ b/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md @@ -116,8 +116,8 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service ( #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [aws_ecr_users](https://github.com/splunk/security_content/blob/develop/macros/aws_ecr_users.yml) * [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) +* [aws_ecr_users](https://github.com/splunk/security_content/blob/develop/macros/aws_ecr_users.yml) > :information_source: > **aws_ecr_container_upload_unknown_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md b/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md index e3595cd0d7..f70e2c6197 100644 --- a/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md +++ b/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md @@ -110,8 +110,8 @@ This search is to detect a gsuite email contains suspicious subject having known #### Macros The SPL above uses the following Macros: -* [gsuite_gmail](https://github.com/splunk/security_content/blob/develop/macros/gsuite_gmail.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [gsuite_gmail](https://github.com/splunk/security_content/blob/develop/macros/gsuite_gmail.yml) > :information_source: > **gsuite_email_suspicious_subject_with_attachment_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-08-20-github_commit_changes_in_master.md b/docs/_posts/2021-08-20-github_commit_changes_in_master.md index 0db42eec42..b176886222 100644 --- a/docs/_posts/2021-08-20-github_commit_changes_in_master.md +++ b/docs/_posts/2021-08-20-github_commit_changes_in_master.md @@ -101,8 +101,8 @@ This search is to detect a pushed or commit to master or main branch. This is to #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [github](https://github.com/splunk/security_content/blob/develop/macros/github.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **github_commit_changes_in_master_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md b/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md index 97395a0a7b..b9eae53195 100644 --- a/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md +++ b/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md @@ -110,8 +110,8 @@ This analytics is to detect a gmail containing a link that are known to be abuse #### Macros The SPL above uses the following Macros: -* [gsuite_gmail](https://github.com/splunk/security_content/blob/develop/macros/gsuite_gmail.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [gsuite_gmail](https://github.com/splunk/security_content/blob/develop/macros/gsuite_gmail.yml) > :information_source: > **gsuite_email_with_known_abuse_web_service_link_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-08-24-adsisearcher_account_discovery.md b/docs/_posts/2021-08-24-adsisearcher_account_discovery.md index ea9a9b6194..5f2ea3159e 100644 --- a/docs/_posts/2021-08-24-adsisearcher_account_discovery.md +++ b/docs/_posts/2021-08-24-adsisearcher_account_discovery.md @@ -105,8 +105,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **adsisearcher_account_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md b/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md index 2885ec9bca..983227c015 100644 --- a/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md +++ b/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md @@ -105,8 +105,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **get_aduser_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md b/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md index 56e7aa0105..1d73972dff 100644 --- a/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md +++ b/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md @@ -104,8 +104,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **domain_group_discovery_with_adsisearcher_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md b/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md index 95bcfb93d3..98c721908f 100644 --- a/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md +++ b/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md @@ -104,8 +104,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **elevated_group_discovery_with_powerview_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-08-31-petitpotam_network_share_access_request.md b/docs/_posts/2021-08-31-petitpotam_network_share_access_request.md index 7ae0dd38c1..74fd24e098 100644 --- a/docs/_posts/2021-08-31-petitpotam_network_share_access_request.md +++ b/docs/_posts/2021-08-31-petitpotam_network_share_access_request.md @@ -108,8 +108,8 @@ During triage, review parallel security events to identify further suspicious ac #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **petitpotam_network_share_access_request_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md b/docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md index 639b6ff4aa..097e4595bc 100644 --- a/docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md +++ b/docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md @@ -105,8 +105,8 @@ The following analytic identifes Event Code 4768, A `Kerberos authentication tic #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **petitpotam_suspicious_kerberos_tgt_request_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-01-circle_ci_disable_security_step.md b/docs/_posts/2021-09-01-circle_ci_disable_security_step.md index 71a252f6f8..9e27a6d39f 100644 --- a/docs/_posts/2021-09-01-circle_ci_disable_security_step.md +++ b/docs/_posts/2021-09-01-circle_ci_disable_security_step.md @@ -117,8 +117,8 @@ This search looks for disable security step in CircleCI pipeline. #### Macros The SPL above uses the following Macros: -* [circleci](https://github.com/splunk/security_content/blob/develop/macros/circleci.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [circleci](https://github.com/splunk/security_content/blob/develop/macros/circleci.yml) > :information_source: > **circle_ci_disable_security_step_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-01-github_commit_in_develop.md b/docs/_posts/2021-09-01-github_commit_in_develop.md index e2886e38e9..2eef99dca3 100644 --- a/docs/_posts/2021-09-01-github_commit_in_develop.md +++ b/docs/_posts/2021-09-01-github_commit_in_develop.md @@ -101,8 +101,8 @@ This search is to detect a pushed or commit to develop branch. This is to avoid #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [github](https://github.com/splunk/security_content/blob/develop/macros/github.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **github_commit_in_develop_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-01-github_dependabot_alert.md b/docs/_posts/2021-09-01-github_dependabot_alert.md index 8e071247fe..fd2a212384 100644 --- a/docs/_posts/2021-09-01-github_dependabot_alert.md +++ b/docs/_posts/2021-09-01-github_dependabot_alert.md @@ -113,8 +113,8 @@ This search looks for Dependabot Alerts in Github logs. #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [github](https://github.com/splunk/security_content/blob/develop/macros/github.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **github_dependabot_alert_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md b/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md index c13d9a26c5..986599f6e5 100644 --- a/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md +++ b/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md @@ -114,9 +114,9 @@ This search looks for Pull Request from unknown user. #### Macros The SPL above uses the following Macros: -* [github_known_users](https://github.com/splunk/security_content/blob/develop/macros/github_known_users.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [github](https://github.com/splunk/security_content/blob/develop/macros/github.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [github_known_users](https://github.com/splunk/security_content/blob/develop/macros/github_known_users.yml) > :information_source: > **github_pull_request_from_unknown_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-02-circle_ci_disable_security_job.md b/docs/_posts/2021-09-02-circle_ci_disable_security_job.md index 136c9bacd3..735373a9e4 100644 --- a/docs/_posts/2021-09-02-circle_ci_disable_security_job.md +++ b/docs/_posts/2021-09-02-circle_ci_disable_security_job.md @@ -113,8 +113,8 @@ This search looks for disable security job in CircleCI pipeline. #### Macros The SPL above uses the following Macros: -* [circleci](https://github.com/splunk/security_content/blob/develop/macros/circleci.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [circleci](https://github.com/splunk/security_content/blob/develop/macros/circleci.yml) > :information_source: > **circle_ci_disable_security_job_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md b/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md index 134b9a1a46..a6cbdb54f1 100644 --- a/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md +++ b/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md @@ -112,8 +112,8 @@ The following hunting detection identifies rundll32.exe with `control_rundll` wi #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md b/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md index 9e7b8b4572..d74d500fcd 100644 --- a/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md +++ b/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md @@ -112,8 +112,8 @@ The following detection identifies rundll32.exe with `control_rundll` within the #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md b/docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md index 2bdb9d99a4..a7fcdc4bf3 100644 --- a/docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md +++ b/docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md @@ -102,9 +102,9 @@ This search is to detect a suspicious wmic.exe process or renamed wmic process t #### Macros The SPL above uses the following Macros: -* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) > :information_source: > **xsl_script_execution_with_wmic_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md b/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md index d8ee054155..9f48a1bb5b 100644 --- a/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md +++ b/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md @@ -106,8 +106,8 @@ This search is to detect an anomaly event of non-chrome process accessing the fi #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **non_chrome_process_accessing_chrome_default_dir_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md b/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md index 8ed284f78d..8ea599e012 100644 --- a/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md +++ b/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md @@ -106,8 +106,8 @@ This search is to detect an anomaly event of non-firefox process accessing the f #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **non_firefox_process_access_firefox_profile_dir_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md b/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md index 8ee59db57a..beb83a8095 100644 --- a/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md +++ b/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md @@ -114,9 +114,9 @@ Monitor for execution of reg.exe with parameters specifying an export of keys th #### Macros The SPL above uses the following Macros: * [process_reg](https://github.com/splunk/security_content/blob/develop/macros/process_reg.yml) -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) > :information_source: > **attempted_credential_dump_from_registry_via_reg_exe_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-16-bits_job_persistence.md b/docs/_posts/2021-09-16-bits_job_persistence.md index 65b5026013..1de2af652c 100644 --- a/docs/_posts/2021-09-16-bits_job_persistence.md +++ b/docs/_posts/2021-09-16-bits_job_persistence.md @@ -104,8 +104,8 @@ The following query identifies Microsoft Background Intelligent Transfer Service #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_bitsadmin](https://github.com/splunk/security_content/blob/develop/macros/process_bitsadmin.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_bitsadmin](https://github.com/splunk/security_content/blob/develop/macros/process_bitsadmin.yml) > :information_source: > **bits_job_persistence_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-16-bitsadmin_download_file.md b/docs/_posts/2021-09-16-bitsadmin_download_file.md index e430f829c2..d2c8c7bf2d 100644 --- a/docs/_posts/2021-09-16-bitsadmin_download_file.md +++ b/docs/_posts/2021-09-16-bitsadmin_download_file.md @@ -109,8 +109,8 @@ The following query identifies Microsoft Background Intelligent Transfer Service #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_bitsadmin](https://github.com/splunk/security_content/blob/develop/macros/process_bitsadmin.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_bitsadmin](https://github.com/splunk/security_content/blob/develop/macros/process_bitsadmin.yml) > :information_source: > **bitsadmin_download_file_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md b/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md index 3a7ad373e5..abb3e468f1 100644 --- a/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md +++ b/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md @@ -112,10 +112,10 @@ This search detects the use of wmic and Powershell to create a shadow copy. #### Macros The SPL above uses the following Macros: -* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) > :information_source: > **creation_of_shadow_copy_with_wmic_and_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md b/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md index dcf5dcfcc6..f6f060195b 100644 --- a/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md +++ b/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md @@ -112,9 +112,9 @@ This search detects credential dumping using copy command from a shadow copy. #### Macros The SPL above uses the following Macros: -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) > :information_source: > **credential_dumping_via_copy_command_from_shadow_copy_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md b/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md index 07f3c1ee10..d6a564ecf3 100644 --- a/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md +++ b/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md @@ -112,9 +112,9 @@ This search detects the creation of a symlink to a shadow copy. #### Macros The SPL above uses the following Macros: -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) > :information_source: > **credential_dumping_via_symlink_to_shadow_copy_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md b/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md index a3b6fe1e24..fc5d25d403 100644 --- a/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md +++ b/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md @@ -112,8 +112,8 @@ The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTM #### Macros The SPL above uses the following Macros: -* [process_hh](https://github.com/splunk/security_content/blob/develop/macros/process_hh.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [process_hh](https://github.com/splunk/security_content/blob/develop/macros/process_hh.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md b/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md index 64f09c68b7..c9b2ff2744 100644 --- a/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md +++ b/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md @@ -112,8 +112,8 @@ The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTM #### Macros The SPL above uses the following Macros: -* [process_hh](https://github.com/splunk/security_content/blob/develop/macros/process_hh.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [process_hh](https://github.com/splunk/security_content/blob/develop/macros/process_hh.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md b/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md index eacfc71a0e..917308ab5f 100644 --- a/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md +++ b/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md @@ -112,8 +112,8 @@ The following analytic identifies "mshta.exe" execution with inline protocol han #### Macros The SPL above uses the following Macros: -* [process_mshta](https://github.com/splunk/security_content/blob/develop/macros/process_mshta.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [process_mshta](https://github.com/splunk/security_content/blob/develop/macros/process_mshta.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md b/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md index 6e43b419ee..6d3b9fd3f3 100644 --- a/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md +++ b/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md @@ -112,8 +112,8 @@ This analytic identifies when Microsoft HTML Application Host (mshta.exe) utilit #### Macros The SPL above uses the following Macros: -* [process_mshta](https://github.com/splunk/security_content/blob/develop/macros/process_mshta.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [process_mshta](https://github.com/splunk/security_content/blob/develop/macros/process_mshta.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md b/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md index 792de3fc4f..1dea81ca3d 100644 --- a/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md +++ b/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md @@ -112,8 +112,8 @@ This search looks for events where `PsExec.exe` is run with the `accepteula` fla #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_psexec](https://github.com/splunk/security_content/blob/develop/macros/process_psexec.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-09-16-dump_lsass_via_procdump.md b/docs/_posts/2021-09-16-dump_lsass_via_procdump.md index cbd7f74e6d..afd7962ebb 100644 --- a/docs/_posts/2021-09-16-dump_lsass_via_procdump.md +++ b/docs/_posts/2021-09-16-dump_lsass_via_procdump.md @@ -114,9 +114,9 @@ During triage, confirm this is procdump.exe executing. If it is the first time a #### Macros The SPL above uses the following Macros: -* [process_procdump](https://github.com/splunk/security_content/blob/develop/macros/process_procdump.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_procdump](https://github.com/splunk/security_content/blob/develop/macros/process_procdump.yml) > :information_source: > **dump_lsass_via_procdump_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md b/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md index 8bbbca5fdd..34a3d5138b 100644 --- a/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md +++ b/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md @@ -107,9 +107,9 @@ This analytic looks for the execution of `wmic.exe` with command-line arguments #### Macros The SPL above uses the following Macros: -* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) > :information_source: > **local_account_discovery_with_wmic_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-16-office_product_spawning_wmic.md b/docs/_posts/2021-09-16-office_product_spawning_wmic.md index 11ee174959..eed2b96620 100644 --- a/docs/_posts/2021-09-16-office_product_spawning_wmic.md +++ b/docs/_posts/2021-09-16-office_product_spawning_wmic.md @@ -107,9 +107,9 @@ The following detection identifies the latest behavior utilized by Ursnif malwar #### Macros The SPL above uses the following Macros: -* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) > :information_source: > **office_product_spawning_wmic_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-16-processes_launching_netsh.md b/docs/_posts/2021-09-16-processes_launching_netsh.md index 5907724877..f65a13f3a8 100644 --- a/docs/_posts/2021-09-16-processes_launching_netsh.md +++ b/docs/_posts/2021-09-16-processes_launching_netsh.md @@ -112,8 +112,8 @@ This search looks for processes launching netsh.exe. Netsh is a command-line scr #### Macros The SPL above uses the following Macros: -* [process_netsh](https://github.com/splunk/security_content/blob/develop/macros/process_netsh.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [process_netsh](https://github.com/splunk/security_content/blob/develop/macros/process_netsh.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-10-04-regsvr32_silent_and_install_param_dll_loading.md b/docs/_posts/2021-10-04-regsvr32_silent_and_install_param_dll_loading.md index aba5066818..c924c644b1 100644 --- a/docs/_posts/2021-10-04-regsvr32_silent_and_install_param_dll_loading.md +++ b/docs/_posts/2021-10-04-regsvr32_silent_and_install_param_dll_loading.md @@ -109,8 +109,8 @@ This analytic is to detect a loading of dll using regsvr32 application with sile #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-10-05-rundll32_shimcache_flush.md b/docs/_posts/2021-10-05-rundll32_shimcache_flush.md index a3863a8678..f51ec23ad7 100644 --- a/docs/_posts/2021-10-05-rundll32_shimcache_flush.md +++ b/docs/_posts/2021-10-05-rundll32_shimcache_flush.md @@ -102,8 +102,8 @@ This analytic is to detect a suspicious rundll32 commandline to clear shim cache #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-10-05-suspicious_copy_on_system32.md b/docs/_posts/2021-10-05-suspicious_copy_on_system32.md index c13cc3d56c..e139502ae5 100644 --- a/docs/_posts/2021-10-05-suspicious_copy_on_system32.md +++ b/docs/_posts/2021-10-05-suspicious_copy_on_system32.md @@ -107,8 +107,8 @@ This analytic is to detect a suspicious copy of file from systemroot folder of t #### Macros The SPL above uses the following Macros: -* [process_copy](https://github.com/splunk/security_content/blob/develop/macros/process_copy.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [process_copy](https://github.com/splunk/security_content/blob/develop/macros/process_copy.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_setspn.md b/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_setspn.md index 36e33ba380..3ead2144b5 100644 --- a/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_setspn.md +++ b/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_setspn.md @@ -109,8 +109,8 @@ During triage, review parallel processes for further suspicious activity. #### Macros The SPL above uses the following Macros: -* [process_setspn](https://github.com/splunk/security_content/blob/develop/macros/process_setspn.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [process_setspn](https://github.com/splunk/security_content/blob/develop/macros/process_setspn.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md b/docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md index 8b58d45823..d893b1bbd3 100644 --- a/docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md +++ b/docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md @@ -104,8 +104,8 @@ The following hunting analytic assists with identifying suspicious tasks that ha #### Macros The SPL above uses the following Macros: -* [wineventlog_task_scheduler](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_task_scheduler.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [wineventlog_task_scheduler](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_task_scheduler.yml) > :information_source: > **winevent_windows_task_scheduler_event_action_started_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-11-11-wmic_xsl_execution_via_url.md b/docs/_posts/2021-11-11-wmic_xsl_execution_via_url.md index 284af4d9fc..3e2d9784e0 100644 --- a/docs/_posts/2021-11-11-wmic_xsl_execution_via_url.md +++ b/docs/_posts/2021-11-11-wmic_xsl_execution_via_url.md @@ -102,9 +102,9 @@ The following analytic identifies `wmic.exe` loading a remote XSL (eXtensible St #### Macros The SPL above uses the following Macros: -* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) > :information_source: > **wmic_xsl_execution_via_url_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md b/docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md index 622f31b0c1..59357aa8f6 100644 --- a/docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md +++ b/docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md @@ -110,9 +110,9 @@ This analytic identifies wmic.exe being launched with parameters to spawn a proc #### Macros The SPL above uses the following Macros: -* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) > :information_source: > **remote_process_instantiation_via_wmi_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-11-12-runas_execution_in_commandline.md b/docs/_posts/2021-11-12-runas_execution_in_commandline.md index cc681854c0..fd8c7b566e 100644 --- a/docs/_posts/2021-11-12-runas_execution_in_commandline.md +++ b/docs/_posts/2021-11-12-runas_execution_in_commandline.md @@ -109,9 +109,9 @@ This analytic look for a spawned runas.exe process with a administrator user opt #### Macros The SPL above uses the following Macros: -* [process_runas](https://github.com/splunk/security_content/blob/develop/macros/process_runas.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_runas](https://github.com/splunk/security_content/blob/develop/macros/process_runas.yml) > :information_source: > **runas_execution_in_commandline_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md b/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md index 81de8c5624..37b92ca050 100644 --- a/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md +++ b/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md @@ -108,8 +108,8 @@ This analytic looks for the execution of `powershell.exe` with arguments utilize #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) > :information_source: > **remote_process_instantiation_via_dcom_and_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md b/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md index 5b8a381b82..133e5e5ae1 100644 --- a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md +++ b/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md @@ -103,8 +103,8 @@ This analytic looks for the execution of `powershell.exe` leveraging the `Invoke #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) > :information_source: > **remote_process_instantiation_via_wmi_and_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md b/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md index b8856a3372..7b124d8434 100644 --- a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md +++ b/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md @@ -99,8 +99,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **remote_process_instantiation_via_wmi_and_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md b/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md index cd91819f97..d611b7f432 100644 --- a/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md +++ b/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md @@ -108,8 +108,8 @@ This analytic looks for the execution of `powershell.exe` with arguments utilize #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) > :information_source: > **remote_process_instantiation_via_winrm_and_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md b/docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md index 3262267714..98e16c7643 100644 --- a/docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md +++ b/docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md @@ -105,8 +105,8 @@ The following analytic identifies executable files (.exe or .dll) being written #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **executable_file_written_in_administrative_smb_share_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md b/docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md index 7616892f0b..f2e189df34 100644 --- a/docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md +++ b/docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md @@ -102,9 +102,9 @@ This analytic is to detect a suspicious dxdiag.exe process command-line executio #### Macros The SPL above uses the following Macros: -* [process_dxdiag](https://github.com/splunk/security_content/blob/develop/macros/process_dxdiag.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_dxdiag](https://github.com/splunk/security_content/blob/develop/macros/process_dxdiag.yml) > :information_source: > **system_info_gathering_using_dxdiag_application_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md b/docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md index 63c380741e..dedb5d334c 100644 --- a/docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md +++ b/docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md @@ -105,8 +105,8 @@ The following analytc uses Windows Event Id 7045, `New Service Was Installed`, t #### Macros The SPL above uses the following Macros: -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) > :information_source: > **windows_service_created_with_suspicious_service_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-11-22-windows_service_created_within_public_path.md b/docs/_posts/2021-11-22-windows_service_created_within_public_path.md index 1c40def6e4..ddf621fad7 100644 --- a/docs/_posts/2021-11-22-windows_service_created_within_public_path.md +++ b/docs/_posts/2021-11-22-windows_service_created_within_public_path.md @@ -107,8 +107,8 @@ The following analytc uses Windows Event Id 7045, `New Service Was Installed`, t #### Macros The SPL above uses the following Macros: -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) > :information_source: > **windows_service_created_within_public_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-11-25-powershell_windows_defender_exclusion_commands.md b/docs/_posts/2021-11-25-powershell_windows_defender_exclusion_commands.md index 6c2914b698..9d367f82a9 100644 --- a/docs/_posts/2021-11-25-powershell_windows_defender_exclusion_commands.md +++ b/docs/_posts/2021-11-25-powershell_windows_defender_exclusion_commands.md @@ -106,8 +106,8 @@ This analytic will detect a suspicious process commandline related to windows de #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **powershell_windows_defender_exclusion_commands_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-11-29-detect_rclone_command-line_usage.md b/docs/_posts/2021-11-29-detect_rclone_command-line_usage.md index 6ededee035..d15ca639fd 100644 --- a/docs/_posts/2021-11-29-detect_rclone_command-line_usage.md +++ b/docs/_posts/2021-11-29-detect_rclone_command-line_usage.md @@ -102,8 +102,8 @@ This analytic identifies commonly used command-line arguments used by `rclone.ex #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_rclone](https://github.com/splunk/security_content/blob/develop/macros/process_rclone.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-12-10-curl_download_and_bash_execution.md b/docs/_posts/2021-12-10-curl_download_and_bash_execution.md index 0c8c4f2440..fc7d368380 100644 --- a/docs/_posts/2021-12-10-curl_download_and_bash_execution.md +++ b/docs/_posts/2021-12-10-curl_download_and_bash_execution.md @@ -137,6 +137,7 @@ False positives should be limited, however filtering may be required. #### Associated Analytic story * [Ingress Tool Transfer](/stories/ingress_tool_transfer) * [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) +* [Linux Living Off The Land](/stories/linux_living_off_the_land) diff --git a/docs/_posts/2021-12-13-linux_java_spawning_shell.md b/docs/_posts/2021-12-13-linux_java_spawning_shell.md index 9c3749457a..a36466edd5 100644 --- a/docs/_posts/2021-12-13-linux_java_spawning_shell.md +++ b/docs/_posts/2021-12-13-linux_java_spawning_shell.md @@ -108,8 +108,8 @@ The following analytic identifies the process name of Java, Apache, or Tomcat sp #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [linux_shells](https://github.com/splunk/security_content/blob/develop/macros/linux_shells.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [linux_shells](https://github.com/splunk/security_content/blob/develop/macros/linux_shells.yml) > :information_source: > **linux_java_spawning_shell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-12-13-windows_java_spawning_shells.md b/docs/_posts/2021-12-13-windows_java_spawning_shells.md index 130435c879..e831d6cb09 100644 --- a/docs/_posts/2021-12-13-windows_java_spawning_shells.md +++ b/docs/_posts/2021-12-13-windows_java_spawning_shells.md @@ -109,8 +109,8 @@ The following analytic identifies the process name of java.exe and w3wp.exe spaw #### Macros The SPL above uses the following Macros: -* [windows_shells](https://github.com/splunk/security_content/blob/develop/macros/windows_shells.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [windows_shells](https://github.com/splunk/security_content/blob/develop/macros/windows_shells.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2021-12-17-linux_add_files_in_known_crontab_directories.md b/docs/_posts/2021-12-17-linux_add_files_in_known_crontab_directories.md index 7a887aa3c0..23d9044a7e 100644 --- a/docs/_posts/2021-12-17-linux_add_files_in_known_crontab_directories.md +++ b/docs/_posts/2021-12-17-linux_add_files_in_known_crontab_directories.md @@ -141,6 +141,7 @@ Administrator or network operator can create file in crontab folders for automat #### Associated Analytic story * [Linux Privilege Escalation](/stories/linux_privilege_escalation) * [Linux Persistence Techniques](/stories/linux_persistence_techniques) +* [Linux Living Off The Land](/stories/linux_living_off_the_land) diff --git a/docs/_posts/2021-12-17-linux_at_allow_config_file_creation.md b/docs/_posts/2021-12-17-linux_at_allow_config_file_creation.md index bb6a258cfd..5831abf03f 100644 --- a/docs/_posts/2021-12-17-linux_at_allow_config_file_creation.md +++ b/docs/_posts/2021-12-17-linux_at_allow_config_file_creation.md @@ -141,6 +141,7 @@ Administrator or network operator can create this file for automation purposes. #### Associated Analytic story * [Linux Privilege Escalation](/stories/linux_privilege_escalation) * [Linux Persistence Techniques](/stories/linux_persistence_techniques) +* [Linux Living Off The Land](/stories/linux_living_off_the_land) diff --git a/docs/_posts/2021-12-17-linux_edit_cron_table_parameter.md b/docs/_posts/2021-12-17-linux_edit_cron_table_parameter.md index 953ced99a4..23987f7b9a 100644 --- a/docs/_posts/2021-12-17-linux_edit_cron_table_parameter.md +++ b/docs/_posts/2021-12-17-linux_edit_cron_table_parameter.md @@ -143,6 +143,7 @@ Administrator or network operator can use this application for automation purpos #### Associated Analytic story * [Linux Privilege Escalation](/stories/linux_privilege_escalation) * [Linux Persistence Techniques](/stories/linux_persistence_techniques) +* [Linux Living Off The Land](/stories/linux_living_off_the_land) diff --git a/docs/_posts/2021-12-17-linux_possible_append_cronjob_entry_on_existing_cronjob_file.md b/docs/_posts/2021-12-17-linux_possible_append_cronjob_entry_on_existing_cronjob_file.md index 03a9fd16f5..56f293a970 100644 --- a/docs/_posts/2021-12-17-linux_possible_append_cronjob_entry_on_existing_cronjob_file.md +++ b/docs/_posts/2021-12-17-linux_possible_append_cronjob_entry_on_existing_cronjob_file.md @@ -143,6 +143,7 @@ Administrator or network operator can use this commandline for automation purpos #### Associated Analytic story * [Linux Privilege Escalation](/stories/linux_privilege_escalation) * [Linux Persistence Techniques](/stories/linux_persistence_techniques) +* [Linux Living Off The Land](/stories/linux_living_off_the_land) diff --git a/docs/_posts/2021-12-17-linux_possible_cronjob_modification_with_editor.md b/docs/_posts/2021-12-17-linux_possible_cronjob_modification_with_editor.md index ed0ee79276..03e963a396 100644 --- a/docs/_posts/2021-12-17-linux_possible_cronjob_modification_with_editor.md +++ b/docs/_posts/2021-12-17-linux_possible_cronjob_modification_with_editor.md @@ -143,6 +143,7 @@ Administrator or network operator can use this commandline for automation purpos #### Associated Analytic story * [Linux Privilege Escalation](/stories/linux_privilege_escalation) * [Linux Persistence Techniques](/stories/linux_persistence_techniques) +* [Linux Living Off The Land](/stories/linux_living_off_the_land) diff --git a/docs/_posts/2021-12-20-linux_service_file_created_in_systemd_directory.md b/docs/_posts/2021-12-20-linux_service_file_created_in_systemd_directory.md index 987f16168d..78dfaed993 100644 --- a/docs/_posts/2021-12-20-linux_service_file_created_in_systemd_directory.md +++ b/docs/_posts/2021-12-20-linux_service_file_created_in_systemd_directory.md @@ -141,6 +141,7 @@ Administrator or network operator can create file in systemd folders for automat #### Associated Analytic story * [Linux Privilege Escalation](/stories/linux_privilege_escalation) * [Linux Persistence Techniques](/stories/linux_persistence_techniques) +* [Linux Living Off The Land](/stories/linux_living_off_the_land) diff --git a/docs/_posts/2021-12-20-linux_service_restarted.md b/docs/_posts/2021-12-20-linux_service_restarted.md index f35765c93a..00f629bd59 100644 --- a/docs/_posts/2021-12-20-linux_service_restarted.md +++ b/docs/_posts/2021-12-20-linux_service_restarted.md @@ -143,6 +143,7 @@ Administrator or network operator can use this commandline for automation purpos #### Associated Analytic story * [Linux Privilege Escalation](/stories/linux_privilege_escalation) * [Linux Persistence Techniques](/stories/linux_persistence_techniques) +* [Linux Living Off The Land](/stories/linux_living_off_the_land) diff --git a/docs/_posts/2021-12-20-linux_service_started_or_enabled.md b/docs/_posts/2021-12-20-linux_service_started_or_enabled.md index eec3c468b0..ac79b84055 100644 --- a/docs/_posts/2021-12-20-linux_service_started_or_enabled.md +++ b/docs/_posts/2021-12-20-linux_service_started_or_enabled.md @@ -143,6 +143,7 @@ Administrator or network operator can use this commandline for automation purpos #### Associated Analytic story * [Linux Privilege Escalation](/stories/linux_privilege_escalation) * [Linux Persistence Techniques](/stories/linux_persistence_techniques) +* [Linux Living Off The Land](/stories/linux_living_off_the_land) diff --git a/docs/_posts/2021-12-21-linux_change_file_owner_to_root.md b/docs/_posts/2021-12-21-linux_change_file_owner_to_root.md index 35bdfcb666..5c20b23e48 100644 --- a/docs/_posts/2021-12-21-linux_change_file_owner_to_root.md +++ b/docs/_posts/2021-12-21-linux_change_file_owner_to_root.md @@ -139,6 +139,7 @@ Administrator or network operator can execute this command. Please update the fi #### Associated Analytic story * [Linux Privilege Escalation](/stories/linux_privilege_escalation) * [Linux Persistence Techniques](/stories/linux_persistence_techniques) +* [Linux Living Off The Land](/stories/linux_living_off_the_land) diff --git a/docs/_posts/2021-12-21-linux_setuid_using_chmod_utility.md b/docs/_posts/2021-12-21-linux_setuid_using_chmod_utility.md index a5ce53de0b..bf887c7bca 100644 --- a/docs/_posts/2021-12-21-linux_setuid_using_chmod_utility.md +++ b/docs/_posts/2021-12-21-linux_setuid_using_chmod_utility.md @@ -141,6 +141,7 @@ Administrator or network operator can execute this command. Please update the fi #### Associated Analytic story * [Linux Privilege Escalation](/stories/linux_privilege_escalation) * [Linux Persistence Techniques](/stories/linux_persistence_techniques) +* [Linux Living Off The Land](/stories/linux_living_off_the_land) diff --git a/docs/_posts/2021-12-22-linux_file_created_in_kernel_driver_directory.md b/docs/_posts/2021-12-22-linux_file_created_in_kernel_driver_directory.md index e756d513a2..a86a4f7c18 100644 --- a/docs/_posts/2021-12-22-linux_file_created_in_kernel_driver_directory.md +++ b/docs/_posts/2021-12-22-linux_file_created_in_kernel_driver_directory.md @@ -139,6 +139,7 @@ Administrator or network operator can create file in this folders for automation #### Associated Analytic story * [Linux Privilege Escalation](/stories/linux_privilege_escalation) * [Linux Persistence Techniques](/stories/linux_persistence_techniques) +* [Linux Rootkit](/stories/linux_rootkit) diff --git a/docs/_posts/2021-12-22-linux_insert_kernel_module_using_insmod_utility.md b/docs/_posts/2021-12-22-linux_insert_kernel_module_using_insmod_utility.md index b2488c3634..fa2fdafb1a 100644 --- a/docs/_posts/2021-12-22-linux_insert_kernel_module_using_insmod_utility.md +++ b/docs/_posts/2021-12-22-linux_insert_kernel_module_using_insmod_utility.md @@ -141,6 +141,7 @@ Administrator or network operator can execute this command. Please update the fi #### Associated Analytic story * [Linux Privilege Escalation](/stories/linux_privilege_escalation) * [Linux Persistence Techniques](/stories/linux_persistence_techniques) +* [Linux Rootkit](/stories/linux_rootkit) diff --git a/docs/_posts/2021-12-22-linux_install_kernel_module_using_modprobe_utility.md b/docs/_posts/2021-12-22-linux_install_kernel_module_using_modprobe_utility.md index 7f68a84eeb..c206c91c05 100644 --- a/docs/_posts/2021-12-22-linux_install_kernel_module_using_modprobe_utility.md +++ b/docs/_posts/2021-12-22-linux_install_kernel_module_using_modprobe_utility.md @@ -141,6 +141,7 @@ Administrator or network operator can execute this command. Please update the fi #### Associated Analytic story * [Linux Privilege Escalation](/stories/linux_privilege_escalation) * [Linux Persistence Techniques](/stories/linux_persistence_techniques) +* [Linux Rootkit](/stories/linux_rootkit) diff --git a/docs/_posts/2021-12-23-linux_common_process_for_elevation_control.md b/docs/_posts/2021-12-23-linux_common_process_for_elevation_control.md index c58ac363d4..42458b714f 100644 --- a/docs/_posts/2021-12-23-linux_common_process_for_elevation_control.md +++ b/docs/_posts/2021-12-23-linux_common_process_for_elevation_control.md @@ -141,6 +141,7 @@ Administrator or network operator can execute this command. Please update the fi #### Associated Analytic story * [Linux Privilege Escalation](/stories/linux_privilege_escalation) * [Linux Persistence Techniques](/stories/linux_persistence_techniques) +* [Linux Living Off The Land](/stories/linux_living_off_the_land) diff --git a/docs/_posts/2022-01-11-linux_possible_access_or_modification_of_sshd_config_file.md b/docs/_posts/2022-01-11-linux_possible_access_or_modification_of_sshd_config_file.md index 3116f02ed4..74cdafaa0c 100644 --- a/docs/_posts/2022-01-11-linux_possible_access_or_modification_of_sshd_config_file.md +++ b/docs/_posts/2022-01-11-linux_possible_access_or_modification_of_sshd_config_file.md @@ -139,6 +139,7 @@ Administrator or network operator can use this commandline for automation purpos #### Associated Analytic story * [Linux Privilege Escalation](/stories/linux_privilege_escalation) * [Linux Persistence Techniques](/stories/linux_persistence_techniques) +* [Linux Living Off The Land](/stories/linux_living_off_the_land) diff --git a/docs/_posts/2022-01-11-linux_possible_ssh_key_file_creation.md b/docs/_posts/2022-01-11-linux_possible_ssh_key_file_creation.md index ee96e8edd4..a4cedaeb99 100644 --- a/docs/_posts/2022-01-11-linux_possible_ssh_key_file_creation.md +++ b/docs/_posts/2022-01-11-linux_possible_ssh_key_file_creation.md @@ -137,6 +137,7 @@ Administrator or network operator can create file in ~/.ssh folders for automati #### Associated Analytic story * [Linux Privilege Escalation](/stories/linux_privilege_escalation) * [Linux Persistence Techniques](/stories/linux_persistence_techniques) +* [Linux Living Off The Land](/stories/linux_living_off_the_land) diff --git a/docs/_posts/2022-01-12-powershell_-_connect_to_internet_with_hidden_window.md b/docs/_posts/2022-01-12-powershell_-_connect_to_internet_with_hidden_window.md index 35a8742ac8..a7e3a6be4d 100644 --- a/docs/_posts/2022-01-12-powershell_-_connect_to_internet_with_hidden_window.md +++ b/docs/_posts/2022-01-12-powershell_-_connect_to_internet_with_hidden_window.md @@ -127,8 +127,8 @@ The following hunting analytic identifies PowerShell commands utilizing the Wind #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) > :information_source: > **powershell_-_connect_to_internet_with_hidden_window_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-01-18-cmd_carry_out_string_command_parameter.md b/docs/_posts/2022-01-18-cmd_carry_out_string_command_parameter.md index 10fc37afbb..9c48054f44 100644 --- a/docs/_posts/2022-01-18-cmd_carry_out_string_command_parameter.md +++ b/docs/_posts/2022-01-18-cmd_carry_out_string_command_parameter.md @@ -112,9 +112,9 @@ The following analytic identifies command-line arguments where `cmd.exe /c` is u #### Macros The SPL above uses the following Macros: -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) > :information_source: > **cmd_carry_out_string_command_parameter_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. @@ -146,6 +146,7 @@ False positives may be high based on legitimate scripted code in any environment * [Hermetic Wiper](/stories/hermetic_wiper) * [Living Off The Land](/stories/living_off_the_land) * [Azorult](/stories/azorult) +* [DarkCrystal RAT](/stories/darkcrystal_rat) diff --git a/docs/_posts/2022-01-18-malicious_powershell_process_-_encoded_command.md b/docs/_posts/2022-01-18-malicious_powershell_process_-_encoded_command.md index 77efddec03..b719ab44b5 100644 --- a/docs/_posts/2022-01-18-malicious_powershell_process_-_encoded_command.md +++ b/docs/_posts/2022-01-18-malicious_powershell_process_-_encoded_command.md @@ -120,8 +120,8 @@ Alternatively, may use regex per matching here https://regexr.com/662ov. #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) > :information_source: > **malicious_powershell_process_-_encoded_command_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. @@ -147,6 +147,7 @@ System administrators may use this option, but it's not common. * [Malicious PowerShell](/stories/malicious_powershell) * [NOBELIUM Group](/stories/nobelium_group) * [WhisperGate](/stories/whispergate) +* [DarkCrystal RAT](/stories/darkcrystal_rat) diff --git a/docs/_posts/2022-01-19-windows_dotnet_binary_in_non_standard_path.md b/docs/_posts/2022-01-19-windows_dotnet_binary_in_non_standard_path.md index 1ce9a54f4f..d77807e154 100644 --- a/docs/_posts/2022-01-19-windows_dotnet_binary_in_non_standard_path.md +++ b/docs/_posts/2022-01-19-windows_dotnet_binary_in_non_standard_path.md @@ -118,8 +118,8 @@ The following analytic identifies native .net binaries within the Windows operat #### Macros The SPL above uses the following Macros: -* [is_net_windows_file](https://github.com/splunk/security_content/blob/develop/macros/is_net_windows_file.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [is_net_windows_file](https://github.com/splunk/security_content/blob/develop/macros/is_net_windows_file.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2022-01-20-ping_sleep_batch_command.md b/docs/_posts/2022-01-20-ping_sleep_batch_command.md index 24d910afbf..548baa0f37 100644 --- a/docs/_posts/2022-01-20-ping_sleep_batch_command.md +++ b/docs/_posts/2022-01-20-ping_sleep_batch_command.md @@ -115,9 +115,9 @@ This analytic will identify the possible execution of ping sleep batch commands. #### Macros The SPL above uses the following Macros: -* [process_ping](https://github.com/splunk/security_content/blob/develop/macros/process_ping.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_ping](https://github.com/splunk/security_content/blob/develop/macros/process_ping.yml) > :information_source: > **ping_sleep_batch_command_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-01-24-windows_nirsoft_utilities.md b/docs/_posts/2022-01-24-windows_nirsoft_utilities.md index 5a80b1df2e..c8dcd7fcfc 100644 --- a/docs/_posts/2022-01-24-windows_nirsoft_utilities.md +++ b/docs/_posts/2022-01-24-windows_nirsoft_utilities.md @@ -103,8 +103,8 @@ The following hunting analytic assists with identifying the proces execution of #### Macros The SPL above uses the following Macros: -* [is_nirsoft_software](https://github.com/splunk/security_content/blob/develop/macros/is_nirsoft_software.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [is_nirsoft_software](https://github.com/splunk/security_content/blob/develop/macros/is_nirsoft_software.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2022-01-28-linux_pkexec_privilege_escalation.md b/docs/_posts/2022-01-28-linux_pkexec_privilege_escalation.md index b4d42dcb83..7a5b67753c 100644 --- a/docs/_posts/2022-01-28-linux_pkexec_privilege_escalation.md +++ b/docs/_posts/2022-01-28-linux_pkexec_privilege_escalation.md @@ -137,6 +137,7 @@ False positives may be present, filter as needed. #### Associated Analytic story * [Linux Privilege Escalation](/stories/linux_privilege_escalation) +* [Linux Living Off The Land](/stories/linux_living_off_the_land) diff --git a/docs/_posts/2022-02-03-o365_added_service_principal.md b/docs/_posts/2022-02-03-o365_added_service_principal.md index 0f07102a62..5f9a419895 100644 --- a/docs/_posts/2022-02-03-o365_added_service_principal.md +++ b/docs/_posts/2022-02-03-o365_added_service_principal.md @@ -105,8 +105,8 @@ This search detects the creation of a new Federation setting by alerting about a #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **o365_added_service_principal_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-02-03-o365_bypass_mfa_via_trusted_ip.md b/docs/_posts/2022-02-03-o365_bypass_mfa_via_trusted_ip.md index 250614bfde..861cd2db17 100644 --- a/docs/_posts/2022-02-03-o365_bypass_mfa_via_trusted_ip.md +++ b/docs/_posts/2022-02-03-o365_bypass_mfa_via_trusted_ip.md @@ -110,8 +110,8 @@ This search detects newly added IP addresses/CIDR blocks to the list of MFA Trus #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **o365_bypass_mfa_via_trusted_ip_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-02-03-o365_disable_mfa.md b/docs/_posts/2022-02-03-o365_disable_mfa.md index 7dc316494e..c8571f10e9 100644 --- a/docs/_posts/2022-02-03-o365_disable_mfa.md +++ b/docs/_posts/2022-02-03-o365_disable_mfa.md @@ -102,8 +102,8 @@ This search detects when multi factor authentication has been disabled, what ent #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **o365_disable_mfa_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-02-07-windows_remote_assistance_spawning_process.md b/docs/_posts/2022-02-07-windows_remote_assistance_spawning_process.md index 250e164d6a..750df54c18 100644 --- a/docs/_posts/2022-02-07-windows_remote_assistance_spawning_process.md +++ b/docs/_posts/2022-02-07-windows_remote_assistance_spawning_process.md @@ -103,8 +103,8 @@ The following analytic identifies the use of Microsoft Remote Assistance, msra.e #### Macros The SPL above uses the following Macros: -* [windows_shells](https://github.com/splunk/security_content/blob/develop/macros/windows_shells.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [windows_shells](https://github.com/splunk/security_content/blob/develop/macros/windows_shells.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2022-02-08-rundll_loading_dll_by_ordinal.md b/docs/_posts/2022-02-08-rundll_loading_dll_by_ordinal.md index 64239bc1a7..1ca1e1d4f7 100644 --- a/docs/_posts/2022-02-08-rundll_loading_dll_by_ordinal.md +++ b/docs/_posts/2022-02-08-rundll_loading_dll_by_ordinal.md @@ -113,8 +113,8 @@ The following analytic identifies rundll32.exe loading an export function by ord #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2022-02-09-kerberoasting_spn_request_with_rc4_encryption.md b/docs/_posts/2022-02-09-kerberoasting_spn_request_with_rc4_encryption.md index 8dacc63d10..b8aee83d87 100644 --- a/docs/_posts/2022-02-09-kerberoasting_spn_request_with_rc4_encryption.md +++ b/docs/_posts/2022-02-09-kerberoasting_spn_request_with_rc4_encryption.md @@ -110,8 +110,8 @@ The following analytic leverages Kerberos Event 4769, A Kerberos service ticket #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **kerberoasting_spn_request_with_rc4_encryption_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-02-15-windows_diskshadow_proxy_execution.md b/docs/_posts/2022-02-15-windows_diskshadow_proxy_execution.md index 1ca1eaee9e..ff5d46003c 100644 --- a/docs/_posts/2022-02-15-windows_diskshadow_proxy_execution.md +++ b/docs/_posts/2022-02-15-windows_diskshadow_proxy_execution.md @@ -106,9 +106,9 @@ DiskShadow.exe is a Microsoft Signed binary present on Windows Server. It has a #### Macros The SPL above uses the following Macros: -* [process_diskshadow](https://github.com/splunk/security_content/blob/develop/macros/process_diskshadow.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_diskshadow](https://github.com/splunk/security_content/blob/develop/macros/process_diskshadow.yml) > :information_source: > **windows_diskshadow_proxy_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-02-18-o365_excessive_authentication_failures_alert.md b/docs/_posts/2022-02-18-o365_excessive_authentication_failures_alert.md index 37dfa77e2e..9552bd6766 100644 --- a/docs/_posts/2022-02-18-o365_excessive_authentication_failures_alert.md +++ b/docs/_posts/2022-02-18-o365_excessive_authentication_failures_alert.md @@ -101,8 +101,8 @@ This search detects when an excessive number of authentication failures occur th #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **o365_excessive_authentication_failures_alert_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-02-22-windows_wmi_process_call_create.md b/docs/_posts/2022-02-22-windows_wmi_process_call_create.md index 96eedbf53b..354377901f 100644 --- a/docs/_posts/2022-02-22-windows_wmi_process_call_create.md +++ b/docs/_posts/2022-02-22-windows_wmi_process_call_create.md @@ -108,9 +108,9 @@ This analytic is to look for wmi commandlines to execute or create process. This #### Macros The SPL above uses the following Macros: -* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) > :information_source: > **windows_wmi_process_call_create_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-02-23-windows_excessive_disabled_services_event.md b/docs/_posts/2022-02-23-windows_excessive_disabled_services_event.md index 0fa7e197b5..46b18ec802 100644 --- a/docs/_posts/2022-02-23-windows_excessive_disabled_services_event.md +++ b/docs/_posts/2022-02-23-windows_excessive_disabled_services_event.md @@ -113,8 +113,8 @@ This analytic will identify suspicious excessive number of system events of serv #### Macros The SPL above uses the following Macros: -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) > :information_source: > **windows_excessive_disabled_services_event_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-02-24-detect_empire_with_powershell_script_block_logging.md b/docs/_posts/2022-02-24-detect_empire_with_powershell_script_block_logging.md index 489425ca79..a7a1a4cd9b 100644 --- a/docs/_posts/2022-02-24-detect_empire_with_powershell_script_block_logging.md +++ b/docs/_posts/2022-02-24-detect_empire_with_powershell_script_block_logging.md @@ -107,8 +107,8 @@ During triage, review parallel processes using an EDR product or 4688 events. It #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **detect_empire_with_powershell_script_block_logging_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-02-24-detect_mimikatz_with_powershell_script_block_logging.md b/docs/_posts/2022-02-24-detect_mimikatz_with_powershell_script_block_logging.md index e4b8cd9522..b21a7a1fd3 100644 --- a/docs/_posts/2022-02-24-detect_mimikatz_with_powershell_script_block_logging.md +++ b/docs/_posts/2022-02-24-detect_mimikatz_with_powershell_script_block_logging.md @@ -107,8 +107,8 @@ During triage, review parallel processes using an EDR product or 4688 events. It #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **detect_mimikatz_with_powershell_script_block_logging_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-02-24-get-foresttrust_with_powershell_script_block.md b/docs/_posts/2022-02-24-get-foresttrust_with_powershell_script_block.md index 5182816179..03a15db1b5 100644 --- a/docs/_posts/2022-02-24-get-foresttrust_with_powershell_script_block.md +++ b/docs/_posts/2022-02-24-get-foresttrust_with_powershell_script_block.md @@ -107,8 +107,8 @@ During triage, review parallel processes using an EDR product or 4688 events. It #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **get-foresttrust_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-02-25-powershell_domain_enumeration.md b/docs/_posts/2022-02-25-powershell_domain_enumeration.md index 3013b00e9f..2afffac1df 100644 --- a/docs/_posts/2022-02-25-powershell_domain_enumeration.md +++ b/docs/_posts/2022-02-25-powershell_domain_enumeration.md @@ -107,8 +107,8 @@ During triage, review parallel processes using an EDR product or 4688 events. It #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **powershell_domain_enumeration_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-02-25-powershell_enable_smb1protocol_feature.md b/docs/_posts/2022-02-25-powershell_enable_smb1protocol_feature.md index 05dd1e46ee..ed94d97bb7 100644 --- a/docs/_posts/2022-02-25-powershell_enable_smb1protocol_feature.md +++ b/docs/_posts/2022-02-25-powershell_enable_smb1protocol_feature.md @@ -106,8 +106,8 @@ This search is to detect a suspicious enabling of smb1protocol through "powershe #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **powershell_enable_smb1protocol_feature_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-02-25-powershell_fileless_process_injection_via_getprocaddress.md b/docs/_posts/2022-02-25-powershell_fileless_process_injection_via_getprocaddress.md index 161f350dd4..5abd2732e9 100644 --- a/docs/_posts/2022-02-25-powershell_fileless_process_injection_via_getprocaddress.md +++ b/docs/_posts/2022-02-25-powershell_fileless_process_injection_via_getprocaddress.md @@ -114,8 +114,8 @@ During triage, review parallel processes using an EDR product or 4688 events. It #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **powershell_fileless_process_injection_via_getprocaddress_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-02-25-powershell_processing_stream_of_data.md b/docs/_posts/2022-02-25-powershell_processing_stream_of_data.md index f037eba0bd..234545e5a1 100644 --- a/docs/_posts/2022-02-25-powershell_processing_stream_of_data.md +++ b/docs/_posts/2022-02-25-powershell_processing_stream_of_data.md @@ -105,8 +105,8 @@ The following analytic identifies suspicious PowerShell script execution via Eve #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **powershell_processing_stream_of_data_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-02-25-recon_using_wmi_class.md b/docs/_posts/2022-02-25-recon_using_wmi_class.md index 42740bd3da..4077b5c3f4 100644 --- a/docs/_posts/2022-02-25-recon_using_wmi_class.md +++ b/docs/_posts/2022-02-25-recon_using_wmi_class.md @@ -105,8 +105,8 @@ The following analytic identifies suspicious PowerShell via EventCode 4104, wher #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **recon_using_wmi_class_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-02-26-serviceprincipalnames_discovery_with_powershell.md b/docs/_posts/2022-02-26-serviceprincipalnames_discovery_with_powershell.md index 765203e484..cf23e2459f 100644 --- a/docs/_posts/2022-02-26-serviceprincipalnames_discovery_with_powershell.md +++ b/docs/_posts/2022-02-26-serviceprincipalnames_discovery_with_powershell.md @@ -104,8 +104,8 @@ During triage, review parallel processes for further suspicious activity. #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **serviceprincipalnames_discovery_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-04-macos_lolbin.md b/docs/_posts/2022-03-04-macos_lolbin.md index 2d6f2c8949..94c82a2200 100644 --- a/docs/_posts/2022-03-04-macos_lolbin.md +++ b/docs/_posts/2022-03-04-macos_lolbin.md @@ -115,8 +115,8 @@ Detect multiple executions of Living off the Land (LOLbin) binaries in a short p #### Macros The SPL above uses the following Macros: -* [osquery](https://github.com/splunk/security_content/blob/develop/macros/osquery.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [osquery](https://github.com/splunk/security_content/blob/develop/macros/osquery.yml) > :information_source: > **macos_lolbin_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-15-detect_regsvcs_with_no_command_line_arguments.md b/docs/_posts/2022-03-15-detect_regsvcs_with_no_command_line_arguments.md index 2a33a397b7..a4972826ff 100644 --- a/docs/_posts/2022-03-15-detect_regsvcs_with_no_command_line_arguments.md +++ b/docs/_posts/2022-03-15-detect_regsvcs_with_no_command_line_arguments.md @@ -113,8 +113,8 @@ The following analytic identifies regsvcs.exe with no command line arguments. Th #### Macros The SPL above uses the following Macros: -* [process_regsvcs](https://github.com/splunk/security_content/blob/develop/macros/process_regsvcs.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [process_regsvcs](https://github.com/splunk/security_content/blob/develop/macros/process_regsvcs.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2022-03-15-kerberos_service_ticket_request_using_rc4_encryption.md b/docs/_posts/2022-03-15-kerberos_service_ticket_request_using_rc4_encryption.md index 2b4295dc4f..54d27c0615 100644 --- a/docs/_posts/2022-03-15-kerberos_service_ticket_request_using_rc4_encryption.md +++ b/docs/_posts/2022-03-15-kerberos_service_ticket_request_using_rc4_encryption.md @@ -105,8 +105,8 @@ The following analytic leverages Kerberos Event 4769, A Kerberos service ticket #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **kerberos_service_ticket_request_using_rc4_encryption_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-15-rundll32_with_no_command_line_arguments_with_network.md b/docs/_posts/2022-03-15-rundll32_with_no_command_line_arguments_with_network.md index d7c1351544..8dc7db224b 100644 --- a/docs/_posts/2022-03-15-rundll32_with_no_command_line_arguments_with_network.md +++ b/docs/_posts/2022-03-15-rundll32_with_no_command_line_arguments_with_network.md @@ -118,8 +118,8 @@ The following analytic identifies rundll32.exe with no command line arguments an #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2022-03-15-suspicious_gpupdate_no_command_line_arguments.md b/docs/_posts/2022-03-15-suspicious_gpupdate_no_command_line_arguments.md index 2f48fe3ae8..686650b32a 100644 --- a/docs/_posts/2022-03-15-suspicious_gpupdate_no_command_line_arguments.md +++ b/docs/_posts/2022-03-15-suspicious_gpupdate_no_command_line_arguments.md @@ -105,8 +105,8 @@ The following analytic identifies gpupdate.exe with no command line arguments. I #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_gpupdate](https://github.com/splunk/security_content/blob/develop/macros/process_gpupdate.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_gpupdate](https://github.com/splunk/security_content/blob/develop/macros/process_gpupdate.yml) > :information_source: > **suspicious_gpupdate_no_command_line_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-15-suspicious_rundll32_no_command_line_arguments.md b/docs/_posts/2022-03-15-suspicious_rundll32_no_command_line_arguments.md index 7df417a8ed..3a513ba44a 100644 --- a/docs/_posts/2022-03-15-suspicious_rundll32_no_command_line_arguments.md +++ b/docs/_posts/2022-03-15-suspicious_rundll32_no_command_line_arguments.md @@ -118,8 +118,8 @@ The following analytic identifies rundll32.exe with no command line arguments. I #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) > :information_source: diff --git a/docs/_posts/2022-03-22-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md b/docs/_posts/2022-03-22-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md index 74f5f965b3..b92d9ede9a 100644 --- a/docs/_posts/2022-03-22-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md +++ b/docs/_posts/2022-03-22-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md @@ -100,8 +100,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **get_addefaultdomainpasswordpolicy_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-22-get_domainuser_with_powershell_script_block.md b/docs/_posts/2022-03-22-get_domainuser_with_powershell_script_block.md index da5c5a0d7a..6537929b66 100644 --- a/docs/_posts/2022-03-22-get_domainuser_with_powershell_script_block.md +++ b/docs/_posts/2022-03-22-get_domainuser_with_powershell_script_block.md @@ -105,8 +105,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **get_domainuser_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-22-get_wmiobject_group_discovery_with_script_block_logging.md b/docs/_posts/2022-03-22-get_wmiobject_group_discovery_with_script_block_logging.md index 3b0d03259d..bc2cd769f7 100644 --- a/docs/_posts/2022-03-22-get_wmiobject_group_discovery_with_script_block_logging.md +++ b/docs/_posts/2022-03-22-get_wmiobject_group_discovery_with_script_block_logging.md @@ -107,8 +107,8 @@ During triage, review parallel processes using an EDR product or 4688 events. It #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **get_wmiobject_group_discovery_with_script_block_logging_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-22-getadgroup_with_powershell_script_block.md b/docs/_posts/2022-03-22-getadgroup_with_powershell_script_block.md index d41c63b039..2f98054adc 100644 --- a/docs/_posts/2022-03-22-getadgroup_with_powershell_script_block.md +++ b/docs/_posts/2022-03-22-getadgroup_with_powershell_script_block.md @@ -105,8 +105,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **getadgroup_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-22-getcurrent_user_with_powershell_script_block.md b/docs/_posts/2022-03-22-getcurrent_user_with_powershell_script_block.md index 9372bf60be..c2c64120a2 100644 --- a/docs/_posts/2022-03-22-getcurrent_user_with_powershell_script_block.md +++ b/docs/_posts/2022-03-22-getcurrent_user_with_powershell_script_block.md @@ -100,8 +100,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **getcurrent_user_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-22-getlocaluser_with_powershell_script_block.md b/docs/_posts/2022-03-22-getlocaluser_with_powershell_script_block.md index daf52c2a5f..c64352aa94 100644 --- a/docs/_posts/2022-03-22-getlocaluser_with_powershell_script_block.md +++ b/docs/_posts/2022-03-22-getlocaluser_with_powershell_script_block.md @@ -110,8 +110,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **getlocaluser_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-22-interactive_session_on_remote_endpoint_with_powershell.md b/docs/_posts/2022-03-22-interactive_session_on_remote_endpoint_with_powershell.md index 794c52a432..6b739035e2 100644 --- a/docs/_posts/2022-03-22-interactive_session_on_remote_endpoint_with_powershell.md +++ b/docs/_posts/2022-03-22-interactive_session_on_remote_endpoint_with_powershell.md @@ -105,8 +105,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **interactive_session_on_remote_endpoint_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-22-kerberos_pre-authentication_flag_disabled_with_powershell.md b/docs/_posts/2022-03-22-kerberos_pre-authentication_flag_disabled_with_powershell.md index 1dbda3af81..ae8a733c0f 100644 --- a/docs/_posts/2022-03-22-kerberos_pre-authentication_flag_disabled_with_powershell.md +++ b/docs/_posts/2022-03-22-kerberos_pre-authentication_flag_disabled_with_powershell.md @@ -105,8 +105,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **kerberos_pre-authentication_flag_disabled_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-22-powershell_execute_com_object.md b/docs/_posts/2022-03-22-powershell_execute_com_object.md index d817299c3a..91cbf07480 100644 --- a/docs/_posts/2022-03-22-powershell_execute_com_object.md +++ b/docs/_posts/2022-03-22-powershell_execute_com_object.md @@ -113,8 +113,8 @@ This search is to detect a COM CLSID execution through powershell. This techniqu #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **powershell_execute_com_object_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-22-powershell_using_memory_as_backing_store.md b/docs/_posts/2022-03-22-powershell_using_memory_as_backing_store.md index 32b10e6e0d..788a155992 100644 --- a/docs/_posts/2022-03-22-powershell_using_memory_as_backing_store.md +++ b/docs/_posts/2022-03-22-powershell_using_memory_as_backing_store.md @@ -105,8 +105,8 @@ The following analytic identifies suspicious PowerShell script execution via Eve #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **powershell_using_memory_as_backing_store_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-22-recon_avproduct_through_pwh_or_wmi.md b/docs/_posts/2022-03-22-recon_avproduct_through_pwh_or_wmi.md index c9a09b279a..85c22023b0 100644 --- a/docs/_posts/2022-03-22-recon_avproduct_through_pwh_or_wmi.md +++ b/docs/_posts/2022-03-22-recon_avproduct_through_pwh_or_wmi.md @@ -100,8 +100,8 @@ The following analytic identifies suspicious PowerShell script execution via Eve #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **recon_avproduct_through_pwh_or_wmi_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-22-remote_process_instantiation_via_dcom_and_powershell_script_block.md b/docs/_posts/2022-03-22-remote_process_instantiation_via_dcom_and_powershell_script_block.md index 669000fd6a..d1a7fe8c0b 100644 --- a/docs/_posts/2022-03-22-remote_process_instantiation_via_dcom_and_powershell_script_block.md +++ b/docs/_posts/2022-03-22-remote_process_instantiation_via_dcom_and_powershell_script_block.md @@ -105,8 +105,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **remote_process_instantiation_via_dcom_and_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-22-remote_process_instantiation_via_winrm_and_powershell_script_block.md b/docs/_posts/2022-03-22-remote_process_instantiation_via_winrm_and_powershell_script_block.md index 9aff5320c5..adfc49a7d9 100644 --- a/docs/_posts/2022-03-22-remote_process_instantiation_via_winrm_and_powershell_script_block.md +++ b/docs/_posts/2022-03-22-remote_process_instantiation_via_winrm_and_powershell_script_block.md @@ -105,8 +105,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **remote_process_instantiation_via_winrm_and_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-22-user_discovery_with_env_vars_powershell_script_block.md b/docs/_posts/2022-03-22-user_discovery_with_env_vars_powershell_script_block.md index c4cca2d7ac..b3eca55344 100644 --- a/docs/_posts/2022-03-22-user_discovery_with_env_vars_powershell_script_block.md +++ b/docs/_posts/2022-03-22-user_discovery_with_env_vars_powershell_script_block.md @@ -100,8 +100,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **user_discovery_with_env_vars_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-28-windows_get-adcomputer_unconstrained_delegation_discovery.md b/docs/_posts/2022-03-28-windows_get-adcomputer_unconstrained_delegation_discovery.md index 5b961d19a5..a3aedd0f60 100644 --- a/docs/_posts/2022-03-28-windows_get-adcomputer_unconstrained_delegation_discovery.md +++ b/docs/_posts/2022-03-28-windows_get-adcomputer_unconstrained_delegation_discovery.md @@ -106,8 +106,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **windows_get-adcomputer_unconstrained_delegation_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-28-windows_powerview_unconstrained_delegation_discovery.md b/docs/_posts/2022-03-28-windows_powerview_unconstrained_delegation_discovery.md index 3864819c70..bf1b12c71f 100644 --- a/docs/_posts/2022-03-28-windows_powerview_unconstrained_delegation_discovery.md +++ b/docs/_posts/2022-03-28-windows_powerview_unconstrained_delegation_discovery.md @@ -106,8 +106,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **windows_powerview_unconstrained_delegation_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-03-31-windows_powerview_constrained_delegation_discovery.md b/docs/_posts/2022-03-31-windows_powerview_constrained_delegation_discovery.md index 2d39394e51..9b6fa36004 100644 --- a/docs/_posts/2022-03-31-windows_powerview_constrained_delegation_discovery.md +++ b/docs/_posts/2022-03-31-windows_powerview_constrained_delegation_discovery.md @@ -106,8 +106,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **windows_powerview_constrained_delegation_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-04-02-getnettcpconnection_with_powershell_script_block.md b/docs/_posts/2022-04-02-getnettcpconnection_with_powershell_script_block.md index 5057a097e8..4567d87c32 100644 --- a/docs/_posts/2022-04-02-getnettcpconnection_with_powershell_script_block.md +++ b/docs/_posts/2022-04-02-getnettcpconnection_with_powershell_script_block.md @@ -99,8 +99,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **getnettcpconnection_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-04-04-github_actions_disable_security_workflow.md b/docs/_posts/2022-04-04-github_actions_disable_security_workflow.md index cb85c01f90..008e97ef0a 100644 --- a/docs/_posts/2022-04-04-github_actions_disable_security_workflow.md +++ b/docs/_posts/2022-04-04-github_actions_disable_security_workflow.md @@ -113,8 +113,8 @@ This search detects a disabled security workflow in GitHub Actions. An attacker #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [github](https://github.com/splunk/security_content/blob/develop/macros/github.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **github_actions_disable_security_workflow_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-04-04-windows_driver_load_non-standard_path.md b/docs/_posts/2022-04-04-windows_driver_load_non-standard_path.md index a49622fd78..e8bf097fdc 100644 --- a/docs/_posts/2022-04-04-windows_driver_load_non-standard_path.md +++ b/docs/_posts/2022-04-04-windows_driver_load_non-standard_path.md @@ -107,8 +107,8 @@ The following analytic uses Windows EventCode 7045 to identify new Kernel Mode D #### Macros The SPL above uses the following Macros: -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) > :information_source: > **windows_driver_load_non-standard_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-04-04-windows_event_for_service_disabled.md b/docs/_posts/2022-04-04-windows_event_for_service_disabled.md index ba8933f81a..5d7224b035 100644 --- a/docs/_posts/2022-04-04-windows_event_for_service_disabled.md +++ b/docs/_posts/2022-04-04-windows_event_for_service_disabled.md @@ -112,8 +112,8 @@ This analytic will identify suspicious system event of services that was modifie #### Macros The SPL above uses the following Macros: -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) > :information_source: > **windows_event_for_service_disabled_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-04-06-web_spring4shell_http_request_class_module.md b/docs/_posts/2022-04-06-web_spring4shell_http_request_class_module.md index aa65234c4a..d73eeffe74 100644 --- a/docs/_posts/2022-04-06-web_spring4shell_http_request_class_module.md +++ b/docs/_posts/2022-04-06-web_spring4shell_http_request_class_module.md @@ -113,8 +113,8 @@ The following analytic identifies the payload related to Spring4Shell, CVE-2022- #### Macros The SPL above uses the following Macros: -* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) > :information_source: > **web_spring4shell_http_request_class_module_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-04-07-any_powershell_downloadfile.md b/docs/_posts/2022-04-07-any_powershell_downloadfile.md index 30bbaab9f1..e59a109794 100644 --- a/docs/_posts/2022-04-07-any_powershell_downloadfile.md +++ b/docs/_posts/2022-04-07-any_powershell_downloadfile.md @@ -118,8 +118,8 @@ The following analytic identifies the use of PowerShell downloading a file using #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) > :information_source: > **any_powershell_downloadfile_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. @@ -150,6 +150,7 @@ False positives may be present and filtering will need to occur by parent proces * [Malicious PowerShell](/stories/malicious_powershell) * [Ingress Tool Transfer](/stories/ingress_tool_transfer) * [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) +* [DarkCrystal RAT](/stories/darkcrystal_rat) diff --git a/docs/_posts/2022-04-07-any_powershell_downloadstring.md b/docs/_posts/2022-04-07-any_powershell_downloadstring.md index c2f2d33779..4ed02b76f5 100644 --- a/docs/_posts/2022-04-07-any_powershell_downloadstring.md +++ b/docs/_posts/2022-04-07-any_powershell_downloadstring.md @@ -113,8 +113,8 @@ The following analytic identifies the use of PowerShell downloading a file using #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) > :information_source: > **any_powershell_downloadstring_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-04-18-nltest_domain_trust_discovery.md b/docs/_posts/2022-04-18-nltest_domain_trust_discovery.md index 2a31c7aba7..223c93175a 100644 --- a/docs/_posts/2022-04-18-nltest_domain_trust_discovery.md +++ b/docs/_posts/2022-04-18-nltest_domain_trust_discovery.md @@ -108,8 +108,8 @@ This search looks for the execution of `nltest.exe` with command-line arguments #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_nltest](https://github.com/splunk/security_content/blob/develop/macros/process_nltest.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_nltest](https://github.com/splunk/security_content/blob/develop/macros/process_nltest.yml) > :information_source: > **nltest_domain_trust_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-04-22-linux_adding_crontab_using_list_parameter.md b/docs/_posts/2022-04-22-linux_adding_crontab_using_list_parameter.md index c2a8c673ef..23b9dfd822 100644 --- a/docs/_posts/2022-04-22-linux_adding_crontab_using_list_parameter.md +++ b/docs/_posts/2022-04-22-linux_adding_crontab_using_list_parameter.md @@ -144,6 +144,7 @@ Administrator or network operator can use this application for automation purpos * [Industroyer2](/stories/industroyer2) * [Linux Privilege Escalation](/stories/linux_privilege_escalation) * [Linux Persistence Techniques](/stories/linux_persistence_techniques) +* [Linux Living Off The Land](/stories/linux_living_off_the_land) diff --git a/docs/_posts/2022-04-25-windows_linked_policies_in_adsi_discovery.md b/docs/_posts/2022-04-25-windows_linked_policies_in_adsi_discovery.md index 34af68501f..70fa0e4f3f 100644 --- a/docs/_posts/2022-04-25-windows_linked_policies_in_adsi_discovery.md +++ b/docs/_posts/2022-04-25-windows_linked_policies_in_adsi_discovery.md @@ -112,8 +112,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **windows_linked_policies_in_adsi_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-04-25-windows_root_domain_linked_policies_discovery.md b/docs/_posts/2022-04-25-windows_root_domain_linked_policies_discovery.md index db7c76d204..dc17c69bb6 100644 --- a/docs/_posts/2022-04-25-windows_root_domain_linked_policies_discovery.md +++ b/docs/_posts/2022-04-25-windows_root_domain_linked_policies_discovery.md @@ -112,8 +112,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **windows_root_domain_linked_policies_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-04-26-powershell_fileless_script_contains_base64_encoded_content.md b/docs/_posts/2022-04-26-powershell_fileless_script_contains_base64_encoded_content.md index b38862bd59..8ec146fe4c 100644 --- a/docs/_posts/2022-04-26-powershell_fileless_script_contains_base64_encoded_content.md +++ b/docs/_posts/2022-04-26-powershell_fileless_script_contains_base64_encoded_content.md @@ -113,8 +113,8 @@ During triage, review parallel processes using an EDR product or 4688 events. It #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **powershell_fileless_script_contains_base64_encoded_content_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-04-26-powershell_get_localgroup_discovery_with_script_block_logging.md b/docs/_posts/2022-04-26-powershell_get_localgroup_discovery_with_script_block_logging.md index c95d548153..ee2fee3daf 100644 --- a/docs/_posts/2022-04-26-powershell_get_localgroup_discovery_with_script_block_logging.md +++ b/docs/_posts/2022-04-26-powershell_get_localgroup_discovery_with_script_block_logging.md @@ -107,8 +107,8 @@ During triage, review parallel processes using an EDR product or 4688 events. It #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **powershell_get_localgroup_discovery_with_script_block_logging_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-04-26-windows_hidden_schedule_task_settings.md b/docs/_posts/2022-04-26-windows_hidden_schedule_task_settings.md index 41c9d503c8..78de749e75 100644 --- a/docs/_posts/2022-04-26-windows_hidden_schedule_task_settings.md +++ b/docs/_posts/2022-04-26-windows_hidden_schedule_task_settings.md @@ -111,8 +111,8 @@ The following query utilizes Windows Security EventCode 4698, A scheduled task w #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **windows_hidden_schedule_task_settings_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-04-27-windows_computer_account_created_by_computer_account.md b/docs/_posts/2022-04-27-windows_computer_account_created_by_computer_account.md index 0716084d03..2c0de92432 100644 --- a/docs/_posts/2022-04-27-windows_computer_account_created_by_computer_account.md +++ b/docs/_posts/2022-04-27-windows_computer_account_created_by_computer_account.md @@ -107,8 +107,8 @@ The following analytic identifes a Computer Account creating a new Computer Acco #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **windows_computer_account_created_by_computer_account_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-04-27-windows_computer_account_requesting_kerberos_ticket.md b/docs/_posts/2022-04-27-windows_computer_account_requesting_kerberos_ticket.md index 6508556aaa..b5599f262c 100644 --- a/docs/_posts/2022-04-27-windows_computer_account_requesting_kerberos_ticket.md +++ b/docs/_posts/2022-04-27-windows_computer_account_requesting_kerberos_ticket.md @@ -107,8 +107,8 @@ The following analytic identifies a ComputerAccount requesting a Kerberos Ticket #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **windows_computer_account_requesting_kerberos_ticket_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-04-27-windows_kerberos_local_successful_logon.md b/docs/_posts/2022-04-27-windows_kerberos_local_successful_logon.md index 3d6baf3523..8801b6f266 100644 --- a/docs/_posts/2022-04-27-windows_kerberos_local_successful_logon.md +++ b/docs/_posts/2022-04-27-windows_kerberos_local_successful_logon.md @@ -107,8 +107,8 @@ The following analytic identifies a local successful authentication event on a W #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **windows_kerberos_local_successful_logon_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-04-28-windows_computer_account_with_spn.md b/docs/_posts/2022-04-28-windows_computer_account_with_spn.md index 7c459b8206..82539a9f8d 100644 --- a/docs/_posts/2022-04-28-windows_computer_account_with_spn.md +++ b/docs/_posts/2022-04-28-windows_computer_account_with_spn.md @@ -109,8 +109,8 @@ The following analytic identifies two SPNs, HOST and RestrictedKrbHost, added us #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) > :information_source: > **windows_computer_account_with_spn_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-02-delete_shadowcopy_with_powershell.md b/docs/_posts/2022-05-02-delete_shadowcopy_with_powershell.md index f8abf6e8cb..4e9539d792 100644 --- a/docs/_posts/2022-05-02-delete_shadowcopy_with_powershell.md +++ b/docs/_posts/2022-05-02-delete_shadowcopy_with_powershell.md @@ -101,8 +101,8 @@ This following analytic detects PowerShell command to delete shadow copy using t #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **delete_shadowcopy_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-02-exchange_powershell_module_usage.md b/docs/_posts/2022-05-02-exchange_powershell_module_usage.md index 805113cb30..8dc84c43b6 100644 --- a/docs/_posts/2022-05-02-exchange_powershell_module_usage.md +++ b/docs/_posts/2022-05-02-exchange_powershell_module_usage.md @@ -111,8 +111,8 @@ Module - New-managementroleassignment can assign a management role to a manageme #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **exchange_powershell_module_usage_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-02-get-domaintrust_with_powershell_script_block.md b/docs/_posts/2022-05-02-get-domaintrust_with_powershell_script_block.md index 4900c5466a..7d062c98df 100644 --- a/docs/_posts/2022-05-02-get-domaintrust_with_powershell_script_block.md +++ b/docs/_posts/2022-05-02-get-domaintrust_with_powershell_script_block.md @@ -102,8 +102,8 @@ During triage, review parallel processes using an EDR product or 4688 events. It #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **get-domaintrust_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-02-get_aduserresultantpasswordpolicy_with_powershell_script_block.md b/docs/_posts/2022-05-02-get_aduserresultantpasswordpolicy_with_powershell_script_block.md index 9372d632c1..f0a972fa96 100644 --- a/docs/_posts/2022-05-02-get_aduserresultantpasswordpolicy_with_powershell_script_block.md +++ b/docs/_posts/2022-05-02-get_aduserresultantpasswordpolicy_with_powershell_script_block.md @@ -100,8 +100,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **get_aduserresultantpasswordpolicy_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-02-get_domainpolicy_with_powershell_script_block.md b/docs/_posts/2022-05-02-get_domainpolicy_with_powershell_script_block.md index d466d8ea96..655d6780c2 100644 --- a/docs/_posts/2022-05-02-get_domainpolicy_with_powershell_script_block.md +++ b/docs/_posts/2022-05-02-get_domainpolicy_with_powershell_script_block.md @@ -100,8 +100,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **get_domainpolicy_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-02-getadcomputer_with_powershell_script_block.md b/docs/_posts/2022-05-02-getadcomputer_with_powershell_script_block.md index 5a645d82a1..e2d297a22f 100644 --- a/docs/_posts/2022-05-02-getadcomputer_with_powershell_script_block.md +++ b/docs/_posts/2022-05-02-getadcomputer_with_powershell_script_block.md @@ -99,8 +99,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **getadcomputer_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-02-getdomaincomputer_with_powershell_script_block.md b/docs/_posts/2022-05-02-getdomaincomputer_with_powershell_script_block.md index 3639a1b2ca..579220084a 100644 --- a/docs/_posts/2022-05-02-getdomaincomputer_with_powershell_script_block.md +++ b/docs/_posts/2022-05-02-getdomaincomputer_with_powershell_script_block.md @@ -99,8 +99,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **getdomaincomputer_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-02-getdomaincontroller_with_powershell_script_block.md b/docs/_posts/2022-05-02-getdomaincontroller_with_powershell_script_block.md index 00262fb378..d74d2d6079 100644 --- a/docs/_posts/2022-05-02-getdomaincontroller_with_powershell_script_block.md +++ b/docs/_posts/2022-05-02-getdomaincontroller_with_powershell_script_block.md @@ -99,8 +99,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **getdomaincontroller_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-02-getdomaingroup_with_powershell_script_block.md b/docs/_posts/2022-05-02-getdomaingroup_with_powershell_script_block.md index 0e67852ad6..c6ece6af3b 100644 --- a/docs/_posts/2022-05-02-getdomaingroup_with_powershell_script_block.md +++ b/docs/_posts/2022-05-02-getdomaingroup_with_powershell_script_block.md @@ -104,8 +104,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **getdomaingroup_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-02-getwmiobject_ds_computer_with_powershell_script_block.md b/docs/_posts/2022-05-02-getwmiobject_ds_computer_with_powershell_script_block.md index ccfb12eb9b..0ac94a228c 100644 --- a/docs/_posts/2022-05-02-getwmiobject_ds_computer_with_powershell_script_block.md +++ b/docs/_posts/2022-05-02-getwmiobject_ds_computer_with_powershell_script_block.md @@ -99,8 +99,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **getwmiobject_ds_computer_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-02-getwmiobject_ds_group_with_powershell_script_block.md b/docs/_posts/2022-05-02-getwmiobject_ds_group_with_powershell_script_block.md index 49d81886a6..2926cfe6fb 100644 --- a/docs/_posts/2022-05-02-getwmiobject_ds_group_with_powershell_script_block.md +++ b/docs/_posts/2022-05-02-getwmiobject_ds_group_with_powershell_script_block.md @@ -104,8 +104,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **getwmiobject_ds_group_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-02-getwmiobject_ds_user_with_powershell_script_block.md b/docs/_posts/2022-05-02-getwmiobject_ds_user_with_powershell_script_block.md index 09b5fbcc7e..c725834aa6 100644 --- a/docs/_posts/2022-05-02-getwmiobject_ds_user_with_powershell_script_block.md +++ b/docs/_posts/2022-05-02-getwmiobject_ds_user_with_powershell_script_block.md @@ -105,8 +105,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **getwmiobject_ds_user_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-02-getwmiobject_user_account_with_powershell_script_block.md b/docs/_posts/2022-05-02-getwmiobject_user_account_with_powershell_script_block.md index 87d8164f20..d58e4c95b0 100644 --- a/docs/_posts/2022-05-02-getwmiobject_user_account_with_powershell_script_block.md +++ b/docs/_posts/2022-05-02-getwmiobject_user_account_with_powershell_script_block.md @@ -109,8 +109,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **getwmiobject_user_account_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-02-mailsniper_invoke_functions.md b/docs/_posts/2022-05-02-mailsniper_invoke_functions.md index 6a6a5d308d..7b6ebe3924 100644 --- a/docs/_posts/2022-05-02-mailsniper_invoke_functions.md +++ b/docs/_posts/2022-05-02-mailsniper_invoke_functions.md @@ -106,8 +106,8 @@ This search is to detect known mailsniper.ps1 functions executed in a machine. T #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **mailsniper_invoke_functions_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-02-powershell_creating_thread_mutex.md b/docs/_posts/2022-05-02-powershell_creating_thread_mutex.md index 814d838666..96a6d3a6bc 100644 --- a/docs/_posts/2022-05-02-powershell_creating_thread_mutex.md +++ b/docs/_posts/2022-05-02-powershell_creating_thread_mutex.md @@ -110,8 +110,8 @@ The following analytic identifies suspicious PowerShell script execution via Eve #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **powershell_creating_thread_mutex_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-02-powershell_loading_dotnet_into_memory_via_reflection.md b/docs/_posts/2022-05-02-powershell_loading_dotnet_into_memory_via_reflection.md index 2f73515400..161fdd2029 100644 --- a/docs/_posts/2022-05-02-powershell_loading_dotnet_into_memory_via_reflection.md +++ b/docs/_posts/2022-05-02-powershell_loading_dotnet_into_memory_via_reflection.md @@ -107,8 +107,8 @@ During triage, review parallel processes using an EDR product or 4688 events. It #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **powershell_loading_dotnet_into_memory_via_reflection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-02-powershell_remove_windows_defender_directory.md b/docs/_posts/2022-05-02-powershell_remove_windows_defender_directory.md index a53b226b49..2d01e6842c 100644 --- a/docs/_posts/2022-05-02-powershell_remove_windows_defender_directory.md +++ b/docs/_posts/2022-05-02-powershell_remove_windows_defender_directory.md @@ -112,8 +112,8 @@ This analytic will identify a suspicious PowerShell command used to delete the W #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **powershell_remove_windows_defender_directory_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-02-windows_krbrelayup_service_creation.md b/docs/_posts/2022-05-02-windows_krbrelayup_service_creation.md index 50bd382f02..197ec18a1a 100644 --- a/docs/_posts/2022-05-02-windows_krbrelayup_service_creation.md +++ b/docs/_posts/2022-05-02-windows_krbrelayup_service_creation.md @@ -108,8 +108,8 @@ The following analytic identifies the default service name created by KrbRelayUp #### Macros The SPL above uses the following Macros: -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) > :information_source: > **windows_krbrelayup_service_creation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-02-wmi_recon_running_process_or_services.md b/docs/_posts/2022-05-02-wmi_recon_running_process_or_services.md index 207622e563..4f73182311 100644 --- a/docs/_posts/2022-05-02-wmi_recon_running_process_or_services.md +++ b/docs/_posts/2022-05-02-wmi_recon_running_process_or_services.md @@ -100,8 +100,8 @@ The following analytic identifies suspicious PowerShell script execution via Eve #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **wmi_recon_running_process_or_services_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-03-disabled_kerberos_pre-authentication_discovery_with_get-aduser.md b/docs/_posts/2022-05-03-disabled_kerberos_pre-authentication_discovery_with_get-aduser.md index f483a96387..84d1304b12 100644 --- a/docs/_posts/2022-05-03-disabled_kerberos_pre-authentication_discovery_with_get-aduser.md +++ b/docs/_posts/2022-05-03-disabled_kerberos_pre-authentication_discovery_with_get-aduser.md @@ -104,8 +104,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **disabled_kerberos_pre-authentication_discovery_with_get-aduser_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-03-disabled_kerberos_pre-authentication_discovery_with_powerview.md b/docs/_posts/2022-05-03-disabled_kerberos_pre-authentication_discovery_with_powerview.md index e00de9eaed..316018d21b 100644 --- a/docs/_posts/2022-05-03-disabled_kerberos_pre-authentication_discovery_with_powerview.md +++ b/docs/_posts/2022-05-03-disabled_kerberos_pre-authentication_discovery_with_powerview.md @@ -104,8 +104,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **disabled_kerberos_pre-authentication_discovery_with_powerview_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-11-potential_password_in_username.md b/docs/_posts/2022-05-11-potential_password_in_username.md index 1cc277a682..b02953a543 100644 --- a/docs/_posts/2022-05-11-potential_password_in_username.md +++ b/docs/_posts/2022-05-11-potential_password_in_username.md @@ -128,8 +128,8 @@ This search identifies users who have entered their passwords in username fields #### Macros The SPL above uses the following Macros: -* [potential_password_in_username_false_positive_reduction](https://github.com/splunk/security_content/blob/develop/macros/potential_password_in_username_false_positive_reduction.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [potential_password_in_username_false_positive_reduction](https://github.com/splunk/security_content/blob/develop/macros/potential_password_in_username_false_positive_reduction.yml) > :information_source: > **potential_password_in_username_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-05-26-linux_at_application_execution.md b/docs/_posts/2022-05-26-linux_at_application_execution.md index 6ab7c3618b..f840f31900 100644 --- a/docs/_posts/2022-05-26-linux_at_application_execution.md +++ b/docs/_posts/2022-05-26-linux_at_application_execution.md @@ -143,6 +143,7 @@ Administrator or network operator can use this application for automation purpos #### Associated Analytic story * [Linux Privilege Escalation](/stories/linux_privilege_escalation) * [Linux Persistence Techniques](/stories/linux_persistence_techniques) +* [Linux Living Off The Land](/stories/linux_living_off_the_land) diff --git a/docs/_posts/2022-05-26-macos_plutil.md b/docs/_posts/2022-05-26-macos_plutil.md index cb78981f6e..9d7140b763 100644 --- a/docs/_posts/2022-05-26-macos_plutil.md +++ b/docs/_posts/2022-05-26-macos_plutil.md @@ -109,8 +109,8 @@ Detect usage of plutil to modify plist files. Adversaries can modiy plist files #### Macros The SPL above uses the following Macros: -* [osquery](https://github.com/splunk/security_content/blob/develop/macros/osquery.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [osquery](https://github.com/splunk/security_content/blob/develop/macros/osquery.yml) > :information_source: > **macos_plutil_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-06-21-windows_gather_victim_network_info_through_ip_check_web_services.md b/docs/_posts/2022-06-21-windows_gather_victim_network_info_through_ip_check_web_services.md index 44652880cc..4e5ebec2f9 100644 --- a/docs/_posts/2022-06-21-windows_gather_victim_network_info_through_ip_check_web_services.md +++ b/docs/_posts/2022-06-21-windows_gather_victim_network_info_through_ip_check_web_services.md @@ -137,6 +137,7 @@ Filter internet browser application to minimize the false positive of this detec #### Associated Analytic story * [Azorult](/stories/azorult) +* [DarkCrystal RAT](/stories/darkcrystal_rat) diff --git a/docs/_posts/2022-06-22-windows_powerview_kerberos_service_ticket_request.md b/docs/_posts/2022-06-22-windows_powerview_kerberos_service_ticket_request.md index 60344e0f16..75f7474d96 100644 --- a/docs/_posts/2022-06-22-windows_powerview_kerberos_service_ticket_request.md +++ b/docs/_posts/2022-06-22-windows_powerview_kerberos_service_ticket_request.md @@ -111,8 +111,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **windows_powerview_kerberos_service_ticket_request_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-06-22-windows_powerview_spn_discovery.md b/docs/_posts/2022-06-22-windows_powerview_spn_discovery.md index 5349d48409..74b4341344 100644 --- a/docs/_posts/2022-06-22-windows_powerview_spn_discovery.md +++ b/docs/_posts/2022-06-22-windows_powerview_spn_discovery.md @@ -112,8 +112,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **windows_powerview_spn_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-06-24-windows_impair_defense_add_xml_applocker_rules.md b/docs/_posts/2022-06-24-windows_impair_defense_add_xml_applocker_rules.md index cc408d6a95..8ebf909852 100644 --- a/docs/_posts/2022-06-24-windows_impair_defense_add_xml_applocker_rules.md +++ b/docs/_posts/2022-06-24-windows_impair_defense_add_xml_applocker_rules.md @@ -114,8 +114,8 @@ The following analytic is to identify a process that imports applocker xml polic #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) > :information_source: > **windows_impair_defense_add_xml_applocker_rules_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-06-29-remote_system_discovery_with_adsisearcher.md b/docs/_posts/2022-06-29-remote_system_discovery_with_adsisearcher.md index 1850a59000..f56b600f94 100644 --- a/docs/_posts/2022-06-29-remote_system_discovery_with_adsisearcher.md +++ b/docs/_posts/2022-06-29-remote_system_discovery_with_adsisearcher.md @@ -99,8 +99,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **remote_system_discovery_with_adsisearcher_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-06-30-windows_powershell_import_applocker_policy.md b/docs/_posts/2022-06-30-windows_powershell_import_applocker_policy.md index f569b01de2..0c5cfceca3 100644 --- a/docs/_posts/2022-06-30-windows_powershell_import_applocker_policy.md +++ b/docs/_posts/2022-06-30-windows_powershell_import_applocker_policy.md @@ -107,8 +107,8 @@ The following analytic is to identify the imports of Windows PowerShell Applocke #### Macros The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) > :information_source: > **windows_powershell_import_applocker_policy_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-07-11-azure_active_directory_high_risk_sign-in.md b/docs/_posts/2022-07-11-azure_active_directory_high_risk_sign-in.md new file mode 100644 index 0000000000..07e45f0d0d --- /dev/null +++ b/docs/_posts/2022-07-11-azure_active_directory_high_risk_sign-in.md @@ -0,0 +1,169 @@ +--- +title: "Azure Active Directory High Risk Sign-in" +excerpt: "Brute Force +, Password Spraying +" +categories: + - Cloud +last_modified_at: 2022-07-11 +toc: true +toc_label: "" +tags: + - Brute Force + - Password Spraying + - Credential Access + - Credential Access + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic triggers on a high risk sign-in against Azure Active Directory identified by Azure Identity Protection. Identity Protection monitors sign-in events using heuristics and machine learning to identify potentially malicious events and categorizes them in three categories high, medium and low. + +- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud + +- **Last Updated**: 2022-07-11 +- **Author**: Mauricio Velazco, Splunk +- **ID**: 1ecff169-26d7-4161-9a7b-2ac4c8e61bea + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | + +| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Exploitation + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` + `azuread` body.category=UserRiskEvents body.properties.riskLevel=high +| rename body.properties.* as * +| stats values(userPrincipalName) by _time, ipAddress, activity, riskLevel, riskEventType, additionalInfo +| `azure_active_directory_high_risk_sign_in_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [azuread](https://github.com/splunk/security_content/blob/develop/macros/azuread.yml) + +> :information_source: +> **azure_active_directory_high_risk_sign-in_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* body.category +* body.properties.riskLevel +* body.properties.userPrincipalName +* body.properties.ipAddress +* body.properties.activity +* body.properties.riskEventType +* body.properties.additionalInfo + + +#### How To Implement +You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase (https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the RiskyUsers and UserRiskEvents log category. + +#### Known False Positives +Details for the risk calculation algorithm used by Identity Protection are unknown and may be prone to false positives. + +#### Associated Analytic story +* [Azure Active Directory Account Takeover](/stories/azure_active_directory_account_takeover) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 54.0 | 60 | 90 | A high risk event was identified by Identify Protection for user $body.properties.userPrincipalName$ | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://attack.mitre.org/techniques/T1110/003/](https://attack.mitre.org/techniques/T1110/003/) +* [https://docs.microsoft.com/en-us/security/compass/incident-response-playbook-password-spray](https://docs.microsoft.com/en-us/security/compass/incident-response-playbook-password-spray) +* [https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/overview-identity-protection](https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/overview-identity-protection) +* [https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-risks](https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-risks) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/azuread_highrisk/azure-audit.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/azuread_highrisk/azure-audit.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/azure_active_directory_high_risk_sign_in.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-11-azure_ad_unusual_number_of_failed_authentications_from_ip.md b/docs/_posts/2022-07-11-azure_ad_unusual_number_of_failed_authentications_from_ip.md new file mode 100644 index 0000000000..cd7209d473 --- /dev/null +++ b/docs/_posts/2022-07-11-azure_ad_unusual_number_of_failed_authentications_from_ip.md @@ -0,0 +1,173 @@ +--- +title: "Azure AD Unusual Number of Failed Authentications From Ip" +excerpt: "Brute Force +, Password Spraying +" +categories: + - Cloud +last_modified_at: 2022-07-11 +toc: true +toc_label: "" +tags: + - Brute Force + - Password Spraying + - Credential Access + - Credential Access + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies one source Ip failing to authenticate with multiple valid users. This behavior could represent an adversary performing a Password Spraying attack against an Azure Active Directory tenant to obtain initial access or elevate privileges. Error Code 50126 represents an invalid password.\ +The detection calculates the standard deviation for source Ip and leverages the 3-sigma statistical rule to identify an unusual number of failed authentication attempts. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ +While looking for anomalies using statistical methods like the standard deviation can have benefits, we also recommend using threshold-based detections to complement coverage. A similar analytic following the threshold model is `Azure AD Multiple Users Failing To Authenticate From Ip`. + +- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud + +- **Last Updated**: 2022-07-11 +- **Author**: Mauricio Velazco, Splunk +- **ID**: 3d8d3a36-93b8-42d7-8d91-c5f24cec223d + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | + +| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Exploitation + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` + `azuread` body.properties.status.errorCode= 50126 body.category= SignInLogs body.properties.authenticationDetails{}.succeeded= false +| rename body.properties.* as * +| bucket span=5m _time +| stats dc(userPrincipalName) AS unique_accounts values(userPrincipalName) as tried_accounts by _time, ipAddress +| eventstats avg(unique_accounts) as ip_avg , stdev(unique_accounts) as ip_std by ipAddress +| eval upperBound=(ip_avg+ip_std*3) +| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) +| `azure_ad_unusual_number_of_failed_authentications_from_ip_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [azuread](https://github.com/splunk/security_content/blob/develop/macros/azuread.yml) + +> :information_source: +> **azure_ad_unusual_number_of_failed_authentications_from_ip_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* body.properties.status.errorCode +* body.category +* body.properties.authenticationDetails +* body.properties.userPrincipalName +* body.properties.ipAddress + + +#### How To Implement +You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the SignInLogs log category. + +#### Known False Positives +A source Ip failing to authenticate with multiple users is not a common for legitimate behavior. + +#### Associated Analytic story +* [Azure Active Directory Account Takeover](/stories/azure_active_directory_account_takeover) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 54.0 | 60 | 90 | Possible Password Spraying attack against Azure AD from source ip $body.properties.ipAddress$ | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://attack.mitre.org/techniques/T1110/003/](https://attack.mitre.org/techniques/T1110/003/) +* [https://docs.microsoft.com/en-us/security/compass/incident-response-playbook-password-spray](https://docs.microsoft.com/en-us/security/compass/incident-response-playbook-password-spray) +* [https://www.cisa.gov/uscert/ncas/alerts/aa21-008a](https://www.cisa.gov/uscert/ncas/alerts/aa21-008a) +* [https://docs.microsoft.com/azure/active-directory/reports-monitoring/reference-sign-ins-error-codes](https://docs.microsoft.com/azure/active-directory/reports-monitoring/reference-sign-ins-error-codes) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/azuread/azure-audit.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/azuread/azure-audit.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-12-aws_defense_evasion_stop_logging_cloudtrail.md b/docs/_posts/2022-07-12-aws_defense_evasion_stop_logging_cloudtrail.md new file mode 100644 index 0000000000..6be54f4310 --- /dev/null +++ b/docs/_posts/2022-07-12-aws_defense_evasion_stop_logging_cloudtrail.md @@ -0,0 +1,168 @@ +--- +title: "AWS Defense Evasion Stop Logging Cloudtrail" +excerpt: "Disable Cloud Logs +, Impair Defenses +" +categories: + - Cloud +last_modified_at: 2022-07-12 +toc: true +toc_label: "" +tags: + - Disable Cloud Logs + - Impair Defenses + - Defense Evasion + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic identifies `StopLogging` events in CloudTrail logs. Adversaries often try to impair their target's defenses by stopping their macliious activity from being logged, so that they may operate with stealth and avoid detection. When the adversary has the right type of permissions in the compromised AWS environment, they may easily stop logging. + +- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud + +- **Last Updated**: 2022-07-12 +- **Author**: Bhavin Patel, Splunk +- **ID**: 8a2f3ca2-4eb5-4389-a549-14063882e537 + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1562.008](https://attack.mitre.org/techniques/T1562/008/) | Disable Cloud Logs | Defense Evasion | + +| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Actions on Objectives + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` +`cloudtrail` eventName = StopLogging eventSource = cloudtrail.amazonaws.com userAgent !=console.amazonaws.com errorCode = success +| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.name) as stopped_cloudtrail_name by src region eventName userAgent user_arn aws_account_id +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `aws_defense_evasion_stop_logging_cloudtrail_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) + +> :information_source: +> **aws_defense_evasion_stop_logging_cloudtrail_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* eventName +* eventSource +* requestParameters.name +* userAgent +* aws_account_id +* src +* region + + +#### How To Implement +You must install Splunk AWS Add on and enable Cloudtrail logs in your AWS Environment. + +#### Known False Positives +While this search has no known false positives, it is possible that an AWS admin has stopped cloudtrail logging. Please investigate this activity. + +#### Associated Analytic story +* [AWS Defense Evasion](/stories/aws_defense_evasion) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 90.0 | 100 | 90 | User $user_arn$ has stopped Cloudtrail logging for account id $aws_account_id$ from IP $src$ | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://attack.mitre.org/techniques/T1562/008/](https://attack.mitre.org/techniques/T1562/008/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/aws_cloudtrail_events.json) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-12-azure_ad_multiple_users_failing_to_authenticate_from_ip.md b/docs/_posts/2022-07-12-azure_ad_multiple_users_failing_to_authenticate_from_ip.md new file mode 100644 index 0000000000..3483238cec --- /dev/null +++ b/docs/_posts/2022-07-12-azure_ad_multiple_users_failing_to_authenticate_from_ip.md @@ -0,0 +1,170 @@ +--- +title: "Azure AD Multiple Users Failing To Authenticate From Ip" +excerpt: "Brute Force +, Password Spraying +" +categories: + - Cloud +last_modified_at: 2022-07-12 +toc: true +toc_label: "" +tags: + - Brute Force + - Password Spraying + - Credential Access + - Credential Access + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies one source Ip failing to authenticate with 30 unique valid users within 5 minutes. This behavior could represent an adversary performing a Password Spraying attack against an Azure Active Directory tenant to obtain initial access or elevate privileges. Error Code 50126 represents an invalid password. This logic can be used for real time security monitoring as well as threat hunting exercises.\ +Azure AD tenants can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold if needed. + +- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud + +- **Last Updated**: 2022-07-12 +- **Author**: Mauricio Velazco, Splunk +- **ID**: 94481a6a-8f59-4c86-957f-55a71e3612a6 + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | + +| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Exploitation + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` + `azuread` body.properties.status.errorCode= 50126 body.category= SignInLogs body.properties.authenticationDetails{}.succeeded= false +| rename body.properties.* as * +| bucket span=5m _time +| stats dc(userPrincipalName) AS unique_accounts values(userPrincipalName) as tried_accounts by _time, ipAddress +| where unique_accounts > 30 +| `azure_ad_multiple_users_failing_to_authenticate_from_ip_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [azuread](https://github.com/splunk/security_content/blob/develop/macros/azuread.yml) + +> :information_source: +> **azure_ad_multiple_users_failing_to_authenticate_from_ip_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* body.properties.status.errorCode +* body.category +* body.properties.authenticationDetails +* body.properties.userPrincipalName +* body.properties.ipAddress + + +#### How To Implement +You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the SignInLogs log category. + +#### Known False Positives +A source Ip failing to authenticate with multiple users is not a common for legitimate behavior. + +#### Associated Analytic story +* [Azure Active Directory Account Takeover](/stories/azure_active_directory_account_takeover) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 63.0 | 70 | 90 | Source Ip $body.properties.ipAddress$ failed to authenticate with 30 users within 5 minutes. | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://attack.mitre.org/techniques/T1110/003/](https://attack.mitre.org/techniques/T1110/003/) +* [https://docs.microsoft.com/en-us/security/compass/incident-response-playbook-password-spray](https://docs.microsoft.com/en-us/security/compass/incident-response-playbook-password-spray) +* [https://www.cisa.gov/uscert/ncas/alerts/aa21-008a](https://www.cisa.gov/uscert/ncas/alerts/aa21-008a) +* [https://docs.microsoft.com/azure/active-directory/reports-monitoring/reference-sign-ins-error-codes](https://docs.microsoft.com/azure/active-directory/reports-monitoring/reference-sign-ins-error-codes) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/azuread/azure-audit.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/azuread/azure-audit.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-12-azure_ad_successful_single-factor_authentication.md b/docs/_posts/2022-07-12-azure_ad_successful_single-factor_authentication.md new file mode 100644 index 0000000000..77c71e8715 --- /dev/null +++ b/docs/_posts/2022-07-12-azure_ad_successful_single-factor_authentication.md @@ -0,0 +1,162 @@ +--- +title: "Azure AD Successful Single-Factor Authentication" +excerpt: "Security Account Manager +" +categories: + - Cloud +last_modified_at: 2022-07-12 +toc: true +toc_label: "" +tags: + - Security Account Manager + - Credential Access + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies a successful authentication event against Azure Active Directory for an account without Multi-Factor Authentication enabled. This could be evidence of a missconfiguration, a policy violation or an account take over attempt that should be investigated + +- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud + +- **Last Updated**: 2022-07-12 +- **Author**: Mauricio Velazco, Splunk +- **ID**: a560e7f6-1711-4353-885b-40be53101fcd + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Exploitation + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` + `azuread` body.category=SignInLogs body.properties.authenticationRequirement=singleFactorAuthentication body.properties.authenticationDetails{}.succeeded=true +| rename body.properties.* as * +| stats values(userPrincipalName) by _time, ipAddress, appDisplayName, authenticationRequirement +| `azure_ad_successful_single_factor_authentication_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [azuread](https://github.com/splunk/security_content/blob/develop/macros/azuread.yml) + +> :information_source: +> **azure_ad_successful_single-factor_authentication_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* body.category +* body.properties.authenticationRequirement +* body.properties.authenticationDetails +* body.properties.userPrincipalName +* body.properties.ipAddress +* body.properties.appDisplayName + + +#### How To Implement +You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the SignInLogs log category. + +#### Known False Positives +Although not recommended, certain users may be required without multi-factor authentication. Filter as needed + +#### Associated Analytic story +* [Azure Active Directory Account Takeover](/stories/azure_active_directory_account_takeover) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 50.0 | 50 | 100 | Successful authentication for user $body.properties.userPrincipalName$ without MFA | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://attack.mitre.org/techniques/T1078/004/](https://attack.mitre.org/techniques/T1078/004/) +* [https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-mfa-howitworks*](https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-mfa-howitworks*) +* [https://www.forbes.com/sites/daveywinder/2020/07/08/new-dark-web-audit-reveals-15-billion-stolen-logins-from-100000-breaches-passwords-hackers-cybercrime/?sh=69927b2a180f](https://www.forbes.com/sites/daveywinder/2020/07/08/new-dark-web-audit-reveals-15-billion-stolen-logins-from-100000-breaches-passwords-hackers-cybercrime/?sh=69927b2a180f) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.004/azuread/azure-audit.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.004/azuread/azure-audit.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/azure_ad_successful_single_factor_authentication.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-13-aws_defense_evasion_delete_cloudtrail.md b/docs/_posts/2022-07-13-aws_defense_evasion_delete_cloudtrail.md new file mode 100644 index 0000000000..d67243e2a5 --- /dev/null +++ b/docs/_posts/2022-07-13-aws_defense_evasion_delete_cloudtrail.md @@ -0,0 +1,168 @@ +--- +title: "AWS Defense Evasion Delete Cloudtrail" +excerpt: "Disable Cloud Logs +, Impair Defenses +" +categories: + - Cloud +last_modified_at: 2022-07-13 +toc: true +toc_label: "" +tags: + - Disable Cloud Logs + - Impair Defenses + - Defense Evasion + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic identifies AWS `DeleteTrail` events within CloudTrail logs. Adversaries often try to impair their target's defenses by stopping their malicious activity from being logged, so that they may operate with stealth and avoid detection. When the adversary has the right type of permissions in the compromised AWS environment, they may delete the the entire cloudtrail that is logging activities in the environment. + +- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud + +- **Last Updated**: 2022-07-13 +- **Author**: Bhavin Patel, Splunk +- **ID**: 82092925-9ca1-4e06-98b8-85a2d3889552 + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1562.008](https://attack.mitre.org/techniques/T1562/008/) | Disable Cloud Logs | Defense Evasion | + +| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Actions on Objectives + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` +`cloudtrail` eventName = DeleteTrail eventSource = cloudtrail.amazonaws.com userAgent !=console.amazonaws.com errorCode = success +| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.name) as deleted_cloudtrail_name by src region eventName userAgent user_arn aws_account_id +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `aws_defense_evasion_delete_cloudtrail_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) + +> :information_source: +> **aws_defense_evasion_delete_cloudtrail_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* eventName +* eventSource +* requestParameters.name +* userAgent +* aws_account_id +* src +* region + + +#### How To Implement +You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. + +#### Known False Positives +While this search has no known false positives, it is possible that an AWS admin has stopped cloudTrail logging. Please investigate this activity. + +#### Associated Analytic story +* [AWS Defense Evasion](/stories/aws_defense_evasion) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 90.0 | 100 | 90 | User $user_arn$ has delete a CloudTrail logging for account id $aws_account_id$ from IP $src$ | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://attack.mitre.org/techniques/T1562/008/](https://attack.mitre.org/techniques/T1562/008/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/aws_cloudtrail_events.json) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-13-azure_ad_successful_powershell_authentication.md b/docs/_posts/2022-07-13-azure_ad_successful_powershell_authentication.md new file mode 100644 index 0000000000..d7732dc4a0 --- /dev/null +++ b/docs/_posts/2022-07-13-azure_ad_successful_powershell_authentication.md @@ -0,0 +1,174 @@ +--- +title: "Azure AD Successful PowerShell Authentication" +excerpt: "Valid Accounts +, Cloud Accounts +" +categories: + - Cloud +last_modified_at: 2022-07-13 +toc: true +toc_label: "" +tags: + - Valid Accounts + - Cloud Accounts + - Defense Evasion + - Initial Access + - Persistence + - Privilege Escalation + - Defense Evasion + - Initial Access + - Persistence + - Privilege Escalation + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies a successful authentication event against an Azure AD tenant using PowerShell commandlets. This behavior is not common for regular, non administrative users. After compromising an account in Azure AD, attackers and red teams alike will perform enumeration and discovery techniques. One method of executing these techniques is leveraging the native PowerShell modules. + +- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud + +- **Last Updated**: 2022-07-13 +- **Author**: Mauricio Velazco, Splunk +- **ID**: 62f10052-d7b3-4e48-b57b-56f8e3ac7ceb + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | + +| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Exploitation + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` + `azuread` body.category=SignInLogs body.properties.authenticationDetails{}.succeeded=true body.properties.appDisplayName="Azure Active Directory PowerShell" +| rename body.properties.* as * +| stats values(userPrincipalName) by _time, ipAddress, appDisplayName, userAgent +| `azure_ad_successful_powershell_authentication_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [azuread](https://github.com/splunk/security_content/blob/develop/macros/azuread.yml) + +> :information_source: +> **azure_ad_successful_powershell_authentication_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* body.properties.appDisplayName +* body.category +* body.properties.userPrincipalName +* body.properties.ipAddress +* body.properties.appDisplayName +* body.properties.userAgent + + +#### How To Implement +You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the SignInLogs log category. + +#### Known False Positives +Administrative users will likely use PowerShell commandlets to troubleshoot and maintain the environment. Filter as needed. + +#### Associated Analytic story +* [Azure Active Directory Account Takeover](/stories/azure_active_directory_account_takeover) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 54.0 | 60 | 90 | Successful authentication for user $body.properties.userPrincipalName$ using PowerShell. | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://attack.mitre.org/techniques/T1078/004/](https://attack.mitre.org/techniques/T1078/004/) +* [https://docs.microsoft.com/en-us/powershell/module/azuread/connect-azuread?view=azureadps-2.0](https://docs.microsoft.com/en-us/powershell/module/azuread/connect-azuread?view=azureadps-2.0) +* [https://securitycafe.ro/2022/04/29/pentesting-azure-recon-techniques/](https://securitycafe.ro/2022/04/29/pentesting-azure-recon-techniques/) +* [https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Cloud%20-%20Azure%20Pentest.md](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Cloud%20-%20Azure%20Pentest.md) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.004/azuread_pws/azure-audit.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.004/azuread_pws/azure-audit.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/azure_ad_successful_powershell_authentication.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-14-azure_ad_authentication_failed_during_mfa_challenge.md b/docs/_posts/2022-07-14-azure_ad_authentication_failed_during_mfa_challenge.md new file mode 100644 index 0000000000..2e3b4a1154 --- /dev/null +++ b/docs/_posts/2022-07-14-azure_ad_authentication_failed_during_mfa_challenge.md @@ -0,0 +1,179 @@ +--- +title: "Azure AD Authentication Failed During MFA Challenge" +excerpt: "Valid Accounts +, Cloud Accounts +, Multi-Factor Authentication Request Generation +" +categories: + - Cloud +last_modified_at: 2022-07-14 +toc: true +toc_label: "" +tags: + - Valid Accounts + - Cloud Accounts + - Multi-Factor Authentication Request Generation + - Defense Evasion + - Initial Access + - Persistence + - Privilege Escalation + - Defense Evasion + - Initial Access + - Persistence + - Privilege Escalation + - Credential Access + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies an authentication attempt event against an Azure AD tenant that fails during the Multi Factor Authentication challenge. This behavior may represent an adversary trying to authenticate with compromised credentials. In some cases, adversaries may continuously repeat login attempts in order to bombard users with MFA push notifications, SMS messages, and phone calls, potentially resulting in the user finally accepting the authentication request. + +- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud + +- **Last Updated**: 2022-07-14 +- **Author**: Mauricio Velazco, Splunk +- **ID**: e62c9c2e-bf51-4719-906c-3074618fcc1c + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | + +| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | + +| [T1621](https://attack.mitre.org/techniques/T1621/) | Multi-Factor Authentication Request Generation | Credential Access | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Exploitation + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` + `azuread` body.category=SignInLogs body.properties.status.errorCode=500121 +| rename body.properties.* as * +| stats values(userPrincipalName) by _time, ipAddress, status.additionalDetails, appDisplayName, userAgent +| `azure_ad_authentication_failed_during_mfa_challenge_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [azuread](https://github.com/splunk/security_content/blob/develop/macros/azuread.yml) + +> :information_source: +> **azure_ad_authentication_failed_during_mfa_challenge_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* body.category +* body.properties.status.errorCode +* body.properties.userPrincipalName +* body.properties.ipAddress +* body.properties.status.additionalDetails +* body.properties.appDisplayName +* body.properties.userAgent + + +#### How To Implement +You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the RiskyUsers and UserRiskEvents log category. + +#### Known False Positives +Legitimate users may miss to reply the MFA challenge within the time window or deny it by mistake. + +#### Associated Analytic story +* [Azure Active Directory Account Takeover](/stories/azure_active_directory_account_takeover) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 54.0 | 60 | 90 | User $body.properties.userPrincipalName$ failed to pass MFA challenge | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://attack.mitre.org/techniques/T1621/](https://attack.mitre.org/techniques/T1621/) +* [https://attack.mitre.org/techniques/T1078/004/](https://attack.mitre.org/techniques/T1078/004/) +* [https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-mfa-howitworks](https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-mfa-howitworks) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/azuread/azure-audit.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/azuread/azure-audit.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-15-powershell_disable_security_monitoring.md b/docs/_posts/2022-07-15-powershell_disable_security_monitoring.md index 0aff23150f..29cdd34dfe 100644 --- a/docs/_posts/2022-07-15-powershell_disable_security_monitoring.md +++ b/docs/_posts/2022-07-15-powershell_disable_security_monitoring.md @@ -108,8 +108,8 @@ This search is to identifies a modification in registry to disable the windows d #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) > :information_source: > **powershell_disable_security_monitoring_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-07-17-aws_defense_evasion_delete_cloudwatch_log_group.md b/docs/_posts/2022-07-17-aws_defense_evasion_delete_cloudwatch_log_group.md new file mode 100644 index 0000000000..f02495f7de --- /dev/null +++ b/docs/_posts/2022-07-17-aws_defense_evasion_delete_cloudwatch_log_group.md @@ -0,0 +1,168 @@ +--- +title: "AWS Defense Evasion Delete CloudWatch Log Group" +excerpt: "Impair Defenses +, Disable Cloud Logs +" +categories: + - Cloud +last_modified_at: 2022-07-17 +toc: true +toc_label: "" +tags: + - Impair Defenses + - Disable Cloud Logs + - Defense Evasion + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic identifies AWS `DeleteLogGroup` events in CloudTrail logs. Attackers may evade the logging capability by deleting the log group in CloudWatch. This will stop sending the logs and metrics to CloudWatch. When the adversary has the right type of permissions within the compromised AWS environment, they may delete the CloudWatch log group that is logging activities in the environment. + +- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud + +- **Last Updated**: 2022-07-17 +- **Author**: Gowthamaraj Rajendran, Splunk +- **ID**: d308b0f1-edb7-4a62-a614-af321160710f + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + +| [T1562.008](https://attack.mitre.org/techniques/T1562/008/) | Disable Cloud Logs | Defense Evasion | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Actions on Objectives + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` +`cloudtrail` eventName = DeleteLogGroup eventSource = logs.amazonaws.com userAgent !=console.amazonaws.com errorCode = success +| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.logGroupName) as log_group_name by src region eventName userAgent user_arn aws_account_id +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `aws_defense_evasion_delete_cloudwatch_log_group_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) + +> :information_source: +> **aws_defense_evasion_delete_cloudwatch_log_group_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* eventName +* eventSource +* requestParameters.name +* userAgent +* aws_account_id +* src +* region + + +#### How To Implement +You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. + +#### Known False Positives +While this search has no known false positives, it is possible that an AWS admin has deleted CloudWatch logging. Please investigate this activity. + +#### Associated Analytic story +* [AWS Defense Evasion](/stories/aws_defense_evasion) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 90.0 | 100 | 90 | User $user_arn$ has deleted a CloudWatch logging group for account id $aws_account_id$ from IP $src$ | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://attack.mitre.org/techniques/T1562/008/](https://attack.mitre.org/techniques/T1562/008/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/delete_cloudwatch_log_group/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/delete_cloudwatch_log_group/aws_cloudtrail_events.json) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-17-aws_defense_evasion_update_cloudtrail.md b/docs/_posts/2022-07-17-aws_defense_evasion_update_cloudtrail.md new file mode 100644 index 0000000000..886df670fd --- /dev/null +++ b/docs/_posts/2022-07-17-aws_defense_evasion_update_cloudtrail.md @@ -0,0 +1,168 @@ +--- +title: "AWS Defense Evasion Update Cloudtrail" +excerpt: "Impair Defenses +, Disable Cloud Logs +" +categories: + - Cloud +last_modified_at: 2022-07-17 +toc: true +toc_label: "" +tags: + - Impair Defenses + - Disable Cloud Logs + - Defense Evasion + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic identifies `UpdateTrail` events in CloudTrail logs. Attackers may evade the logging capability by updating the settings and impairing them with wrong parameters. For example, Attackers may change the multi-regional log into a single region logs, which evades the logging for other regions. When the adversary has the right type of permissions in the compromised AWS environment, they may update the CloudTrail settings that is logging activities in your environment. + +- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud + +- **Last Updated**: 2022-07-17 +- **Author**: Gowthamaraj Rajendran, Splunk +- **ID**: 7c921d28-ef48-4f1b-85b3-0af8af7697db + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + +| [T1562.008](https://attack.mitre.org/techniques/T1562/008/) | Disable Cloud Logs | Defense Evasion | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Actions on Objectives + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` +`cloudtrail` eventName = UpdateTrail eventSource = cloudtrail.amazonaws.com userAgent !=console.amazonaws.com errorCode = success +| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.name) as cloudtrail_name by src region eventName userAgent user_arn aws_account_id +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `aws_defense_evasion_update_cloudtrail_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) + +> :information_source: +> **aws_defense_evasion_update_cloudtrail_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* eventName +* eventSource +* requestParameters.name +* userAgent +* aws_account_id +* src +* region + + +#### How To Implement +You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. + +#### Known False Positives +While this search has no known false positives, it is possible that an AWS admin has updated cloudtrail logging. Please investigate this activity. + +#### Associated Analytic story +* [AWS Defense Evasion](/stories/aws_defense_evasion) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 90.0 | 100 | 90 | User $user_arn$ has updated a cloudtrail logging for account id $aws_account_id$ from IP $src$ | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://attack.mitre.org/techniques/T1562/008/](https://attack.mitre.org/techniques/T1562/008/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/update_cloudtrail/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/update_cloudtrail/aws_cloudtrail_events.json) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_defense_evasion_update_cloudtrail.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-20-linux_persistence_and_privilege_escalation_risk_behavior.md b/docs/_posts/2022-07-20-linux_persistence_and_privilege_escalation_risk_behavior.md new file mode 100644 index 0000000000..5101b49155 --- /dev/null +++ b/docs/_posts/2022-07-20-linux_persistence_and_privilege_escalation_risk_behavior.md @@ -0,0 +1,167 @@ +--- +title: "Linux Persistence and Privilege Escalation Risk Behavior" +excerpt: "Abuse Elevation Control Mechanism +" +categories: + - Endpoint +last_modified_at: 2022-07-20 +toc: true +toc_label: "" +tags: + - Abuse Elevation Control Mechanism + - Defense Evasion + - Privilege Escalation + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Risk +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +The following correlation is specific to Linux persistence and privilege escalation tactics and is tied to two analytic stories and any Linux analytic tied to persistence and privilege escalation. These techniques often overlap with Persistence techniques, as OS features that let an adversary persist can execute in an elevated context. + +- **Type**: [Correlation](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Risk](https://docs.splunk.com/Documentation/CIM/latest/User/Risk) +- **Last Updated**: 2022-07-20 +- **Author**: Michael Haag, Splunk +- **ID**: ad5ac21b-3b1e-492c-8e19-ea5d5e8e5cf1 + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Exploitation + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Risk.All_Risk where (All_Risk.analyticstories IN ("Linux Privilege Escalation", "Linux Persistence Techniques") OR source = "*Linux*") All_Risk.annotations.mitre_attack.mitre_tactic IN ("persistence", "privilege-escalation") All_Risk.risk_object_type="system" by All_Risk.risk_object All_Risk.annotations.mitre_attack.mitre_tactic source All_Risk.description +| `drop_dm_object_name(All_Risk)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| stats values(source) as detection_name values(annotations.mitre_attack.mitre_tactic) as tactics values(firstTime) as firstTime values(lastTime) as lastTime dc(annotations.mitre_attack.mitre_tactic) as distinct_tactics dc(source) as distinct_detection_name by risk_object +| where distinct_detection_name >= 4 +| `linux_persistence_and_privilege_escalation_risk_behavior_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) + +> :information_source: +> **linux_persistence_and_privilege_escalation_risk_behavior_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* All_Risk.analyticstories +* All_Risk.risk_object_type +* All_Risk.risk_object +* All_Risk.annotations.mitre_attack.mitre_tactic +* source + + +#### How To Implement +Ensure Linux anomaly and TTP analytics are enabled. TTP may be set to Notables for point detections, anomaly should not be notables but risk generators. The correlation relies on more than x amount of distict detection names generated before generating a notable. Modify the value as needed. Default value is set to 4. This value may need to be increased based on activity in your environment. + +#### Known False Positives +False positives will be present based on many factors. Tune the correlation as needed to reduce too many triggers. + +#### Associated Analytic story +* [Linux Privilege Escalation](/stories/linux_privilege_escalation) +* [Linux Persistence Techniques](/stories/linux_persistence_techniques) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 56.0 | 70 | 80 | Privilege escalation and persistence behaviors have been identified on $risk_object$. | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://attack.mitre.org/tactics/TA0004/](https://attack.mitre.org/tactics/TA0004/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/linux_risk/linuxrisk.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/linux_risk/linuxrisk.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_persistence_and_privilege_escalation_risk_behavior.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-20-registry_keys_used_for_persistence.md b/docs/_posts/2022-07-20-registry_keys_used_for_persistence.md new file mode 100644 index 0000000000..a4ef1e513f --- /dev/null +++ b/docs/_posts/2022-07-20-registry_keys_used_for_persistence.md @@ -0,0 +1,177 @@ +--- +title: "Registry Keys Used For Persistence" +excerpt: "Registry Run Keys / Startup Folder +, Boot or Logon Autostart Execution +" +categories: + - Endpoint +last_modified_at: 2022-07-20 +toc: true +toc_label: "" +tags: + - Registry Run Keys / Startup Folder + - Boot or Logon Autostart Execution + - Persistence + - Privilege Escalation + - Persistence + - Privilege Escalation + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +The search looks for modifications to registry keys that can be used to launch an application or service at system startup. + +- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) +- **Last Updated**: 2022-07-20 +- **Author**: Jose Hernandez, David Dorsey, Teoderick Contreras, Rod Soto, Splunk +- **ID**: f5f6af30-7aa7-4295-bfe9-07fe87c01a4b + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1547.001](https://attack.mitre.org/techniques/T1547/001/) | Registry Run Keys / Startup Folder | Persistence, Privilege Escalation | + +| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Actions on Objectives + + +
+
+ + +
+ NIST + +
+ +* PR.PT +* DE.CM +* DE.AE + + + +
+
+ +
+ CIS20 + +
+ +* CIS 8 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce OR Registry.registry_path=*\\currentversion\\run* OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices* OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*" AND Registry.registry_key_name=Debugger) OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\*") OR (Registry.registry_path="*currentVersion\\Windows" AND Registry.registry_key_name="Load") OR (Registry.registry_path="*\\CurrentVersion" AND Registry.registry_key_name="Svchost") OR (Registry.registry_path="*\\CurrentControlSet\Control\Session Manager"AND Registry.registry_key_name="BootExecute") OR (Registry.registry_path="*\\Software\\Run" AND Registry.registry_key_name="auto_update")) by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.registry_key_name +| `drop_dm_object_name(Registry)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `registry_keys_used_for_persistence_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) + +> :information_source: +> **registry_keys_used_for_persistence_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* Registry.registry_key_name +* Registry.registry_path +* Registry.dest +* Registry.user + + +#### How To Implement +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +#### Known False Positives +There are many legitimate applications that must execute on system startup and will use these registry keys to accomplish that task. + +#### Associated Analytic story +* [Suspicious Windows Registry Activities](/stories/suspicious_windows_registry_activities) +* [Suspicious MSHTA Activity](/stories/suspicious_mshta_activity) +* [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) +* [Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns](/stories/possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns) +* [Ransomware](/stories/ransomware) +* [Windows Persistence Techniques](/stories/windows_persistence_techniques) +* [Emotet Malware DHS Report TA18-201A ](/stories/emotet_malware__dhs_report_ta18-201a_) +* [IcedID](/stories/icedid) +* [Remcos](/stories/remcos) +* [Windows Registry Abuse](/stories/windows_registry_abuse) +* [Azorult](/stories/azorult) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 76.0 | 80 | 95 | A registry activity in $registry_path$ related to persistence in host $dest$ | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/windows-sysmon.log) +* [https://media.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/t1547001-runonce.log](https://media.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/t1547001-runonce.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/registry_keys_used_for_persistence.yml) \| *version*: **8** \ No newline at end of file diff --git a/docs/_posts/2022-07-25-aws_defense_evasion_putbucketlifecycle.md b/docs/_posts/2022-07-25-aws_defense_evasion_putbucketlifecycle.md new file mode 100644 index 0000000000..36bed54338 --- /dev/null +++ b/docs/_posts/2022-07-25-aws_defense_evasion_putbucketlifecycle.md @@ -0,0 +1,173 @@ +--- +title: "AWS Defense Evasion PutBucketLifecycle" +excerpt: "Disable Cloud Logs +, Impair Defenses +" +categories: + - Cloud +last_modified_at: 2022-07-25 +toc: true +toc_label: "" +tags: + - Disable Cloud Logs + - Impair Defenses + - Defense Evasion + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic identifies `PutBucketLifecycle` events in CloudTrail logs where a user has created a new lifecycle rule for an S3 bucket with a short expiration period. Attackers may use this API call to impair the CloudTrail logging by removing logs from the S3 bucket by changing the object expiration day to 1 day, in which case the CloudTrail logs will be deleted. + +- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud + +- **Last Updated**: 2022-07-25 +- **Author**: Bhavin Patel +- **ID**: ce1c0e2b-9303-4903-818b-0d9002fc6ea4 + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1562.008](https://attack.mitre.org/techniques/T1562/008/) | Disable Cloud Logs | Defense Evasion | + +| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Actions on Objectives + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` +`cloudtrail` eventName=PutBucketLifecycle user_type=IAMUser errorCode=success +| spath path=requestParameters{}.LifecycleConfiguration{}.Rule{}.Expiration{}.Days output=expiration_days +| spath path=requestParameters{}.bucketName output=bucket_name +| stats count min(_time) as firstTime max(_time) as lastTime by src region eventName userAgent user_arn aws_account_id expiration_days bucket_name user_type +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| where expiration_days < 3 +| `aws_defense_evasion_putbucketlifecycle_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) + +> :information_source: +> **aws_defense_evasion_putbucketlifecycle_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* eventName +* eventSource +* requestParameters.name +* userAgent +* aws_account_id +* src +* region +* requestParameters{}.LifecycleConfiguration{}.Rule{}.Expiration{}.Days +* requestParameters{}.bucketName + + +#### How To Implement +You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. We recommend our users to set the expiration days value according to your company's log retention policies. + +#### Known False Positives +While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names. + +#### Associated Analytic story +* [AWS Defense Evasion](/stories/aws_defense_evasion) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 20.0 | 50 | 40 | User $user_arn$ has created a new rule to on an S3 bucket $bucket_name$ with short expiration days | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://stratus-red-team.cloud/attack-techniques/AWS/aws.defense-evasion.cloudtrail-lifecycle-rule/](https://stratus-red-team.cloud/attack-techniques/AWS/aws.defense-evasion.cloudtrail-lifecycle-rule/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/put_bucketlifecycle/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/put_bucketlifecycle/aws_cloudtrail_events.json) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-26-aws_defense_evasion_impair_security_services.md b/docs/_posts/2022-07-26-aws_defense_evasion_impair_security_services.md new file mode 100644 index 0000000000..13994fe00b --- /dev/null +++ b/docs/_posts/2022-07-26-aws_defense_evasion_impair_security_services.md @@ -0,0 +1,171 @@ +--- +title: "AWS Defense Evasion Impair Security Services" +excerpt: "Disable Cloud Logs +, Impair Defenses +" +categories: + - Cloud +last_modified_at: 2022-07-26 +toc: true +toc_label: "" +tags: + - Disable Cloud Logs + - Impair Defenses + - Defense Evasion + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic looks for several delete specific API calls made to AWS Security Services like CloudWatch, GuardDuty and Web Application Firewalls. These API calls are often leveraged by adversaries to weaken existing security defenses by deleting logging configurations in the CloudWatch alarm, delete a set of detectors from your Guardduty environment or simply delete a bunch of CloudWatch alarms to remain stealthy and avoid detection. + +- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud + +- **Last Updated**: 2022-07-26 +- **Author**: Bhavin Patel, Gowthamaraj Rajendran, Splunk +- **ID**: b28c4957-96a6-47e0-a965-6c767aac1458 + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1562.008](https://attack.mitre.org/techniques/T1562/008/) | Disable Cloud Logs | Defense Evasion | + +| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Actions on Objectives + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` +`cloudtrail` eventName IN ("DeleteLogStream","DeleteDetector","DeleteIPSet","DeleteWebACL","DeleteRule","DeleteRuleGroup","DeleteLoggingConfiguration","DeleteAlarms") +| stats count min(_time) as firstTime max(_time) as lastTime values(eventName) as eventName values(eventSource) as eventSource values(requestParameters.*) as * by src region user_arn aws_account_id user_type user_agent errorCode +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `aws_defense_evasion_impair_security_services_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) + +> :information_source: +> **aws_defense_evasion_impair_security_services_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* eventName +* eventSource +* user_agent +* user_type +* aws_account_id +* src +* region +* errorCode + + +#### How To Implement +You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. + +#### Known False Positives +While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names. + +#### Associated Analytic story +* [AWS Defense Evasion](/stories/aws_defense_evasion) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 42.0 | 70 | 60 | User $user_arn$ has made potentially risky api calls $eventName$ that could impair AWS security services for account id $aws_account_id$ | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://docs.aws.amazon.com/cli/latest/reference/guardduty/index.html](https://docs.aws.amazon.com/cli/latest/reference/guardduty/index.html) +* [https://docs.aws.amazon.com/cli/latest/reference/waf/index.html](https://docs.aws.amazon.com/cli/latest/reference/waf/index.html) +* [https://www.elastic.co/guide/en/security/current/prebuilt-rules.html](https://www.elastic.co/guide/en/security/current/prebuilt-rules.html) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/aws_delete_security_services/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/aws_delete_security_services/aws_cloudtrail_events.json) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_defense_evasion_impair_security_services.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-27-linux_decode_base64_to_shell.md b/docs/_posts/2022-07-27-linux_decode_base64_to_shell.md new file mode 100644 index 0000000000..9712cd7e6a --- /dev/null +++ b/docs/_posts/2022-07-27-linux_decode_base64_to_shell.md @@ -0,0 +1,179 @@ +--- +title: "Linux Decode Base64 to Shell" +excerpt: "Obfuscated Files or Information +, Unix Shell +" +categories: + - Endpoint +last_modified_at: 2022-07-27 +toc: true +toc_label: "" +tags: + - Obfuscated Files or Information + - Unix Shell + - Defense Evasion + - Execution + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies base64 being decoded and passed to a Linux shell. + +- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2022-07-27 +- **Author**: Michael Haag, Splunk +- **ID**: 637b603e-1799-40fd-bf87-47ecbd551b66 + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | + +| [T1059.004](https://attack.mitre.org/techniques/T1059/004/) | Unix Shell | Execution | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Delivery +* Exploitation + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process IN ("*base64 -d*","*base64 --decode*") AND Processes.process="* +|*" `linux_shells` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `linux_decode_base64_to_shell_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [linux_shells](https://github.com/splunk/security_content/blob/develop/macros/linux_shells.yml) + +> :information_source: +> **linux_decode_base64_to_shell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +#### Known False Positives +False positives may be present based on legitimate software being utilized. Filter as needed. + +#### Associated Analytic story +* [Linux Living Off The Land](/stories/linux_living_off_the_land) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 25.0 | 50 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ decoding base64 and passing it to a shell. | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1027/T1027.md#atomic-test-1---decode-base64-data-into-script](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1027/T1027.md#atomic-test-1---decode-base64-data-into-script) +* [https://redcanary.com/blog/lateral-movement-with-secure-shell/](https://redcanary.com/blog/lateral-movement-with-secure-shell/) +* [https://linux.die.net/man/1/base64](https://linux.die.net/man/1/base64) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1027/atomic_red_team/linux-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1027/atomic_red_team/linux-sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_decode_base64_to_shell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-27-linux_kernel_module_enumeration.md b/docs/_posts/2022-07-27-linux_kernel_module_enumeration.md new file mode 100644 index 0000000000..a586f443b2 --- /dev/null +++ b/docs/_posts/2022-07-27-linux_kernel_module_enumeration.md @@ -0,0 +1,174 @@ +--- +title: "Linux Kernel Module Enumeration" +excerpt: "System Information Discovery +, Rootkit +" +categories: + - Endpoint +last_modified_at: 2022-07-27 +toc: true +toc_label: "" +tags: + - System Information Discovery + - Rootkit + - Discovery + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies the process kmod being utilized to list kernel modules in use. Typically, this is not seen as malicious, however it may be a precurser to the use of insmod to install a module. + +- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2022-07-27 +- **Author**: Michael Haag, Splunk +- **ID**: 6df99886-0e04-4c11-8b88-325747419278 + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1082](https://attack.mitre.org/techniques/T1082/) | System Information Discovery | Discovery | + +| [T1014](https://attack.mitre.org/techniques/T1014/) | Rootkit | Defense Evasion | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Reconnaissance + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=kmod Processes.process IN ("*lsmod*", "*list*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `linux_kernel_module_enumeration_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) + +> :information_source: +> **linux_kernel_module_enumeration_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +#### Known False Positives +False positives are present based on automated tooling or system administrative usage. Filter as needed. + +#### Associated Analytic story +* [Linux Rootkit](/stories/linux_rootkit) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 15.0 | 30 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ enumeration kernel modules. | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://man7.org/linux/man-pages/man8/kmod.8.html](https://man7.org/linux/man-pages/man8/kmod.8.html) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1082/atomic_red_team/linux-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1082/atomic_red_team/linux-sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_kernel_module_enumeration.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-27-linux_obfuscated_files_or_information_base64_decode.md b/docs/_posts/2022-07-27-linux_obfuscated_files_or_information_base64_decode.md new file mode 100644 index 0000000000..15921f9b1d --- /dev/null +++ b/docs/_posts/2022-07-27-linux_obfuscated_files_or_information_base64_decode.md @@ -0,0 +1,172 @@ +--- +title: "Linux Obfuscated Files or Information Base64 Decode" +excerpt: "Obfuscated Files or Information +" +categories: + - Endpoint +last_modified_at: 2022-07-27 +toc: true +toc_label: "" +tags: + - Obfuscated Files or Information + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies the use of base64 decode on Linux being utilized to deobfuscate a file. Identify the source of the file and determine if legitimate. Review parallel processes for further behavior before and after. + +- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2022-07-27 +- **Author**: Michael Haag, Splunk +- **ID**: 303b38b2-c03f-44e2-8f41-4594606fcfc7 + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Delivery +* Exploitation + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process IN ("*base64 -d*","*base64 --decode*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `linux_obfuscated_files_or_information_base64_decode_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) + +> :information_source: +> **linux_obfuscated_files_or_information_base64_decode_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +#### Known False Positives +False positives may be present and will require some tuning based on processes. Filter as needed. + +#### Associated Analytic story +* [Linux Living Off The Land](/stories/linux_living_off_the_land) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 15.0 | 30 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ decoding base64. | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1027/T1027.md#atomic-test-1---decode-base64-data-into-script](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1027/T1027.md#atomic-test-1---decode-base64-data-into-script) +* [https://redcanary.com/blog/lateral-movement-with-secure-shell/](https://redcanary.com/blog/lateral-movement-with-secure-shell/) +* [https://linux.die.net/man/1/base64](https://linux.die.net/man/1/base64) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1027/atomic_red_team/linux-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1027/atomic_red_team/linux-sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-27-linux_ssh_authorized_keys_modification.md b/docs/_posts/2022-07-27-linux_ssh_authorized_keys_modification.md new file mode 100644 index 0000000000..f835615d3f --- /dev/null +++ b/docs/_posts/2022-07-27-linux_ssh_authorized_keys_modification.md @@ -0,0 +1,170 @@ +--- +title: "Linux SSH Authorized Keys Modification" +excerpt: "SSH Authorized Keys +" +categories: + - Endpoint +last_modified_at: 2022-07-27 +toc: true +toc_label: "" +tags: + - SSH Authorized Keys + - Persistence + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies based on process execution the modification of SSH Authorized Keys. Adversaries perform this behavior to persist on endpoints. During triage, review parallel processes and capture any additional file modifications for review. + +- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2022-07-27 +- **Author**: Michael Haag, Splunk +- **ID**: f5ab595e-28e5-4327-8077-5008ba97c850 + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1098.004](https://attack.mitre.org/techniques/T1098/004/) | SSH Authorized Keys | Persistence | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Installation + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN ("bash","cat") Processes.process IN ("*/authorized_keys*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `linux_ssh_authorized_keys_modification_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) + +> :information_source: +> **linux_ssh_authorized_keys_modification_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +#### Known False Positives +Filtering will be required as system administrators will add and remove. One way to filter query is to add "echo". + +#### Associated Analytic story +* [Linux Living Off The Land](/stories/linux_living_off_the_land) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 15.0 | 30 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ modifying SSH Authorized Keys. | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://redcanary.com/blog/lateral-movement-with-secure-shell/](https://redcanary.com/blog/lateral-movement-with-secure-shell/) +* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1098.004/T1098.004.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1098.004/T1098.004.md) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.004/ssh_authorized_keys/authkey_linux-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.004/ssh_authorized_keys/authkey_linux-sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_ssh_authorized_keys_modification.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-27-linux_ssh_remote_services_script_execute.md b/docs/_posts/2022-07-27-linux_ssh_remote_services_script_execute.md new file mode 100644 index 0000000000..e280892974 --- /dev/null +++ b/docs/_posts/2022-07-27-linux_ssh_remote_services_script_execute.md @@ -0,0 +1,169 @@ +--- +title: "Linux SSH Remote Services Script Execute" +excerpt: "SSH +" +categories: + - Endpoint +last_modified_at: 2022-07-27 +toc: true +toc_label: "" +tags: + - SSH + - Lateral Movement + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies SSH being utilized to move laterally and execute a script or file on the remote host. + +- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2022-07-27 +- **Author**: Michael Haag, Splunk +- **ID**: aa1748dd-4a5c-457a-9cf6-ca7b4eb711b3 + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1021.004](https://attack.mitre.org/techniques/T1021/004/) | SSH | Lateral Movement | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Exploitation + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=ssh Processes.process IN ("*oStrictHostKeyChecking*", "*oConnectTimeout*", "*oBatchMode*") AND CommandLine IN ("*http:*","*https:*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `linux_ssh_remote_services_script_execute_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) + +> :information_source: +> **linux_ssh_remote_services_script_execute_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +#### Known False Positives +This is not a common command to be executed. Filter as needed. + +#### Associated Analytic story +* [Linux Living Off The Land](/stories/linux_living_off_the_land) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 56.0 | 80 | 70 | An instance of $process_name$ was identified on endpoint $dest$ by user $user$ attempting to move laterally and download a file. | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://redcanary.com/blog/lateral-movement-with-secure-shell/](https://redcanary.com/blog/lateral-movement-with-secure-shell/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.004/atomic_red_team/linux-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.004/atomic_red_team/linux-sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_ssh_remote_services_script_execute.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-27-windows_system_logoff_commandline.md b/docs/_posts/2022-07-27-windows_system_logoff_commandline.md new file mode 100644 index 0000000000..a90d25c8a3 --- /dev/null +++ b/docs/_posts/2022-07-27-windows_system_logoff_commandline.md @@ -0,0 +1,170 @@ +--- +title: "Windows System LogOff Commandline" +excerpt: "System Shutdown/Reboot +" +categories: + - Endpoint +last_modified_at: 2022-07-27 +toc: true +toc_label: "" +tags: + - System Shutdown/Reboot + - Impact + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies Windows commandlined to logoff a windows host machine. This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact, interrupt access, aid destruction of the system like wiping disk or inhibit system recovery. This TTP is a good pivot to check why application trigger this commandline which is not so common way to logoff a machine. + +- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2022-07-27 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 74a8133f-93e7-4b71-9bd3-13a66124fd57 + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1529](https://attack.mitre.org/techniques/T1529/) | System Shutdown/Reboot | Impact | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Exploitation + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` + +| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe) Processes.process="*shutdown*" Processes.process="* /l*" Processes.process="* /t*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `windows_system_logoff_commandline_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) + +> :information_source: +> **windows_system_logoff_commandline_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +#### Known False Positives +Administrator may execute this commandline to trigger shutdown, logoff or restart the host machine. + +#### Associated Analytic story +* [DarkCrystal RAT](/stories/darkcrystal_rat) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 56.0 | 70 | 80 | Process name $process_name$ is seen to execute logoff commandline on $dest$ | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://attack.mitre.org/techniques/T1529/](https://attack.mitre.org/techniques/T1529/) +* [https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor](https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/reboot_logoff_commandline/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/reboot_logoff_commandline/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_system_logoff_commandline.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-27-windows_system_reboot_commandline.md b/docs/_posts/2022-07-27-windows_system_reboot_commandline.md new file mode 100644 index 0000000000..69032bd65f --- /dev/null +++ b/docs/_posts/2022-07-27-windows_system_reboot_commandline.md @@ -0,0 +1,170 @@ +--- +title: "Windows System Reboot CommandLine" +excerpt: "System Shutdown/Reboot +" +categories: + - Endpoint +last_modified_at: 2022-07-27 +toc: true +toc_label: "" +tags: + - System Shutdown/Reboot + - Impact + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies Windows commandlined to reboot a windows host machine. This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact, interrupt access, aid destruction of the system like wiping disk or inhibit system recovery. This TTP is a good pivot to check why application trigger this commandline which is not so common way to reboot a machine. Compare to shutdown and logoff shutdown.exe feature, reboot seen in some automation script like ansible to reboot the machine. + +- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2022-07-27 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 97fc2b60-c8eb-4711-93f7-d26fade3686f + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1529](https://attack.mitre.org/techniques/T1529/) | System Shutdown/Reboot | Impact | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Exploitation + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` + +| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe) Processes.process="*shutdown*" Processes.process="* /r*" Processes.process="* /t*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `windows_system_reboot_commandline_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) + +> :information_source: +> **windows_system_reboot_commandline_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +#### Known False Positives +Administrator may execute this commandline to trigger shutdown or restart the host machine. + +#### Associated Analytic story +* [DarkCrystal RAT](/stories/darkcrystal_rat) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 30.0 | 60 | 50 | Process $process_name$ that executed reboot via commandline on $dest$ | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://attack.mitre.org/techniques/T1529/](https://attack.mitre.org/techniques/T1529/) +* [https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor](https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/reboot_logoff_commandline/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/reboot_logoff_commandline/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_system_reboot_commandline.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-27-windows_system_shutdown_commandline.md b/docs/_posts/2022-07-27-windows_system_shutdown_commandline.md new file mode 100644 index 0000000000..11e2aabc48 --- /dev/null +++ b/docs/_posts/2022-07-27-windows_system_shutdown_commandline.md @@ -0,0 +1,170 @@ +--- +title: "Windows System Shutdown CommandLine" +excerpt: "System Shutdown/Reboot +" +categories: + - Endpoint +last_modified_at: 2022-07-27 +toc: true +toc_label: "" +tags: + - System Shutdown/Reboot + - Impact + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies Windows commandlined to shutdown a windows host machine. This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact, interrupt access, aid destruction of the system like wiping disk or inhibit system recovery. This TTP is a good pivot to check why application trigger this commandline which is not so common way to shutdown a machine. + +- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2022-07-27 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 4fee57b8-d825-4bf3-9ea8-bf405cdb614c + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1529](https://attack.mitre.org/techniques/T1529/) | System Shutdown/Reboot | Impact | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Exploitation + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` + +| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe) Processes.process="*shutdown*" Processes.process="* /s*" Processes.process="* /t*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `windows_system_shutdown_commandline_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) + +> :information_source: +> **windows_system_shutdown_commandline_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +#### Known False Positives +Administrator may execute this commandline to trigger shutdown or restart the host machine. + +#### Associated Analytic story +* [DarkCrystal RAT](/stories/darkcrystal_rat) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 49.0 | 70 | 70 | Process $process_name$ seen to execute shutdown via commandline on $dest$ | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://attack.mitre.org/techniques/T1529/](https://attack.mitre.org/techniques/T1529/) +* [https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor](https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/dcrat/shutdown_commandline/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/dcrat/shutdown_commandline/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_system_shutdown_commandline.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-28-linux_clipboard_data_copy.md b/docs/_posts/2022-07-28-linux_clipboard_data_copy.md new file mode 100644 index 0000000000..ec5bde1098 --- /dev/null +++ b/docs/_posts/2022-07-28-linux_clipboard_data_copy.md @@ -0,0 +1,170 @@ +--- +title: "Linux Clipboard Data Copy" +excerpt: "Clipboard Data +" +categories: + - Endpoint +last_modified_at: 2022-07-28 +toc: true +toc_label: "" +tags: + - Clipboard Data + - Collection + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies the use of Linux Xclip copying data out of the clipboard. Adversaries have utilized this technique to capture passwords, IP addresses, or store payloads. + +- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2022-07-28 +- **Author**: Michael Haag, Splunk +- **ID**: 7173b2ad-6146-418f-85ae-c3479e4515fc + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1115](https://attack.mitre.org/techniques/T1115/) | Clipboard Data | Collection | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Reconnaissance + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=xclip Processes.process IN ("*-o *", "*-sel *", "*-selection *", "*clip *","*clipboard*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `linux_clipboard_data_copy_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) + +> :information_source: +> **linux_clipboard_data_copy_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +#### Known False Positives +False positives may be present on Linux desktop as it may commonly be used by administrators or end users. Filter as needed. + +#### Associated Analytic story +* [Linux Living Off The Land](/stories/linux_living_off_the_land) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 16.0 | 40 | 40 | An instance of $process_name$ was identified on endpoint $dest$ by user $user$ adding or removing content from the clipboard. | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://attack.mitre.org/techniques/T1115/](https://attack.mitre.org/techniques/T1115/) +* [https://linux.die.net/man/1/xclip](https://linux.die.net/man/1/xclip) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1115/atomic_red_team/linux-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1115/atomic_red_team/linux-sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_clipboard_data_copy.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-28-windows_command_shell_dcrat_forkbomb_payload.md b/docs/_posts/2022-07-28-windows_command_shell_dcrat_forkbomb_payload.md new file mode 100644 index 0000000000..e9061fd00e --- /dev/null +++ b/docs/_posts/2022-07-28-windows_command_shell_dcrat_forkbomb_payload.md @@ -0,0 +1,177 @@ +--- +title: "Windows Command Shell DCRat ForkBomb Payload" +excerpt: "Windows Command Shell +, Command and Scripting Interpreter +" +categories: + - Endpoint +last_modified_at: 2022-07-28 +toc: true +toc_label: "" +tags: + - Windows Command Shell + - Command and Scripting Interpreter + - Execution + - Execution + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies DCRat "forkbomb" payload feature. This technique was seen in dark crystal RAT backdoor capabilities where it will execute several cmd child process executing "notepad.exe & pause". This analytic detects the multiple cmd.exe and child process notepad.exe execution using batch script in the targeted host within 30s timeframe. this TTP can be a good pivot to check DCRat infection. + +- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2022-07-28 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 2bb1a362-7aa8-444a-92ed-1987e8da83e1 + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution | + +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Exploitation + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` + +| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.parent_process_id) as parent_process_id values(Processes.process_id) as process_id dc(Processes.parent_process_id) as parent_process_id_count dc(Processes.process_id) as process_id_count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name= "cmd.exe" (Processes.process_name = "notepad.exe" OR Processes.original_file_name= "notepad.exe") Processes.parent_process = "*.bat*" by Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.parent_process Processes.dest Processes.user _time span=30s +| where parent_process_id_count>= 10 AND process_id_count >=10 +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `windows_command_shell_dcrat_forkbomb_payload_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) + +> :information_source: +> **windows_command_shell_dcrat_forkbomb_payload_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of wermgr.exe may be used. + +#### Known False Positives +unknown + +#### Associated Analytic story +* [DarkCrystal RAT](/stories/darkcrystal_rat) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 81.0 | 90 | 90 | Multiple cmd.exe processes with child process of notepad.exe executed on $dest$ | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://cert.gov.ua/article/405538](https://cert.gov.ua/article/405538) +* [https://malpedia.caad.fkie.fraunhofer.de/details/win.dcrat](https://malpedia.caad.fkie.fraunhofer.de/details/win.dcrat) +* [https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor](https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/dcrat/dcrat_forkbomb/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/dcrat/dcrat_forkbomb/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-28-windows_system_time_discovery_w32tm_delay.md b/docs/_posts/2022-07-28-windows_system_time_discovery_w32tm_delay.md new file mode 100644 index 0000000000..ead5cd04d9 --- /dev/null +++ b/docs/_posts/2022-07-28-windows_system_time_discovery_w32tm_delay.md @@ -0,0 +1,171 @@ +--- +title: "Windows System Time Discovery W32tm Delay" +excerpt: "System Time Discovery +" +categories: + - Endpoint +last_modified_at: 2022-07-28 +toc: true +toc_label: "" +tags: + - System Time Discovery + - Discovery + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies DCRat delay time tactics using w32tm. This technique was seen in DCRAT malware where it uses stripchart function of w32tm.exe application to delay the execution of its payload like c2 communication , beaconing and execution. This anomaly detection may help the analyst to check other possible event like the process who execute this command that may lead to DCRat attack. + +- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2022-07-28 +- **Author**: Teoderick Contreras, Splunk +- **ID**: b2cc69e7-11ba-42dc-a269-59c069a48870 + + +#### Annotations + +
+ ATT&CK + +
+ + +| ID | Technique | Tactic | +| -------------- | ---------------- |-------------------- | +| [T1124](https://attack.mitre.org/techniques/T1124/) | System Time Discovery | Discovery | + +
+
+ + +
+ Kill Chain Phase + +
+ +* Reconnaissance + + +
+
+ + +
+ NIST + +
+ +* DE.CM + + + +
+
+ +
+ CIS20 + +
+ +* CIS 3 +* CIS 5 +* CIS 16 + + + +
+
+ +
+ CVE + +
+ + +
+
+ +#### Search + +``` + +| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = w32tm.exe Processes.process= "* /stripchart *" Processes.process= "* /computer:localhost *" Processes.process= "* /period:*" Processes.process= "* /dataonly *" Processes.process= "* /samples:*" by Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id Processes.dest Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `windows_system_time_discovery_w32tm_delay_filter` +``` + +#### Macros +The SPL above uses the following Macros: +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) + +> :information_source: +> **windows_system_time_discovery_w32tm_delay_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of wermgr.exe may be used. + +#### Known False Positives +unknown + +#### Associated Analytic story +* [DarkCrystal RAT](/stories/darkcrystal_rat) + + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 36.0 | 60 | 60 | Process name w32tm.exe is using suspcicious command line arguments $process$ on host $dest$. | + + +> :information_source: +> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. + +#### Reference + +* [https://cert.gov.ua/article/405538](https://cert.gov.ua/article/405538) +* [https://malpedia.caad.fkie.fraunhofer.de/details/win.dcrat](https://malpedia.caad.fkie.fraunhofer.de/details/win.dcrat) +* [https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor](https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/dcrat/dcrat_delay_execution/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/dcrat/dcrat_delay_execution/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_system_time_discovery_w32tm_delay.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/aws_defense_evasion.md b/docs/_stories/aws_defense_evasion.md new file mode 100644 index 0000000000..86474cdca5 --- /dev/null +++ b/docs/_stories/aws_defense_evasion.md @@ -0,0 +1,46 @@ +--- +title: "AWS Defense Evasion" +last_modified_at: 2022-07-15 +toc: true +toc_label: "" +tags: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Actions on Objectives +--- + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +Identify activity and techniques associated with the Evasion of Defenses within AWS, such as Disabling CloudTrail, Deleting CloudTrail and many others. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: +- **Last Updated**: 2022-07-15 +- **Author**: Gowthamaraj Rajendran, Splunk +- **ID**: 4e00b690-293f-434d-a9d8-bcfb2ea5fff9 + +#### Narrative + +Adversaries employ a variety of techniques in order to avoid detection and operate without barriers. This often involves modifying the configuration of security monitoring tools to get around them or explicitly disabling them to prevent them from running. This Analytic Story includes analytics that identify activity consistent with adversaries attempting to disable various security mechanisms on AWS. Such activity may involve deleting the CloudTrail logs , as this is where all the AWS logs get stored or explicitly changing the retention policy of S3 buckets. Other times, adversaries attempt deletion of a specified AWS CloudWatch log group. + +#### Detections + +| Name | Technique | Type | +| ----------- | ----------- |--------------| +| [AWS Defense Evasion Delete Cloudtrail](/cloud/aws_defense_evasion_delete_cloudtrail/) | [Disable Cloud Logs](/tags/#disable-cloud-logs), [Impair Defenses](/tags/#impair-defenses)| TTP | +| [AWS Defense Evasion Delete CloudWatch Log Group](/cloud/aws_defense_evasion_delete_cloudwatch_log_group/) | [Impair Defenses](/tags/#impair-defenses), [Disable Cloud Logs](/tags/#disable-cloud-logs)| TTP | +| [AWS Defense Evasion Impair Security Services](/cloud/aws_defense_evasion_impair_security_services/) | [Disable Cloud Logs](/tags/#disable-cloud-logs), [Impair Defenses](/tags/#impair-defenses)| Hunting | +| [AWS Defense Evasion PutBucketLifecycle](/cloud/aws_defense_evasion_putbucketlifecycle/) | [Disable Cloud Logs](/tags/#disable-cloud-logs), [Impair Defenses](/tags/#impair-defenses)| Hunting | +| [AWS Defense Evasion Stop Logging Cloudtrail](/cloud/aws_defense_evasion_stop_logging_cloudtrail/) | [Disable Cloud Logs](/tags/#disable-cloud-logs), [Impair Defenses](/tags/#impair-defenses)| TTP | +| [AWS Defense Evasion Update Cloudtrail](/cloud/aws_defense_evasion_update_cloudtrail/) | [Impair Defenses](/tags/#impair-defenses), [Disable Cloud Logs](/tags/#disable-cloud-logs)| TTP | + +#### Reference + +* [https://attack.mitre.org/tactics/TA0005/](https://attack.mitre.org/tactics/TA0005/) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/stories/aws_defense_evasion.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/azure_active_directory_account_takeover.md b/docs/_stories/azure_active_directory_account_takeover.md new file mode 100644 index 0000000000..5ed75782ac --- /dev/null +++ b/docs/_stories/azure_active_directory_account_takeover.md @@ -0,0 +1,52 @@ +--- +title: "Azure Active Directory Account Takeover" +last_modified_at: 2022-07-14 +toc: true +toc_label: "" +tags: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Exploitation +--- + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +Monitor for activities and techniques associated with Account Takover attacks against Azure Active Directory tenants. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: +- **Last Updated**: 2022-07-14 +- **Author**: Mauricio Velazco, Splunk +- **ID**: 41514c46-7118-4eab-a9bb-f3bfa4e3bea9 + +#### Narrative + +Azure Active Directory (Azure AD) is Microsofts enterprise cloud-based identity and access management (IAM) service. Azure AD is the backbone of most of Azure services like Office 365. It can sync with on-premise Active Directory environments and provide authentication to other cloud-based systems via the OAuth protocol. According to Microsoft, Azure AD manages more than 1.2 billion identities and processes over 8 billion authentications per day.\ Account Takeover (ATO) is an attack whereby cybercriminals gain unauthorized access to online accounts by using different techniques like brute force, social engineering, phishing & spear phishing, credential stuffing, etc. By posing as the real user, cyber-criminals can change account details, send out phishing emails, steal financial information or sensitive data, or use any stolen information to access further accounts within the organization.\ This analytic storic groups detections that can help security operations teams identify the potential compromise of Azure Active Directory accounts. + +#### Detections + +| Name | Technique | Type | +| ----------- | ----------- |--------------| +| [Azure Active Directory High Risk Sign-in](/cloud/azure_active_directory_high_risk_sign-in/) | [Brute Force](/tags/#brute-force), [Password Spraying](/tags/#password-spraying)| TTP | +| [Azure AD Authentication Failed During MFA Challenge](/cloud/azure_ad_authentication_failed_during_mfa_challenge/) | [Valid Accounts](/tags/#valid-accounts), [Cloud Accounts](/tags/#cloud-accounts), [Multi-Factor Authentication Request Generation](/tags/#multi-factor-authentication-request-generation)| TTP | +| [Azure AD Multiple Users Failing To Authenticate From Ip](/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip/) | [Brute Force](/tags/#brute-force), [Password Spraying](/tags/#password-spraying)| Anomaly | +| [Azure AD Successful PowerShell Authentication](/cloud/azure_ad_successful_powershell_authentication/) | [Valid Accounts](/tags/#valid-accounts), [Cloud Accounts](/tags/#cloud-accounts)| TTP | +| [Azure AD Successful Single-Factor Authentication](/cloud/azure_ad_successful_single-factor_authentication/) | [Security Account Manager](/tags/#security-account-manager)| TTP | +| [Azure AD Unusual Number of Failed Authentications From Ip](/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip/) | [Brute Force](/tags/#brute-force), [Password Spraying](/tags/#password-spraying)| Anomaly | + +#### Reference + +* [https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-whatis](https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-whatis) +* [https://azure.microsoft.com/en-us/services/active-directory/#overview](https://azure.microsoft.com/en-us/services/active-directory/#overview) +* [https://attack.mitre.org/techniques/T1586/](https://attack.mitre.org/techniques/T1586/) +* [https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-compare-azure-ad-to-ad](https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-compare-azure-ad-to-ad) +* [https://www.imperva.com/learn/application-security/account-takeover-ato/](https://www.imperva.com/learn/application-security/account-takeover-ato/) +* [https://www.varonis.com/blog/azure-active-directory](https://www.varonis.com/blog/azure-active-directory) +* [https://www.barracuda.com/glossary/account-takeover](https://www.barracuda.com/glossary/account-takeover) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/stories/azure_active_directory_account_takeover.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/darkcrystal_rat.md b/docs/_stories/darkcrystal_rat.md new file mode 100644 index 0000000000..f50f718fb7 --- /dev/null +++ b/docs/_stories/darkcrystal_rat.md @@ -0,0 +1,62 @@ +--- +title: "DarkCrystal RAT" +last_modified_at: 2022-07-26 +toc: true +toc_label: "" +tags: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Actions on Objectives + - Command & Control + - Exploitation + - Reconnaissance +--- + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +Leverage searches that allow you to detect and investigate unusual activities that might relate to the DcRat malware including ddos, spawning more process, botnet c2 communication, defense evasion and etc. The DcRat malware is known commercial backdoor that was first released in 2018. This tool was sold in underground forum and known to be one of the cheapest commercial RATs. DcRat is modular and bespoke plugin framework make it a very flexible option, helpful for a range of nefearious uses. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2022-07-26 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 639e6006-0885-4847-9394-ddc2902629bf + +#### Narrative + +Adversaries may use this technique to maximize the impact on the target organization in operations where network wide availability interruption is the goal. + +#### Detections + +| Name | Technique | Type | +| ----------- | ----------- |--------------| +| [Any Powershell DownloadFile](/endpoint/any_powershell_downloadfile/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | +| [CMD Carry Out String Command Parameter](/endpoint/cmd_carry_out_string_command_parameter/) | [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Hunting | +| [Executables Or Script Creation In Suspicious Path](/endpoint/executables_or_script_creation_in_suspicious_path/) | [Masquerading](/tags/#masquerading)| TTP | +| [Malicious PowerShell Process - Encoded Command](/endpoint/malicious_powershell_process_-_encoded_command/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information)| Hunting | +| [Malicious PowerShell Process - Execution Policy Bypass](/endpoint/malicious_powershell_process_-_execution_policy_bypass/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | +| [Office Document Executing Macro Code](/endpoint/office_document_executing_macro_code/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | +| [Office Product Spawn CMD Process](/endpoint/office_product_spawn_cmd_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta)| TTP | +| [Suspicious Process File Path](/endpoint/suspicious_process_file_path/) | [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | +| [Windows Command Shell DCRat ForkBomb Payload](/endpoint/windows_command_shell_dcrat_forkbomb_payload/) | [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| TTP | +| [Windows Gather Victim Network Info Through Ip Check Web Services](/endpoint/windows_gather_victim_network_info_through_ip_check_web_services/) | [IP Addresses](/tags/#ip-addresses), [Gather Victim Network Information](/tags/#gather-victim-network-information)| Hunting | +| [Windows High File Deletion Frequency](/endpoint/windows_high_file_deletion_frequency/) | [Data Destruction](/tags/#data-destruction)| Anomaly | +| [Windows System LogOff Commandline](/endpoint/windows_system_logoff_commandline/) | [System Shutdown/Reboot](/tags/#system-shutdown/reboot)| Anomaly | +| [Windows System Reboot CommandLine](/endpoint/windows_system_reboot_commandline/) | [System Shutdown/Reboot](/tags/#system-shutdown/reboot)| Anomaly | +| [Windows System Shutdown CommandLine](/endpoint/windows_system_shutdown_commandline/) | [System Shutdown/Reboot](/tags/#system-shutdown/reboot)| Anomaly | +| [Windows System Time Discovery W32tm Delay](/endpoint/windows_system_time_discovery_w32tm_delay/) | [System Time Discovery](/tags/#system-time-discovery)| Anomaly | +| [Winword Spawning Cmd](/endpoint/winword_spawning_cmd/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | +| [Winword Spawning PowerShell](/endpoint/winword_spawning_powershell/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | + +#### Reference + +* [https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor](https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor) +* [https://malpedia.caad.fkie.fraunhofer.de/details/win.dcrat](https://malpedia.caad.fkie.fraunhofer.de/details/win.dcrat) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/stories/darkcrystal_rat.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/linux_living_off_the_land.md b/docs/_stories/linux_living_off_the_land.md new file mode 100644 index 0000000000..50e0cac11d --- /dev/null +++ b/docs/_stories/linux_living_off_the_land.md @@ -0,0 +1,68 @@ +--- +title: "Linux Living Off The Land" +last_modified_at: 2022-07-27 +toc: true +toc_label: "" +tags: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Actions on Objectives + - Delivery + - Exploitation + - Installation + - Reconnaissance +--- + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +Linux Living Off The Land consists of binaries that may be used to bypass local security restrictions within misconfigured systems. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2022-07-27 +- **Author**: Michael Haag, Splunk +- **ID**: e405a2d7-dc8e-4227-8e9d-f60267b8c0cd + +#### Narrative + +Similar to Windows LOLBAS project, the GTFOBins project focuses solely on Unix binaries that may be abused in multiple categories including Reverse Shell, File Upload, File Download and much more. These binaries are native to the operating system and the functionality is typically native. The behaviors are typically not malicious by default or vulnerable, but these are built in functionality of the applications. When reviewing any notables or hunting through mountains of events of interest, it's important to identify the binary, review command-line arguments, path of file, and capture any network and file modifications. Linux analysis may be a bit cumbersome due to volume and how process behavior is seen in EDR products. Piecing it together will require some effort. + +#### Detections + +| Name | Technique | Type | +| ----------- | ----------- |--------------| +| [Curl Download and Bash Execution](/endpoint/curl_download_and_bash_execution/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | +| [Linux Add Files In Known Crontab Directories](/endpoint/linux_add_files_in_known_crontab_directories/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | +| [Linux Adding Crontab Using List Parameter](/endpoint/linux_adding_crontab_using_list_parameter/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Hunting | +| [Linux At Allow Config File Creation](/endpoint/linux_at_allow_config_file_creation/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | +| [Linux At Application Execution](/endpoint/linux_at_application_execution/) | [At](/tags/#at), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | +| [Linux Change File Owner To Root](/endpoint/linux_change_file_owner_to_root/) | [Linux and Mac File and Directory Permissions Modification](/tags/#linux-and-mac-file-and-directory-permissions-modification), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification)| Anomaly | +| [Linux Clipboard Data Copy](/endpoint/linux_clipboard_data_copy/) | [Clipboard Data](/tags/#clipboard-data)| Anomaly | +| [Linux Common Process For Elevation Control](/endpoint/linux_common_process_for_elevation_control/) | [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Hunting | +| [Linux Decode Base64 to Shell](/endpoint/linux_decode_base64_to_shell/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Unix Shell](/tags/#unix-shell)| TTP | +| [Linux Edit Cron Table Parameter](/endpoint/linux_edit_cron_table_parameter/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Hunting | +| [Linux Obfuscated Files or Information Base64 Decode](/endpoint/linux_obfuscated_files_or_information_base64_decode/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information)| Anomaly | +| [Linux pkexec Privilege Escalation](/endpoint/linux_pkexec_privilege_escalation/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation)| TTP | +| [Linux Possible Access Or Modification Of sshd Config File](/endpoint/linux_possible_access_or_modification_of_sshd_config_file/) | [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation)| Anomaly | +| [Linux Possible Append Cronjob Entry on Existing Cronjob File](/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Hunting | +| [Linux Possible Cronjob Modification With Editor](/endpoint/linux_possible_cronjob_modification_with_editor/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Hunting | +| [Linux Possible Ssh Key File Creation](/endpoint/linux_possible_ssh_key_file_creation/) | [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation)| Anomaly | +| [Linux Service File Created In Systemd Directory](/endpoint/linux_service_file_created_in_systemd_directory/) | [Systemd Timers](/tags/#systemd-timers), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | +| [Linux Service Restarted](/endpoint/linux_service_restarted/) | [Systemd Timers](/tags/#systemd-timers), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | +| [Linux Service Started Or Enabled](/endpoint/linux_service_started_or_enabled/) | [Systemd Timers](/tags/#systemd-timers), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | +| [Linux Setuid Using Chmod Utility](/endpoint/linux_setuid_using_chmod_utility/) | [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | +| [Linux SSH Authorized Keys Modification](/endpoint/linux_ssh_authorized_keys_modification/) | [SSH Authorized Keys](/tags/#ssh-authorized-keys)| Anomaly | +| [Linux SSH Remote Services Script Execute](/endpoint/linux_ssh_remote_services_script_execute/) | [SSH](/tags/#ssh)| TTP | +| [Suspicious Curl Network Connection](/endpoint/suspicious_curl_network_connection/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | + +#### Reference + +* [https://gtfobins.github.io/](https://gtfobins.github.io/) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/stories/linux_living_off_the_land.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/linux_persistence_techniques.md b/docs/_stories/linux_persistence_techniques.md index c64cd93e45..3b8a17f7cb 100644 --- a/docs/_stories/linux_persistence_techniques.md +++ b/docs/_stories/linux_persistence_techniques.md @@ -8,6 +8,7 @@ tags: - Splunk Enterprise Security - Splunk Cloud - Endpoint + - Risk - Exploitation --- @@ -18,7 +19,7 @@ tags: Monitor for activities and techniques associated with maintaining persistence on a Linux system--a sign that an adversary may have compromised your environment. - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Risk](https://docs.splunk.com/Documentation/CIM/latest/User/Risk) - **Last Updated**: 2021-12-17 - **Author**: Teoderick Contreras, Splunk - **ID**: e40d13e5-d38b-457e-af2a-e8e6a2f2b516 @@ -47,6 +48,7 @@ Maintaining persistence is one of the first steps taken by attackers after the i | [Linux Insert Kernel Module Using Insmod Utility](/endpoint/linux_insert_kernel_module_using_insmod_utility/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| Anomaly | | [Linux Install Kernel Module Using Modprobe Utility](/endpoint/linux_install_kernel_module_using_modprobe_utility/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| Anomaly | | [Linux NOPASSWD Entry In Sudoers File](/endpoint/linux_nopasswd_entry_in_sudoers_file/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | +| [Linux Persistence and Privilege Escalation Risk Behavior](/endpoint/linux_persistence_and_privilege_escalation_risk_behavior/) | [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Correlation | | [Linux Possible Access Or Modification Of sshd Config File](/endpoint/linux_possible_access_or_modification_of_sshd_config_file/) | [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation)| Anomaly | | [Linux Possible Access To Credential Files](/endpoint/linux_possible_access_to_credential_files/) | [/etc/passwd and /etc/shadow](/tags/#/etc/passwd-and-/etc/shadow), [OS Credential Dumping](/tags/#os-credential-dumping)| Anomaly | | [Linux Possible Access To Sudoers File](/endpoint/linux_possible_access_to_sudoers_file/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | diff --git a/docs/_stories/linux_privilege_escalation.md b/docs/_stories/linux_privilege_escalation.md index 4c46eb4c93..fdb6ca337d 100644 --- a/docs/_stories/linux_privilege_escalation.md +++ b/docs/_stories/linux_privilege_escalation.md @@ -8,6 +8,7 @@ tags: - Splunk Enterprise Security - Splunk Cloud - Endpoint + - Risk - Exploitation --- @@ -18,7 +19,7 @@ tags: Monitor for and investigate activities that may be associated with a Linux privilege-escalation attack, including unusual processes running on endpoints, schedule task, services, setuid, root execution and more. - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Risk](https://docs.splunk.com/Documentation/CIM/latest/User/Risk) - **Last Updated**: 2021-12-17 - **Author**: Teoderick Contreras, Splunk - **ID**: b9879c24-670a-44c0-895e-98cdb7d0e848 @@ -47,6 +48,7 @@ Privilege escalation is a "land-and-expand" technique, wherein an adversary gain | [Linux Insert Kernel Module Using Insmod Utility](/endpoint/linux_insert_kernel_module_using_insmod_utility/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| Anomaly | | [Linux Install Kernel Module Using Modprobe Utility](/endpoint/linux_install_kernel_module_using_modprobe_utility/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| Anomaly | | [Linux NOPASSWD Entry In Sudoers File](/endpoint/linux_nopasswd_entry_in_sudoers_file/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | +| [Linux Persistence and Privilege Escalation Risk Behavior](/endpoint/linux_persistence_and_privilege_escalation_risk_behavior/) | [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Correlation | | [Linux pkexec Privilege Escalation](/endpoint/linux_pkexec_privilege_escalation/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation)| TTP | | [Linux Possible Access Or Modification Of sshd Config File](/endpoint/linux_possible_access_or_modification_of_sshd_config_file/) | [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation)| Anomaly | | [Linux Possible Access To Credential Files](/endpoint/linux_possible_access_to_credential_files/) | [/etc/passwd and /etc/shadow](/tags/#/etc/passwd-and-/etc/shadow), [OS Credential Dumping](/tags/#os-credential-dumping)| Anomaly | diff --git a/docs/_stories/linux_rootkit.md b/docs/_stories/linux_rootkit.md new file mode 100644 index 0000000000..eece76bf1d --- /dev/null +++ b/docs/_stories/linux_rootkit.md @@ -0,0 +1,48 @@ +--- +title: "Linux Rootkit" +last_modified_at: 2022-07-27 +toc: true +toc_label: "" +tags: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation + - Reconnaissance +--- + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2022-07-27 +- **Author**: Michael Haag, Splunk +- **ID**: e30f4054-ac08-4999-b8bc-5cc46886c18d + +#### Narrative + +Rootkits or rootkit enabling functionality may reside at the user or kernel level in the operating system or lower, to include a hypervisor, Master Boot Record, or System Firmware. Rootkits have been seen for Windows, Linux, and Mac OS X systems. Linux rootkits may not standout as much as a Windows rootkit, therefore understanding what kernel modules are installed today and monitoring for new is important. As with any rootkit, it may blend in using a common kernel name or variation of legitimate names. + +#### Detections + +| Name | Technique | Type | +| ----------- | ----------- |--------------| +| [Linux File Created In Kernel Driver Directory](/endpoint/linux_file_created_in_kernel_driver_directory/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| Anomaly | +| [Linux Insert Kernel Module Using Insmod Utility](/endpoint/linux_insert_kernel_module_using_insmod_utility/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| Anomaly | +| [Linux Install Kernel Module Using Modprobe Utility](/endpoint/linux_install_kernel_module_using_modprobe_utility/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| Anomaly | +| [Linux Kernel Module Enumeration](/endpoint/linux_kernel_module_enumeration/) | [System Information Discovery](/tags/#system-information-discovery), [Rootkit](/tags/#rootkit)| Anomaly | + +#### Reference + +* [https://attack.mitre.org/techniques/T1014/](https://attack.mitre.org/techniques/T1014/) +* [https://content.fireeye.com/apt-41/rpt-apt41](https://content.fireeye.com/apt-41/rpt-apt41) +* [https://medium.com/chronicle-blog/winnti-more-than-just-windows-and-gates-e4f03436031a](https://medium.com/chronicle-blog/winnti-more-than-just-windows-and-gates-e4f03436031a) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/stories/linux_rootkit.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/mitre-map/coverage.json b/docs/mitre-map/coverage.json index 3ae393b8e1..d519883da1 100644 --- a/docs/mitre-map/coverage.json +++ b/docs/mitre-map/coverage.json @@ -6,8 +6,8 @@ "techniques": [ { "techniqueID": "T1059", - "score": 46, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/detect_risky_spl_using_pretrained_ml_model.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_command_and_scripting_interpreter_delete_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_command_and_scripting_interpreter_risky_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_command_and_scripting_interpreter_risky_spl_mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_distinct_processes_from_windows_temp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/living_off_the_land.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/log4shell_cve_2021_44228_exploitation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/macos_lolbin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_and_scripting_interpreter_hunting_path_traversal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_and_scripting_interpreter_path_traversal_exec.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_identify_protocol_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/exchange_powershell_module_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" + "score": 47, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/detect_risky_spl_using_pretrained_ml_model.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_command_and_scripting_interpreter_delete_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_command_and_scripting_interpreter_risky_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_command_and_scripting_interpreter_risky_spl_mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_distinct_processes_from_windows_temp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/living_off_the_land.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/log4shell_cve_2021_44228_exploitation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/macos_lolbin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_and_scripting_interpreter_hunting_path_traversal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_and_scripting_interpreter_path_traversal_exec.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_identify_protocol_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/exchange_powershell_module_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { "techniqueID": "T1083", @@ -41,8 +41,8 @@ }, { "techniqueID": "T1078", - "score": 36, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_user_enumeration_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_computer_account_name_change.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_kerberos_service_ticket_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_ticket_granting_ticket_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_account_lockout_events.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_failed_sso_attempts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_user_logins_from_multiple_cities.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_attach_to_role_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_permanent_key_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_role_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_sts_assume_role_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_detect_gcploit_framework.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unusual_number_of_computer_service_tickets_requested.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unusual_number_of_remote_endpoint_authentication_events.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_user_enumeration_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_powershell_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_computer_account_name_change.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_kerberos_service_ticket_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_ticket_granting_ticket_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_account_lockout_events.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_failed_sso_attempts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_user_logins_from_multiple_cities.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_attach_to_role_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_permanent_key_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_role_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_sts_assume_role_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_detect_gcploit_framework.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unusual_number_of_computer_service_tickets_requested.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unusual_number_of_remote_endpoint_authentication_events.yml" }, { "techniqueID": "T1189", @@ -51,8 +51,8 @@ }, { "techniqueID": "T1078.004", - "score": 19, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml" + "score": 21, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_powershell_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml" }, { "techniqueID": "T1136.003", @@ -64,6 +64,16 @@ "score": 11, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_new_federated_domain_added.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___account_harvesting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_add_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, + { + "techniqueID": "T1562.008", + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_impair_security_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_update_cloudtrail.yml" + }, + { + "techniqueID": "T1562", + "score": 61, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_impair_security_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_update_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_iptables_firewall_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_for_service_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_excessive_disabled_services_event.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_registry_delete_task_sd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_terminating_lsass_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml" + }, { "techniqueID": "T1486", "score": 7, @@ -91,8 +101,8 @@ }, { "techniqueID": "T1110", - "score": 11, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disabled_users_failing_to_authenticate_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_invalid_users_failed_authentication_via_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_users_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/high_number_of_login_failures_from_a_single_source.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_active_directory_high_risk_sign_in.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disabled_users_failing_to_authenticate_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_invalid_users_failed_authentication_via_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_users_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/high_number_of_login_failures_from_a_single_source.yml" }, { "techniqueID": "T1098", @@ -115,9 +125,19 @@ "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_network_acl_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml" }, { - "techniqueID": "T1562", - "score": 55, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_iptables_firewall_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_for_service_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_excessive_disabled_services_event.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_registry_delete_task_sd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_terminating_lsass_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml" + "techniqueID": "T1110.003", + "score": 11, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/azure_active_directory_high_risk_sign_in.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disabled_users_failing_to_authenticate_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_invalid_users_failed_authentication_via_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_users_authenticate_using_explicit_credentials.yml" + }, + { + "techniqueID": "T1621", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml" + }, + { + "techniqueID": "T1003.002", + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml" }, { "techniqueID": "T1554", @@ -246,8 +266,8 @@ }, { "techniqueID": "T1059.003", - "score": 8, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_started_forcefully.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml" + "score": 9, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_started_forcefully.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml" }, { "techniqueID": "T1078.002", @@ -356,8 +376,8 @@ }, { "techniqueID": "T1548", - "score": 23, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_operation_with_consent_admin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_uac_remote_restriction.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_common_process_for_elevation_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_doas_conf_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_doas_tool_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_access_to_sudoers_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_setuid_using_chmod_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_setuid_using_setcap_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_sudo_or_su_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_sudoers_tmp_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_visudo_utility_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/services_escalate_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml" + "score": 24, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_operation_with_consent_admin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_uac_remote_restriction.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_common_process_for_elevation_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_doas_conf_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_doas_tool_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_persistence_and_privilege_escalation_risk_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_access_to_sudoers_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_setuid_using_chmod_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_setuid_using_setcap_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_sudo_or_su_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_sudoers_tmp_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_visudo_utility_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/services_escalate_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml" }, { "techniqueID": "T1105", @@ -384,11 +404,6 @@ "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_registry_certificate_added.yml" }, - { - "techniqueID": "T1003.002", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml" - }, { "techniqueID": "T1490", "score": 10, @@ -476,8 +491,8 @@ }, { "techniqueID": "T1027", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/csc_net_on_the_fly_compilation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/csc_net_on_the_fly_compilation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_decode_base64_to_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1531", @@ -724,11 +739,21 @@ "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml" }, + { + "techniqueID": "T1115", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_clipboard_data_copy.yml" + }, { "techniqueID": "T1548.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_common_process_for_elevation_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_setuid_using_chmod_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_setuid_using_setcap_utility.yml" }, + { + "techniqueID": "T1059.004", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_decode_base64_to_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/macos_lolbin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_linux_discovery_commands.yml" + }, { "techniqueID": "T1548.003", "score": 7, @@ -754,6 +779,16 @@ "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_file_creation_in_profile_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml" }, + { + "techniqueID": "T1082", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_kernel_module_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/web_servers_executing_suspicious_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/detect_attackers_scanning_for_vulnerable_jboss_servers.yml" + }, + { + "techniqueID": "T1014", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_kernel_module_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_driver_load_non_standard_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_drivers_loaded_by_signature.yml" + }, { "techniqueID": "T1036.004", "score": 1, @@ -766,8 +801,8 @@ }, { "techniqueID": "T1098.004", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_ssh_key_file_creation.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_ssh_key_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_ssh_authorized_keys_modification.yml" }, { "techniqueID": "T1003.008", @@ -784,6 +819,11 @@ "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_service_file_created_in_systemd_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_service_restarted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_service_started_or_enabled.yml" }, + { + "techniqueID": "T1021.004", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_ssh_remote_services_script_execute.yml" + }, { "techniqueID": "T1055.001", "score": 2, @@ -794,11 +834,6 @@ "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/logon_script_event_trigger_execution.yml" }, - { - "techniqueID": "T1059.004", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/macos_lolbin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_linux_discovery_commands.yml" - }, { "techniqueID": "T1647", "score": 1, @@ -839,11 +874,6 @@ "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msi_module_loaded_by_non_system_binary.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, - { - "techniqueID": "T1110.003", - "score": 8, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disabled_users_failing_to_authenticate_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_invalid_users_failed_authentication_via_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_users_authenticate_using_explicit_credentials.yml" - }, { "techniqueID": "T1016.001", "score": 1, @@ -959,11 +989,6 @@ "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, - { - "techniqueID": "T1082", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/web_servers_executing_suspicious_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/detect_attackers_scanning_for_vulnerable_jboss_servers.yml" - }, { "techniqueID": "T1547.003", "score": 1, @@ -1004,11 +1029,6 @@ "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_credential_theft.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_in_non_standard_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_remote_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_uninstall_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_uninstall_option_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_url_in_command_line.yml" }, - { - "techniqueID": "T1014", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_driver_load_non_standard_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_drivers_loaded_by_signature.yml" - }, { "techniqueID": "T1202", "score": 2, @@ -1044,6 +1064,16 @@ "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_access_software_rms_registry.yml" }, + { + "techniqueID": "T1529", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_logoff_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_reboot_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_shutdown_commandline.yml" + }, + { + "techniqueID": "T1124", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_time_discovery_w32tm_delay.yml" + }, { "techniqueID": "T1220", "score": 2, @@ -1152,7 +1182,7 @@ "#096ed7" ], "minValue": 0, - "maxValue": 55 + "maxValue": 61 }, "filters": { "platforms": [ From d1f890a4e9fb2be9ca148275882d6b1e5b508449 Mon Sep 17 00:00:00 2001 From: Lou Stella Date: Fri, 29 Jul 2022 17:12:35 -0500 Subject: [PATCH 2/2] Adding hunting playbook --- playbooks/hunting.json | 5505 ++++++++++++++++++++++++++++++++++++++++ playbooks/hunting.png | Bin 0 -> 204044 bytes playbooks/hunting.py | 373 +++ playbooks/hunting.yml | 24 + 4 files changed, 5902 insertions(+) create mode 100644 playbooks/hunting.json create mode 100644 playbooks/hunting.png create mode 100644 playbooks/hunting.py create mode 100644 playbooks/hunting.yml diff --git a/playbooks/hunting.json b/playbooks/hunting.json new file mode 100644 index 0000000000..499206cba8 --- /dev/null +++ b/playbooks/hunting.json @@ -0,0 +1,5505 @@ +{ + "blockly": false, + "blockly_xml": "", + "category": "Onboarding", + "coa": { + "data": { + "clean": true, + "code_block": "\"\"\"\nThe hunting Playbook queries a number of internal security technologies in order to determine if any of the artifacts present in your data source have been observed in your environment.\n\"\"\"\n\ndef get_specific_assets(action, include_products=None):\n \n supported_assets = phantom.get_assets(action=action)\n # phantom.debug(\"Action Supported Assets\")\n # phantom.debug(supported_assets)\n \n if not supported_assets:\n # no supported products configured\n return []\n \n if not include_products:\n # no product filters, so return whatever we found\n return [x['name'] for x in supported_assets]\n \n if include_products:\n \n if (type(include_products) != list):\n phantom.debug(\"Please specify a list for filter_products\")\n return []\n \n # make the product names sent to this funcion lower\n include_products = [x.lower() for x in include_products]\n \n # get products that are configured and asked for\n assets_matched = [x['name'] for x in supported_assets if x['product_name'].lower() in include_products]\n # phantom.debug(\"Action Supported Matches\")\n # phantom.debug(assets_matched)\n return assets_matched\n \n # should not reach here\n return []", + "description": "Hunt for internal sightings of malicious files or connections to malicious domains or IP addresses.", + "joint": { + "cells": [ + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "370dd52c-9988-4e95-bfa0-7326d1710717", + "router": { + "name": "metro" + }, + "source": { + "id": "316c9705-7ae6-421d-8e39-09ed4d5eaf72", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "2c95ee18-c36d-40b4-9a1d-889badec9d4f", + "selector": ".port-body[type=\"input\"]" + }, + "type": "link", + "z": 4 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "c3529b6a-3e65-4955-ba02-34c06302327a", + "router": { + "name": "metro" + }, + "source": { + "id": "2c95ee18-c36d-40b4-9a1d-889badec9d4f", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "8656f57d-779a-4133-a244-5191a6714a83", + "selector": ".port-body[type=\"input\"]" + }, + "type": "link", + "z": 29 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "6d247fbe-3ded-4151-ad4a-93302a55e32b", + "router": { + "name": "metro" + }, + "source": { + "id": "316c9705-7ae6-421d-8e39-09ed4d5eaf72", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "ed123d2f-999b-4cdc-b141-a48f7da89227", + "selector": ".port-body[type=\"input\"]" + }, + "type": "link", + "z": 69 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "1b0673da-2779-464c-a51c-2563217414a2", + "router": { + "name": "metro" + }, + "source": { + "id": "8656f57d-779a-4133-a244-5191a6714a83", + "port": "out-1", + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "666fe7a3-1c31-4238-ba36-ea3cfd8d2884", + "selector": ".port-body[type=\"input\"]" + }, + "type": "link", + "z": 177 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "5191bf3b-fdaa-4f48-ac52-4e7419e69664", + "router": { + "name": "metro" + }, + "source": { + "id": "666fe7a3-1c31-4238-ba36-ea3cfd8d2884", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "65cec994-6cd3-47da-849a-f015982d8a23", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" + }, + "type": "link", + "vertices": [ + { + "x": 1600, + "y": 80 + } + ], + "z": 202 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "f6873242-210c-4a03-9461-9a251503c199", + "router": { + "name": "metro" + }, + "source": { + "id": "5578c85f-4a27-401e-be14-7793e82b92c5", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "7ca41dcf-c8bd-46f4-bb7d-6df6d254c01f", + "selector": ".port-body[type=\"input\"]" + }, + "type": "link", + "z": 609 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "6011a55b-8289-4934-9db9-70b4416ebd1f", + "router": { + "name": "metro" + }, + "source": { + "id": "7ca41dcf-c8bd-46f4-bb7d-6df6d254c01f", + "port": "out-1", + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "9052a241-042b-4189-b56d-fcc0bf461cc6", + "selector": ".port-body[type=\"input\"]" + }, + "type": "link", + "z": 616 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "e75dcbfb-0575-442a-a3ec-468a815144a2", + "router": { + "name": "metro" + }, + "source": { + "id": "9052a241-042b-4189-b56d-fcc0bf461cc6", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "93d4e099-5891-4c2b-b6db-ac512e981f06", + "selector": ".port-body[type=\"input\"]" + }, + "type": "link", + "z": 686 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "282072cb-d450-40c0-b142-6727d131f38a", + "router": { + "name": "metro" + }, + "source": { + "id": "93d4e099-5891-4c2b-b6db-ac512e981f06", + "port": "out-1", + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "e07929c3-d5ce-44c1-b08d-3b4fede3bc59", + "selector": ".port-body[type=\"input\"]" + }, + "type": "link", + "z": 713 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "8346a4a6-4ca6-429c-a9ed-df734d719534", + "router": { + "name": "metro" + }, + "source": { + "id": "316c9705-7ae6-421d-8e39-09ed4d5eaf72", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "8c6c1d82-e40b-4f58-b6c0-cc8c40791cae", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" + }, + "type": "link", + "z": 864 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "028d5235-a996-48e5-9f5e-05042bf25230", + "router": { + "name": "metro" + }, + "source": { + "id": "ed123d2f-999b-4cdc-b141-a48f7da89227", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "c79812bd-7079-4317-a492-d36f2de1ac83", + "selector": ".port-body[type=\"input\"]" + }, + "type": "link", + "z": 918 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "e397dbe7-376c-4760-bdd8-a4cbf8ff7cc0", + "router": { + "name": "metro" + }, + "source": { + "id": "c79812bd-7079-4317-a492-d36f2de1ac83", + "port": "out-1", + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "5578c85f-4a27-401e-be14-7793e82b92c5", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" + }, + "type": "link", + "z": 1009 + }, + { + "0": "S", + "1": "T", + "2": "A", + "3": "R", + "4": "T", + "active": false, + "angle": 0, + "attrs": { + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".color-band": { + "fill": "#3C444D" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "ref-x": 33, + "ref-y": 8, + "text": "START" + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "ref-x": 13, + "xlink:href": "/inc/coa/img/block_icon_start.svg" + }, + "g.notes": { + "display": "block" + } + }, + "block_code": "def on_start(container):\n phantom.debug('on_start() called')\n \n # call 'hunt_domain_1' block\n hunt_domain_1(container=container)\n\n # call 'hunt_file_1' block\n hunt_file_1(container=container)\n\n # call 'run_query_1' block\n run_query_1(container=container)\n\n return", + "callback_code": "# read-only block view not available", + "callback_start": 1, + "callsback": false, + "connected_to_start": true, + "connection_name": "", + "connection_type": "", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "description": "", + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "316c9705-7ae6-421d-8e39-09ed4d5eaf72", + "inPorts": [], + "join_code": "# read-only block view not available", + "join_optional": [], + "join_start": 1, + "line_end": 64, + "line_start": 50, + "name": "", + "notes": "", + "number": 0, + "order": 1, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 120, + "y": 60 + }, + "previous_function": "", + "previous_name": "", + "show_number": true, + "size": { + "height": 54, + "width": 80 + }, + "status": "", + "title": "START", + "type": "coa.StartEnd", + "warn": false, + "z": 1197 + }, + { + "0": "E", + "1": "N", + "2": "D", + "active": false, + "angle": 0, + "attrs": { + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".title": { + "text": "END" + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_end.svg" + }, + "g.notes": { + "display": "block" + } + }, + "block_code": "def on_finish(container, summary):\n phantom.debug('on_finish() called')\n # This function is called after all actions are completed.\n # summary of all the action and/or all details of actions\n # can be collected here.\n\n # summary_json = phantom.get_summary()\n # if 'result' in summary_json:\n # for action_result in summary_json['result']:\n # if 'action_run_id' in action_result:\n # action_results = phantom.get_action_results(action_run_id=action_result['action_run_id'], result_data=False, flatten=False)\n # phantom.debug(action_results)\n\n return", + "callback_code": "# read-only block view not available", + "callback_start": 1, + "callsback": false, + "connected_to_start": true, + "connection_name": "get system info, detonate file, run query", + "connection_type": "action", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "description": "", + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "65cec994-6cd3-47da-849a-f015982d8a23", + "inPorts": [ + "in" + ], + "join_code": "# read-only block view not available", + "join_optional": [], + "join_start": 1, + "line_end": 373, + "line_start": 360, + "name": "", + "notes": "", + "number": 0, + "order": 13, + "outPorts": [], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 1660, + "y": 340 + }, + "previous_function": "", + "previous_name": "", + "show_number": true, + "size": { + "height": 54, + "width": 80 + }, + "status": "", + "title": "END", + "type": "coa.StartEnd", + "warn": false, + "z": 1273 + }, + { + "action": "get system info", + "action_type": "investigate", + "active": false, + "active_keys": {}, + "active_values": { + "ip_hostname": "filtered-artifact:*.cef.sourceAddress" + }, + "angle": 0, + "app": "", + "approver": "", + "assets": [ + { + "action": "", + "active": true, + "app_name": "", + "app_version": "", + "appid": "", + "config_type": "asset", + "fields": { + "ip_hostname": "filtered-artifact:*.cef.sourceAddress", + "sensor_id": "" + }, + "has_app": true, + "id": "-", + "loaded": false, + "missing": false, + "name": "carbonblack", + "output": [ + { + "contains": [ + "carbon black sensor id" + ], + "data_path": "action_result.parameter.sensor_id", + "data_type": "numeric" + }, + { + "contains": [ + "host name", + "ip" + ], + "data_path": "action_result.parameter.ip_hostname", + "data_type": "string" + }, + { + "data_path": "action_result.status", + "data_type": "string" + }, + { + "data_path": "action_result.message", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.systemvolume_total_size", + "data_type": "string" + }, + { + "column_name": "OS", + "column_order": 4, + "data_path": "action_result.data.*.os_environment_display_string", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.systemvolume_free_size", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.physical_memory_size", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.shard_id", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.clock_delta", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.supports_cblr", + "data_type": "boolean" + }, + { + "data_path": "action_result.data.*.sensor_uptime", + "data_type": "string" + }, + { + "column_name": "Is Isolated?", + "column_order": 2, + "data_path": "action_result.data.*.is_isolating", + "data_type": "boolean" + }, + { + "column_name": "Sensor ID", + "column_order": 5, + "contains": [ + "carbon black sensor id" + ], + "data_path": "action_result.data.*.id", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.build_id", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.uptime", + "data_type": "string" + }, + { + "column_name": "DNS Name", + "column_order": 3, + "data_path": "action_result.data.*.computer_dns_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.last_update", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.power_state", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.next_checkin_time", + "data_type": "string" + }, + { + "column_name": "Status", + "column_order": 2, + "data_path": "action_result.data.*.status", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.num_eventlog_bytes", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sensor_health_status", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.sensor_health_message", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.build_version_string", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.computer_sid", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.node_id", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.cookie", + "data_type": "numeric" + }, + { + "column_name": "Name", + "column_order": 0, + "contains": [ + "host name" + ], + "data_path": "action_result.data.*.computer_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.license_expiration", + "data_type": "string" + }, + { + "column_name": "Supports Isolation?", + "column_order": 4, + "data_path": "action_result.data.*.supports_isolation", + "data_type": "boolean" + }, + { + "data_path": "action_result.data.*.parity_host_id", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.supports_2nd_gen_modloads", + "data_type": "boolean" + }, + { + "data_path": "action_result.data.*.network_adapters", + "data_type": "string" + }, + { + "column_name": "IP Addresses", + "column_order": 1, + "data_path": "action_result.data.*.ips", + "data_type": "string" + }, + { + "column_name": "Isolation Enabled?", + "column_order": 3, + "data_path": "action_result.data.*.network_isolation_enabled", + "data_type": "boolean" + }, + { + "data_path": "action_result.data.*.registration_time", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.restart_queued", + "data_type": "boolean" + }, + { + "data_path": "action_result.data.*.num_storefiles_bytes", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.os_environment_id", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.boot_id", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.last_checkin_time", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.group_id", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.display", + "data_type": "boolean" + }, + { + "data_path": "action_result.data.*.uninstall", + "data_type": "boolean" + }, + { + "data_path": "action_result.data.*.event_log_flush_time", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.emet_telemetry_path", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.emet_version", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.emet_report_setting", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.emet_exploit_action", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.emet_is_gpo", + "data_type": "boolean" + }, + { + "data_path": "action_result.data.*.emet_dump_flags", + "data_type": "string" + }, + { + "data_path": "action_result.summary.total_endpoints", + "data_type": "numeric" + }, + { + "data_path": "summary.total_objects", + "data_type": "numeric" + }, + { + "data_path": "summary.total_objects_successful", + "data_type": "numeric" + } + ], + "product_name": "", + "product_vendor": "", + "type": "endpoint" + } + ], + "attrs": { + ".action": { + "text": "get system info" + }, + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".border": { + "stroke": "#5094D4" + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".message": { + "fill": "#FFFFFF", + "font-size": 12, + "font-weight": 300, + "opacity": 0, + "ref": ".background", + "ref-x": 5, + "ref-y": 105, + "text": "Configuring now" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "text": "Investigate" + }, + "g.approver image": { + "opacity": 1 + }, + "g.code image": { + "opacity": 1, + "xlink:href": "/inc/coa/img/block_icon_code_dark_on.svg" + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_investigate.svg" + }, + "g.notes": { + "display": "block" + }, + "g.notes image": { + "opacity": 1 + }, + "g.timer image": { + "opacity": 1 + }, + "rect.warn-background": { + "fill": "#5094D4" + }, + "text.icon": { + "fill": "#5094D4" + } + }, + "block_code": "# read-only block view not available", + "callback_code": "", + "callback_start": 1, + "callsback": true, + "color": "#654796", + "connected_to_start": false, + "connection_name": "hunt domain", + "connection_type": "action", + "custom_callback": "", + "custom_code": "def get_system_info_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None):\n \n assets = get_specific_assets(\"get system info\", [\"Carbon Black\"])\n \n if (not assets):\n phantom.debug(\"Carbon Black::get system info not found returning.\")\n \n # collect data for 'get_system_info_1' call\n filtered_container_data = phantom.collect2(container=container, datapath=['filtered-artifact:*.cef.sourceAddress', 'filtered-artifact:*.id'], filter_artifacts=filtered_artifacts)\n\n parameters = []\n \n # build parameters list for 'get_system_info_1' call\n for filtered_container_item in filtered_container_data:\n if filtered_container_item[0]:\n parameters.append({\n 'ip_hostname': filtered_container_item[0],\n })\n\n if parameters:\n phantom.act(\"get system info\", parameters=parameters, assets=assets, name=\"get_system_info_1\") \n else:\n phantom.error(\"'get_system_info_1' will not be executed due to lack of parameters\")\n \n return", + "custom_join": "", + "custom_name": "", + "delay": "0", + "description": "", + "has_custom": true, + "has_custom_block": true, + "has_custom_callback": false, + "has_custom_join": false, + "id": "666fe7a3-1c31-4238-ba36-ea3cfd8d2884", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 110, + "line_start": 84, + "message": "Configuring now", + "name": "get system info", + "notes": "", + "number": 1, + "order": 3, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 640, + "y": 40 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "get_system_info_1", + "required_params": {}, + "reviewer": "", + "showNumber": false, + "show_number": false, + "size": { + "height": 112, + "width": 168 + }, + "state": "asset", + "status": "", + "title": "Investigate", + "type": "coa.Action", + "warn": false, + "z": 1320 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "1f411c3a-1b14-4e69-9501-b9110eb433be", + "router": { + "name": "metro" + }, + "source": { + "id": "e07929c3-d5ce-44c1-b08d-3b4fede3bc59", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "65cec994-6cd3-47da-849a-f015982d8a23", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" + }, + "type": "link", + "vertices": [ + { + "x": 1620, + "y": 220 + } + ], + "z": 1336 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "b859523d-1b6a-4d34-898d-3e5d5372a8ef", + "router": { + "name": "metro" + }, + "source": { + "id": "8c6c1d82-e40b-4f58-b6c0-cc8c40791cae", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "65cec994-6cd3-47da-849a-f015982d8a23", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" + }, + "type": "link", + "z": 1337 + }, + { + "active": false, + "angle": 0, + "attrs": { + ".background": { + "fill": "#000000", + "stroke": "#5C6773", + "transform": "rotate(45 30 70)" + }, + ".border": { + "stroke": "#5094D4", + "transform": "rotate(45 30 70)" + }, + ".inPorts>.port-0>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".number": { + "text": 4 + }, + ".outPorts>.port-0": { + "port": { + "id": "out-1", + "type": "out" + }, + "ref-x": 83, + "ref-y": 40 + }, + ".outPorts>.port-0>.port-body": { + "port": { + "id": "out-1", + "type": "out" + } + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.notes": { + "display": "block" + }, + "g.notes image": { + "opacity": 1 + } + }, + "block_code": "def filter_4(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('filter_4() called')\n\n # collect filtered artifact ids for 'if' condition 1\n matched_artifacts_1, matched_results_1 = phantom.condition(\n container=container,\n action_results=results,\n conditions=[\n [\"hunt_file_1:action_result.data.*.binary.total_results\", \">\", 0],\n [\"artifact:*.cef.fileHash\", \"==\", \"hunt_file_1:action_result.parameter.hash\"],\n ],\n logical_operator='and',\n name=\"filter_4:condition_1\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_1 or matched_results_1:\n file_reputation_1(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n\n return", + "callback_code": "", + "callback_start": 1, + "callsback": false, + "connected_to_start": true, + "connection_name": "hunt file", + "connection_type": "action", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "description": "", + "hasElse": false, + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "c79812bd-7079-4317-a492-d36f2de1ac83", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 130, + "line_start": 110, + "name": "filter", + "notes": "", + "number": 4, + "order": 4, + "outPorts": [ + "out-1" + ], + "outputs": [ + { + "conditions": [ + { + "comparison": ">", + "data_type": "", + "param": "hunt_file_1:action_result.data.*.binary.total_results", + "value": "0" + }, + { + "comparison": "==", + "data_type": "", + "param": "artifact:*.cef.fileHash", + "value": "hunt_file_1:action_result.parameter.hash" + } + ], + "display": "If", + "logic": "and", + "type": "if" + } + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 500, + "y": 180 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "filter_4", + "show_number": true, + "size": { + "height": 82, + "width": 82 + }, + "state": "filter", + "status": "", + "type": "coa.Filter", + "warn": false, + "z": 1343 + }, + { + "active": false, + "angle": 0, + "attrs": { + ".background": { + "fill": "#000000", + "stroke": "#5C6773", + "transform": "rotate(45 30 70)" + }, + ".border": { + "stroke": "#5094D4", + "transform": "rotate(45 30 70)" + }, + ".inPorts>.port-0>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".number": { + "text": 2 + }, + ".outPorts>.port-0": { + "port": { + "id": "out-1", + "type": "out" + }, + "ref-x": 83, + "ref-y": 40 + }, + ".outPorts>.port-0>.port-body": { + "port": { + "id": "out-1", + "type": "out" + } + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.notes": { + "display": "block" + }, + "g.notes image": { + "opacity": 1 + } + }, + "block_code": "def filter_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('filter_2() called')\n\n # collect filtered artifact ids for 'if' condition 1\n matched_artifacts_1, matched_results_1 = phantom.condition(\n container=container,\n action_results=results,\n conditions=[\n [\"action_result.summary.positives\", \"==\", 0],\n [\"artifact:*.cef.fileHash\", \"==\", \"file_reputation_1:action_result.parameter.hash\"],\n ],\n logical_operator='and',\n name=\"filter_2:condition_1\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_1 or matched_results_1:\n get_file_2(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n\n return", + "callback_code": "", + "callback_start": 1, + "callsback": false, + "connected_to_start": true, + "connection_name": "file reputation", + "connection_type": "action", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "description": "", + "hasElse": false, + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "7ca41dcf-c8bd-46f4-bb7d-6df6d254c01f", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 150, + "line_start": 130, + "name": "filter", + "notes": "", + "number": 2, + "order": 5, + "outPorts": [ + "out-1" + ], + "outputs": [ + { + "conditions": [ + { + "comparison": "==", + "data_type": "", + "param": "action_result.summary.positives", + "value": "0" + }, + { + "comparison": "==", + "data_type": "", + "param": "artifact:*.cef.fileHash", + "value": "file_reputation_1:action_result.parameter.hash" + } + ], + "display": "If", + "logic": "and", + "type": "if" + } + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 880, + "y": 180 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "filter_2", + "show_number": true, + "size": { + "height": 82, + "width": 82 + }, + "state": "filter", + "status": "", + "type": "coa.Filter", + "warn": false, + "z": 1345 + }, + { + "action": "get file", + "action_type": "investigate", + "active": false, + "active_keys": {}, + "active_values": { + "hash": "filtered-artifact:*.cef.fileHash" + }, + "angle": 0, + "app": "", + "approver": "", + "assets": [ + { + "action": "", + "active": true, + "app_name": "", + "app_version": "", + "appid": "", + "config_type": "asset", + "fields": { + "hash": "filtered-artifact:*.cef.fileHash" + }, + "has_app": true, + "id": "-", + "loaded": false, + "missing": false, + "name": "carbonblack", + "output": [ + { + "data_path": "action_result.data.*.name", + "data_type": "string" + }, + { + "column_name": "Vault ID", + "column_order": 1, + "contains": [ + "vault id" + ], + "data_path": "action_result.data.*.vault_id", + "data_type": "string" + }, + { + "column_name": "MD5", + "column_order": 0, + "contains": [ + "md5", + "hash" + ], + "data_path": "action_result.data.*.file_details.md5", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.icon", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.group", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.signed", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.os_type", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.endpoint", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.is_64bit", + "data_type": "boolean" + }, + { + "data_path": "action_result.data.*.file_details.file_desc", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.last_seen", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.timestamp", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.cb_version", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.file_details.host_count", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.file_details.watchlists.*.wid", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.watchlists.*.value", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.company_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.file_version", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.orig_mod_len", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.file_details.product_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.digsig_result", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.internal_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.copied_mod_len", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.file_details.legal_copyright", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.product_version", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.digsig_publisher", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.digsig_sign_time", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.observed_filename", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.original_filename", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.digsig_result_code", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.file_details.is_executable_image", + "data_type": "boolean" + }, + { + "data_path": "action_result.data.*.file_details.server_added_timestamp", + "data_type": "string" + }, + { + "data_path": "action_result.status", + "data_type": "string" + }, + { + "data_path": "action_result.message", + "data_type": "string" + }, + { + "data_path": "action_result.summary.name", + "data_type": "string" + }, + { + "contains": [ + "vault id" + ], + "data_path": "action_result.summary.vault_id", + "data_type": "string" + }, + { + "data_path": "action_result.summary.file_type", + "data_type": "string" + }, + { + "contains": [ + "hash", + "md5" + ], + "data_path": "action_result.parameter.hash", + "data_type": "string" + }, + { + "data_path": "summary.total_objects", + "data_type": "numeric" + }, + { + "data_path": "summary.total_objects_successful", + "data_type": "numeric" + } + ], + "product_name": "", + "product_vendor": "", + "type": "endpoint" + } + ], + "attrs": { + ".action": { + "text": "get file" + }, + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".border": { + "stroke": "#5094D4" + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".message": { + "fill": "#FFFFFF", + "font-size": 12, + "font-weight": 300, + "opacity": 0, + "ref": ".background", + "ref-x": 5, + "ref-y": 105, + "text": "Configuring now" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "text": "Investigate" + }, + "g.approver image": { + "opacity": 1 + }, + "g.code image": { + "opacity": 1, + "xlink:href": "/inc/coa/img/block_icon_code_dark_on.svg" + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_investigate.svg" + }, + "g.notes": { + "display": "block" + }, + "g.notes image": { + "opacity": 1 + }, + "g.timer image": { + "opacity": 1 + }, + "rect.warn-background": { + "fill": "#5094D4" + }, + "text.icon": { + "fill": "#5094D4" + } + }, + "block_code": "# read-only block view not available", + "callback_code": "", + "callback_start": 1, + "callsback": true, + "color": "#654796", + "connected_to_start": true, + "connection_name": "file reputation", + "connection_type": "action", + "custom_callback": "", + "custom_code": "def get_file_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None):\n \n assets = get_specific_assets(\"get file\", [\"Carbon Black\"])\n \n if (not assets):\n phantom.debug(\"Carbon Black::get file not found returning.\")\n \n # collect data for 'get_file_2' call\n filtered_container_data = phantom.collect2(container=container, datapath=['filtered-artifact:*.cef.fileHash', 'filtered-artifact:*.id'], filter_artifacts=filtered_artifacts)\n\n parameters = []\n \n # build parameters list for 'get_file_2' call\n for filtered_container_item in filtered_container_data:\n if filtered_container_item[0]:\n parameters.append({\n 'hash': filtered_container_item[0],\n })\n\n if parameters:\n phantom.act(\"get file\", parameters=parameters, assets=assets, callback=filter_3, name=\"get_file_2\") \n else:\n phantom.error(\"'get_file_2' will not be executed due to lack of parameters\")\n \n return", + "custom_join": "", + "custom_name": "", + "delay": "0", + "description": "", + "has_custom": true, + "has_custom_block": true, + "has_custom_callback": false, + "has_custom_join": false, + "id": "9052a241-042b-4189-b56d-fcc0bf461cc6", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 205, + "line_start": 179, + "message": "Configuring now", + "name": "get file", + "notes": "", + "number": 2, + "order": 7, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 1020, + "y": 180 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "get_file_2", + "required_params": { + "hash": true + }, + "reviewer": "", + "showNumber": false, + "show_number": false, + "size": { + "height": 112, + "width": 168 + }, + "state": "asset", + "status": "", + "title": "Investigate", + "type": "coa.Action", + "warn": false, + "z": 1350 + }, + { + "action": "detonate file", + "action_type": "investigate", + "active": false, + "active_keys": {}, + "active_values": { + "file_name": "", + "force_analysis": "", + "private": "", + "vault_id": "get_file_2:filtered-action_result.data.*.vault_id", + "vm": "" + }, + "angle": 0, + "app": "", + "approver": "", + "assets": [ + { + "action": "", + "active": true, + "app_name": "", + "app_version": "", + "appid": "", + "config_type": "asset", + "fields": { + "file_name": "", + "force_analysis": "", + "private": "", + "vault_id": "get_file_2:filtered-action_result.data.*.vault_id", + "vm": "" + }, + "has_app": true, + "id": "-", + "loaded": false, + "missing": false, + "name": "threatgrid", + "output": [ + { + "contains": [ + "threatgrid task id" + ], + "data_path": "action_result.summary.id", + "data_type": "string" + }, + { + "contains": [ + "url" + ], + "data_path": "action_result.summary.results_url", + "data_type": "string" + }, + { + "contains": [ + "file name" + ], + "data_path": "action_result.summary.target", + "data_type": "string" + }, + { + "contains": [ + "hash", + "md5" + ], + "data_path": "action_result.data.*.report.disk.mbr.hashes.curr.md5", + "data_type": "string" + }, + { + "contains": [ + "hash", + "sha1" + ], + "data_path": "action_result.data.*.report.disk.mbr.hashes.curr.sha1", + "data_type": "string" + }, + { + "contains": [ + "hash", + "sha256" + ], + "data_path": "action_result.data.*.report.disk.mbr.hashes.curr.sha256", + "data_type": "string" + }, + { + "contains": [ + "hash", + "md5" + ], + "data_path": "action_result.data.*.report.disk.mbr.hashes.orig.md5", + "data_type": "string" + }, + { + "contains": [ + "hash", + "sha1" + ], + "data_path": "action_result.data.*.report.disk.mbr.hashes.orig.sha1", + "data_type": "string" + }, + { + "contains": [ + "hash", + "sha256" + ], + "data_path": "action_result.data.*.report.disk.mbr.hashes.orig.sha256", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.disk.mbr.changed", + "data_type": "boolean" + }, + { + "data_path": "action_result.data.*.report.disk.mbr.contents.curr", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.disk.mbr.contents.orig", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.disk.partition_tables.curr.*.size", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.disk.partition_tables.curr.*.type", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.disk.partition_tables.curr.*.start", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.disk.partition_tables.orig.*.size", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.disk.partition_tables.orig.*.type", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.disk.partition_tables.orig.*.start", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.disk.partition_tables.changed", + "data_type": "boolean" + }, + { + "data_path": "action_result.data.*.report.iocs.*.ioc", + "data_type": "string" + }, + { + "contains": [ + "url" + ], + "data_path": "action_result.data.*.report.iocs.*.data.*.URL", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.iocs.*.data.*.Method", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.iocs.*.data.*.Network_Stream", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.iocs.*.hits", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.iocs.*.tags", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.iocs.*.title", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.iocs.*.category", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.iocs.*.severity", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.iocs.*.truncated", + "data_type": "boolean" + }, + { + "data_path": "action_result.data.*.report.iocs.*.confidence", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.iocs.*.description", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.status.id", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.status.vm", + "data_type": "string" + }, + { + "contains": [ + "hash", + "md5" + ], + "data_path": "action_result.data.*.report.status.md5", + "data_type": "string" + }, + { + "contains": [ + "hash", + "sha1" + ], + "data_path": "action_result.data.*.report.status.sha1", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.status.origin", + "data_type": "string" + }, + { + "contains": [ + "hash", + "sha256" + ], + "data_path": "action_result.data.*.report.status.sha256", + "data_type": "string" + }, + { + "contains": [ + "url" + ], + "data_path": "action_result.data.*.report.status.done_url", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.status.running_on", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.status.vm_runtime", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.status.original_filename", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.status.analysis_started_at", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.status.analysis_submitted_at", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.new", + "data_type": "boolean" + }, + { + "contains": [ + "pid" + ], + "data_path": "action_result.data.*.report.dynamic.processes.*.pid", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.kpid", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.proc", + "data_type": "boolean" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.time", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.monitored", + "data_type": "boolean" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.process_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.startup_info.tid", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.startup_info.upid", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.startup_info.uthread", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.startup_info.dll_path", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.startup_info.shell_info", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.startup_info.command_line", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.startup_info.desktop_info", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.startup_info.runtime_data", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.startup_info.window_title", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.startup_info.image_pathname", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.startup_info.current_directory", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.analyzed_because", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.registry_keys_read.*.key_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.registry_keys_read.*.key_value", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.registry_keys_opened.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.registry_keys_opened.*.access", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.dynamic.processes.*.registry_keys_opened.*.options", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.network.*.dst", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.network.*.src", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.network.*.uid", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.network.*.bytes", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.network.*.ts_end", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.network.*.history", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.network.*.packets", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.network.*.service", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.network.*.session", + "data_type": "numeric" + }, + { + "contains": [ + "port" + ], + "data_path": "action_result.data.*.report.network.*.dst_port", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.network.*.duration", + "data_type": "numeric" + }, + { + "contains": [ + "port" + ], + "data_path": "action_result.data.*.report.network.*.src_port", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.network.*.ts_begin", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.network.*.transport", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.network.*.bytes_orig", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.network.*.bytes_resp", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.network.*.conn_state", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.network.*.bytes_missed", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.network.*.packets_orig", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.network.*.packets_resp", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.network.*.bytes_payload", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.network.*.bytes_orig_payload", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.network.*.bytes_resp_payload", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.version", + "data_type": "numeric" + }, + { + "contains": [ + "hash", + "md5" + ], + "data_path": "action_result.data.*.report.metadata.malware_desc.*.md5", + "data_type": "string" + }, + { + "contains": [ + "hash", + "sha1" + ], + "data_path": "action_result.data.*.report.metadata.malware_desc.*.sha1", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.metadata.malware_desc.*.size", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.metadata.malware_desc.*.type", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.metadata.malware_desc.*.magic", + "data_type": "string" + }, + { + "contains": [ + "hash", + "md5" + ], + "data_path": "action_result.data.*.report.metadata.malware_desc.*.sha256", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.metadata.malware_desc.*.filename", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.metadata.sandcastle_env.vm", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.metadata.sandcastle_env.vm_id", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.metadata.sandcastle_env.run_time", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.metadata.sandcastle_env.current_os", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.metadata.sandcastle_env.sandcastle", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.metadata.sandcastle_env.analysis_end", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.metadata.sandcastle_env.analysis_start", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.metadata.sandcastle_env.controlsubject", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.metadata.sandcastle_env.sample_executed", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.metadata.general_details.sandbox_id", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.metadata.general_details.report_created", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.report.metadata.general_details.sandbox_version", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.versions.file.js", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.versions.file.pe", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.versions.file.ini", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.versions.file.lnk", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.versions.file.pdf", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.versions.file.rtf", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.versions.file.txt", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.versions.file.html", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.versions.file.version", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.versions.network.version", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.versions.version", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.created-time", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.entropy", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.exports", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.file_info.company_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.file_info.copyright", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.file_info.file_description", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.file_info.file_version", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.file_info.internal_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.file_info.original_file_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.file_info.product_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.file_info.product_version", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.dos.checksum", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.dos.header_relocations", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.dos.initial_code_segment", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.dos.initial_instruction_pointer", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.dos.initial_stack_pointer", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.dos.initial_stack_segment", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.dos.pages", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.dos.size_in_paragraphs", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.pe.import_hash", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.pe.number_of_symbols", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.pe.optional_header.actual_checksum", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.pe.optional_header.claimed_checksum", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.pe.optional_header.entrypoint_address", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.pe.optional_header.file_alignment", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.pe.optional_header.linker_major_version", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.pe.optional_header.linker_minor_version", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.pe.optional_header.loader_flag", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.pe.optional_header.number_of_rva_and_sizes", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.pe.optional_header.reserved_field", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.pe.optional_header.section_alignment", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.pe.optional_header.size", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.pe.optional_header.subsystem", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.pe.signed", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.headers.pe.timestamp", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.imports.*.dll", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.imports.*.entries", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.internal_checksum_match", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.resources.*.codepage", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.resources.*.language", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.resources.*.locale", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.resources.*.offset", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.resources.*.path", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.resources.*.resource_sha256", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.resources.*.size", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.resources.*.sublanguage", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.resources.*.type", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.sections.*.address", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.sections.*.characteristics", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.sections.*.data_pointer", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.sections.*.entropy", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.sections.*.entropy_type", + "data_type": "string" + }, + { + "contains": [ + "url" + ], + "data_path": "action_result.data.*.report.artifacts.*.forensics.Sections.InternetShortcut.Properties.URL", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.sections.*.section", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.sections.*.section_hash", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.sections.*.size", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.sections.*.virtual_size", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.signatures", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.tag_attrs", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.tags", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.forensics.urls", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.magic-type", + "data_type": "string" + }, + { + "contains": [ + "hash", + "md5" + ], + "data_path": "action_result.data.*.report.artifacts.*.md5", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.mime-type", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.origin", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.path", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.relation.network", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.relation.process", + "data_type": "string" + }, + { + "contains": [ + "hash", + "sha1" + ], + "data_path": "action_result.data.*.report.artifacts.*.sha1", + "data_type": "string" + }, + { + "contains": [ + "hash", + "sha256" + ], + "data_path": "action_result.data.*.report.artifacts.*.sha256", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.size", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.artifacts.*.type", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.report.annotations.network.*.ts", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.status.id", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.status.os", + "data_type": "string" + }, + { + "contains": [ + "hash", + "md5" + ], + "data_path": "action_result.data.*.status.md5", + "data_type": "string" + }, + { + "contains": [ + "hash", + "sha1" + ], + "data_path": "action_result.data.*.status.sha1", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.status.login", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.status.state", + "data_type": "string" + }, + { + "contains": [ + "hash", + "sha256" + ], + "data_path": "action_result.data.*.status.sha256", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.status.status", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.status.filename", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.status.started_at", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.status.completed_at", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.status.submitted_at", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.status.submission_id", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.threat.bis", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.threat.count", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.threat.score", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.threat.sample", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.threat.max-severity", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.threat.max-confidence", + "data_type": "numeric" + }, + { + "data_path": "action_result.status", + "data_type": "string" + }, + { + "data_path": "action_result.message", + "data_type": "string" + }, + { + "contains": [ + "file name" + ], + "data_path": "action_result.parameter.file_name", + "data_type": "string" + }, + { + "data_path": "action_result.parameter.force_analysis", + "data_type": "boolean" + }, + { + "contains": [ + "vault id", + "pe file", + "pdf" + ], + "data_path": "action_result.parameter.vault_id", + "data_type": "string" + }, + { + "data_path": "action_result.parameter.vm", + "data_type": "string" + }, + { + "data_path": "action_result.parameter.private", + "data_type": "boolean" + }, + { + "data_path": "summary.total_objects", + "data_type": "numeric" + }, + { + "data_path": "summary.total_objects_successful", + "data_type": "numeric" + } + ], + "product_name": "", + "product_vendor": "", + "type": "sandbox" + } + ], + "attrs": { + ".action": { + "text": "detonate file" + }, + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".border": { + "stroke": "#5094D4" + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".message": { + "fill": "#FFFFFF", + "font-size": 12, + "font-weight": 300, + "opacity": 0, + "ref": ".background", + "ref-x": 5, + "ref-y": 105, + "text": "Configuring now" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "text": "Investigate" + }, + "g.approver image": { + "opacity": 1 + }, + "g.code image": { + "opacity": 1, + "xlink:href": "/inc/coa/img/block_icon_code_dark_on.svg" + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_investigate.svg" + }, + "g.notes": { + "display": "block" + }, + "g.notes image": { + "opacity": 1 + }, + "g.timer image": { + "opacity": 1 + }, + "rect.warn-background": { + "fill": "#5094D4" + }, + "text.icon": { + "fill": "#5094D4" + } + }, + "block_code": "# read-only block view not available", + "callback_code": "", + "callback_start": 1, + "callsback": true, + "color": "#654796", + "connected_to_start": true, + "connection_name": "get file", + "connection_type": "action", + "custom_callback": "", + "custom_code": "def detonate_file_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None):\n \n assets = get_specific_assets(\"detonate file\", [\"Threat Grid\"])\n \n if (not assets):\n phantom.debug(\"Threat Grid::detonate file not found returning.\")\n \n # collect data for 'detonate_file_1' call\n filtered_results_data_1 = phantom.collect2(container=container, datapath=[\"get_file_2:filtered-action_result.data.*.vault_id\", \"get_file_2:filtered-action_result.parameter.context.artifact_id\"], action_results=filtered_results)\n\n parameters = []\n \n # build parameters list for 'detonate_file_1' call\n for filtered_results_item_1 in filtered_results_data_1:\n if filtered_results_item_1[0]:\n parameters.append({\n 'vault_id': filtered_results_item_1[0],\n 'file_name': \"\",\n 'vm': \"\",\n 'force_analysis': \"\",\n 'private': \"\",\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': filtered_results_item_1[1]},\n })\n\n if parameters:\n phantom.act(\"detonate file\", parameters=parameters, assets=assets, name=\"detonate_file_1\") \n else:\n phantom.error(\"'detonate_file_1' will not be executed due to lack of parameters\")\n \n return", + "custom_join": "", + "custom_name": "", + "delay": "0", + "description": "", + "has_custom": true, + "has_custom_block": true, + "has_custom_callback": false, + "has_custom_join": false, + "id": "e07929c3-d5ce-44c1-b08d-3b4fede3bc59", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 237, + "line_start": 205, + "message": "Configuring now", + "name": "detonate file", + "notes": "", + "number": 1, + "order": 8, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 1400, + "y": 180 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "detonate_file_1", + "required_params": { + "vault_id": true + }, + "reviewer": "", + "showNumber": false, + "show_number": false, + "size": { + "height": 112, + "width": 168 + }, + "state": "asset", + "status": "", + "title": "Investigate", + "type": "coa.Action", + "warn": false, + "z": 1351 + }, + { + "active": false, + "angle": 0, + "attrs": { + ".background": { + "fill": "#000000", + "stroke": "#5C6773", + "transform": "rotate(45 30 70)" + }, + ".border": { + "stroke": "#5094D4", + "transform": "rotate(45 30 70)" + }, + ".inPorts>.port-0>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".number": { + "text": 3 + }, + ".outPorts>.port-0": { + "port": { + "id": "out-1", + "type": "out" + }, + "ref-x": 83, + "ref-y": 40 + }, + ".outPorts>.port-0>.port-body": { + "port": { + "id": "out-1", + "type": "out" + } + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.notes": { + "display": "block" + }, + "g.notes image": { + "opacity": 1 + } + }, + "block_code": "def filter_3(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('filter_3() called')\n\n # collect filtered artifact ids for 'if' condition 1\n matched_artifacts_1, matched_results_1 = phantom.condition(\n container=container,\n action_results=results,\n conditions=[\n [\"get_file_2:action_result.data.*.vault_id\", \"!=\", \"\"],\n ],\n name=\"filter_3:condition_1\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_1 or matched_results_1:\n detonate_file_1(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n\n return", + "callback_code": "", + "callback_start": 1, + "callsback": false, + "connected_to_start": true, + "connection_name": "get file", + "connection_type": "action", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "description": "", + "hasElse": false, + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "93d4e099-5891-4c2b-b6db-ac512e981f06", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 255, + "line_start": 237, + "name": "filter", + "notes": "", + "number": 3, + "order": 9, + "outPorts": [ + "out-1" + ], + "outputs": [ + { + "conditions": [ + { + "comparison": "!=", + "data_type": "", + "param": "get_file_2:action_result.data.*.vault_id", + "value": "" + } + ], + "display": "If", + "logic": "and", + "type": "if" + } + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 1260, + "y": 180 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "filter_3", + "show_number": true, + "size": { + "height": 82, + "width": 82 + }, + "state": "filter", + "status": "", + "type": "coa.Filter", + "warn": false, + "z": 1352 + }, + { + "action": "file reputation", + "action_type": "investigate", + "active": false, + "active_keys": {}, + "active_values": { + "hash": "artifact:*.cef.fileHash" + }, + "angle": 0, + "app": "", + "approver": "", + "assets": [ + { + "action": "", + "active": true, + "app_name": "", + "app_version": "", + "appid": "", + "config_type": "asset", + "fields": { + "hash": "artifact:*.cef.fileHash" + }, + "has_app": true, + "id": "-", + "loaded": false, + "missing": false, + "name": "reversinglabs", + "output": [ + { + "contains": [ + "hash", + "sha256", + "sha1", + "md5" + ], + "data_path": "action_result.parameter.hash", + "data_type": "string" + }, + { + "data_path": "action_result.message", + "data_type": "string" + }, + { + "data_path": "action_result.status", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.status", + "data_type": "string" + }, + { + "contains": [ + "sha1" + ], + "data_path": "action_result.data.*.sha1", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.first_seen_on", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.last_scanned_on", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.last_seen_on", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.single_scan", + "data_type": "boolean" + }, + { + "data_path": "action_result.data.*.first_scanned_on", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sample_type", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sample_size", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.xref.*.scanner_match", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.xref.*.scanner_count", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.xref.*.results.*.result", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.xref.*.results.*.scanner", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.xref.*.scanned_on", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.xref.*.scanners.*.timestamp", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.xref.*.scanners.*.version", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.xref.*.scanners.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sha384", + "data_type": "string" + }, + { + "contains": [ + "sha256" + ], + "data_path": "action_result.data.*.sha256", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sha512", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.ripemd160", + "data_type": "string" + }, + { + "contains": [ + "md5" + ], + "data_path": "action_result.data.*.md5", + "data_type": "string" + }, + { + "data_path": "action_result.summary.positives", + "data_type": "numeric" + }, + { + "data_path": "action_result.summary.total_scans", + "data_type": "numeric" + }, + { + "data_path": "summary.total_positives", + "data_type": "numeric" + }, + { + "data_path": "summary.total_objects", + "data_type": "numeric" + }, + { + "data_path": "summary.total_objects_successful", + "data_type": "numeric" + } + ], + "product_name": "", + "product_vendor": "", + "type": "reputation" + } + ], + "attrs": { + ".action": { + "text": "file reputation" + }, + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".border": { + "stroke": "#5094D4" + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".message": { + "fill": "#FFFFFF", + "font-size": 12, + "font-weight": 300, + "opacity": 0, + "ref": ".background", + "ref-x": 5, + "ref-y": 105, + "text": "Configuring now" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "text": "Investigate" + }, + "g.approver image": { + "opacity": 1 + }, + "g.code image": { + "opacity": 1, + "xlink:href": "/inc/coa/img/block_icon_code_dark_on.svg" + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_investigate.svg" + }, + "g.notes": { + "display": "block" + }, + "g.notes image": { + "opacity": 1 + }, + "g.timer image": { + "opacity": 1 + }, + "rect.warn-background": { + "fill": "#5094D4" + }, + "text.icon": { + "fill": "#5094D4" + } + }, + "block_code": "# read-only block view not available", + "callback_code": "", + "callback_start": 1, + "callsback": true, + "color": "#654796", + "connected_to_start": true, + "connection_name": "hunt file", + "connection_type": "action", + "custom_callback": "", + "custom_code": "def file_reputation_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None):\n \n assets = get_specific_assets(\"file reputation\", [\"TitaniumCloud\"])\n \n if (not assets):\n phantom.debug(\"ReversingLabs/TitaniumCloud::file reputation not found returning.\")\n\n # collect data for 'file_reputation_1' call\n container_data = phantom.collect2(container=container, datapath=['filtered-artifact:*.cef.fileHash', 'filtered-artifact:*.id'], filter_artifacts=filtered_artifacts)\n \n phantom.debug(container_data)\n\n parameters = []\n \n # build parameters list for 'file_reputation_1' call\n for container_item in container_data:\n if container_item[0]:\n parameters.append({\n 'hash': container_item[0],\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': container_item[1]},\n })\n\n if parameters:\n phantom.act(\"file reputation\", parameters=parameters, assets=assets, name=\"file_reputation_1\", callback=filter_2) \n else:\n phantom.error(\"'file_reputation_1' will not be executed due to lack of parameters\")\n \n return", + "custom_join": "", + "custom_name": "", + "delay": "0", + "description": "", + "has_custom": true, + "has_custom_block": true, + "has_custom_callback": false, + "has_custom_join": false, + "id": "5578c85f-4a27-401e-be14-7793e82b92c5", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 285, + "line_start": 255, + "message": "Configuring now", + "name": "file reputation", + "notes": "", + "number": 1, + "order": 10, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 640, + "y": 180 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "file_reputation_1", + "required_params": { + "hash": true + }, + "reviewer": "", + "showNumber": false, + "show_number": false, + "size": { + "height": 112, + "width": 168 + }, + "state": "asset", + "status": "", + "title": "Investigate", + "type": "coa.Action", + "warn": false, + "z": 1353 + }, + { + "action": "run query", + "action_type": "investigate", + "active": false, + "active_keys": {}, + "active_values": { + "display": "adsf", + "query": "dfaf" + }, + "angle": 0, + "app": "", + "approver": "", + "assets": [ + { + "action": "", + "active": true, + "app_name": "", + "app_version": "", + "appid": "", + "config_type": "asset", + "fields": { + "display": "adsf", + "query": "dfaf" + }, + "has_app": true, + "id": "-", + "loaded": false, + "missing": false, + "name": "splunk_entr", + "output": [ + { + "column_name": "Host", + "column_order": "0", + "contains": [ + "host name" + ], + "data_path": "action_result.data.*.host", + "data_type": "string" + }, + { + "column_name": "Time", + "column_order": "1", + "contains": [], + "data_path": "action_result.data.*._time", + "data_type": "string" + }, + { + "column_name": "Raw", + "column_order": "2", + "contains": [], + "data_path": "action_result.data.*._raw", + "data_type": "string" + }, + { + "data_path": "action_result.data.*._cd", + "data_type": "string" + }, + { + "data_path": "action_result.data.*._si", + "data_type": "string" + }, + { + "data_path": "action_result.data.*._bkt", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.index", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.source", + "data_type": "string" + }, + { + "data_path": "action_result.data.*._serial", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.linecount", + "data_type": "string" + }, + { + "data_path": "action_result.data.*._indextime", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sourcetype", + "data_type": "string" + }, + { + "data_path": "action_result.data.*._sourcetype", + "data_type": "string" + }, + { + "contains": [ + "host name" + ], + "data_path": "action_result.data.*.splunk_server", + "data_type": "string" + }, + { + "data_path": "action_result.status", + "data_type": "string" + }, + { + "data_path": "action_result.message", + "data_type": "string" + }, + { + "data_path": "action_result.summary.total_events", + "data_type": "numeric" + }, + { + "contains": [ + "splunk query" + ], + "data_path": "action_result.parameter.query", + "data_type": "string" + }, + { + "data_path": "action_result.parameter.display", + "data_type": "string" + }, + { + "data_path": "summary.total_objects", + "data_type": "numeric" + }, + { + "data_path": "summary.total_objects_successful", + "data_type": "numeric" + } + ], + "product_name": "", + "product_vendor": "", + "type": "siem" + } + ], + "attrs": { + ".action": { + "text": "run query" + }, + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".border": { + "stroke": "#5094D4" + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".message": { + "fill": "#FFFFFF", + "font-size": 12, + "font-weight": 300, + "opacity": 0, + "ref": ".background", + "ref-x": 5, + "ref-y": 105, + "text": "Configuring now" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "text": "Investigate" + }, + "g.approver image": { + "opacity": 1 + }, + "g.code image": { + "opacity": 1, + "xlink:href": "/inc/coa/img/block_icon_code_dark_on.svg" + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_investigate.svg" + }, + "g.notes": { + "display": "block" + }, + "g.notes image": { + "opacity": 1 + }, + "g.timer image": { + "opacity": 1 + }, + "rect.warn-background": { + "fill": "#5094D4" + }, + "text.icon": { + "fill": "#5094D4" + } + }, + "block_code": "# read-only block view not available", + "callback_code": "", + "callback_start": 1, + "callsback": true, + "color": "#654796", + "connected_to_start": true, + "connection_name": "", + "connection_type": "", + "custom_callback": "", + "custom_code": "def run_query_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None):\n\n assets = get_specific_assets(\"run query\", [\"Splunk Enterprise\", \"Carbon Black\"])\n \n if (not assets):\n phantom.debug(\"Did not find any asset configured, supporting run query\")\n return\n \n container_data_src = phantom.collect2(container=container, datapath=['artifact:*.cef.sourceAddress', 'artifact:*.id'])\n container_data_dst = phantom.collect2(container=container, datapath=['artifact:*.cef.destinationAddress', 'artifact:*.id'])\n\n parameters = []\n \n # build parameters list for 'run_query_1' call\n \n phantom.debug(\"Got the following assets:\")\n phantom.debug(','.join([x for x in assets]))\n \n for container_item in container_data_src:\n if container_item[0]:\n parameters.append({\n 'query': container_item[0],\n 'display': \"\",\n 'type': \"process\",\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': container_item[1]},\n })\n \n for container_item in container_data_dst:\n if container_item[0]:\n parameters.append({\n 'query': container_item[0],\n 'display': \"\",\n 'type': \"process\",\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': container_item[1]},\n })\n \n if (parameters):\n phantom.act(\"run query\", parameters=parameters, assets=assets, name=\"run_query_1\")\n else:\n phantom.error(\"'run_query_1' will not be executed due to lack of parameters\")\n \n return", + "custom_join": "", + "custom_name": "", + "delay": "0", + "description": "", + "has_custom": true, + "has_custom_block": true, + "has_custom_callback": false, + "has_custom_join": false, + "id": "8c6c1d82-e40b-4f58-b6c0-cc8c40791cae", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 330, + "line_start": 285, + "message": "Configuring now", + "name": "run query", + "notes": "", + "number": 1, + "order": 11, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 260, + "y": 320 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "run_query_1", + "required_params": { + "query": true + }, + "reviewer": "", + "showNumber": false, + "show_number": false, + "size": { + "height": 112, + "width": 168 + }, + "state": "asset", + "status": "", + "title": "Investigate", + "type": "coa.Action", + "warn": false, + "z": 1355 + }, + { + "action": "hunt file", + "action_type": "investigate", + "active": false, + "active_keys": {}, + "active_values": { + "hash": "artifact:*.cef.fileHash", + "range": "", + "type": "" + }, + "angle": 0, + "app": "", + "approver": "", + "assets": [ + { + "action": "", + "active": true, + "app_name": "", + "app_version": "", + "appid": "", + "config_type": "asset", + "fields": { + "hash": "artifact:*.cef.fileHash", + "range": "", + "type": "" + }, + "has_app": true, + "id": "-", + "loaded": false, + "missing": false, + "name": "carbonblack", + "output": [ + { + "data_path": "action_result.status", + "data_type": "string" + }, + { + "contains": [ + "hash", + "md5" + ], + "data_path": "action_result.parameter.hash", + "data_type": "string" + }, + { + "contains": [ + "carbon black query type" + ], + "data_path": "action_result.parameter.type", + "data_type": "string" + }, + { + "data_path": "action_result.parameter.range", + "data_type": "string" + }, + { + "data_path": "action_result.message", + "data_type": "string" + }, + { + "data_path": "action_result.summary.device_count", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.terms", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.total_results", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.facets.parent_name.*.ratio", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.facets.parent_name.*.percent", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.facets.parent_name.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.facets.parent_name.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.facets.process_name.*.ratio", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.facets.process_name.*.percent", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.facets.process_name.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.facets.process_name.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.facets.group.*.ratio", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.facets.group.*.percent", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.facets.group.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.facets.group.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.facets.path_full.*.ratio", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.facets.path_full.*.percent", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.facets.path_full.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.facets.path_full.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.facets.process_md5.*.ratio", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.facets.process_md5.*.percent", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.facets.process_md5.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.facets.process_md5.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.facets.hostname.*.ratio", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.facets.hostname.*.percent", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.facets.hostname.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.facets.hostname.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.facets.host_type.*.ratio", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.facets.host_type.*.percent", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.facets.host_type.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.facets.host_type.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.facets.hour_of_day.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.facets.hour_of_day.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.facets.start.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.facets.start.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.facets.day_of_week.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.facets.day_of_week.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.facets.username_full.*.ratio", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.facets.username_full.*.percent", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.facets.username_full.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.facets.username_full.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.results.*.modload_count", + "data_type": "numeric" + }, + { + "contains": [ + "carbon black sensor id" + ], + "data_path": "action_result.data.*.process.results.*.sensor_id", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.results.*.process_md5", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.results.*.parent_unique_id", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.results.*.cmdline", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.results.*.filemod_count", + "data_type": "numeric" + }, + { + "contains": [ + "carbon black process id" + ], + "data_path": "action_result.data.*.process.results.*.id", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.results.*.parent_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.results.*.parent_md5", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.results.*.group", + "data_type": "string" + }, + { + "contains": [ + "host name" + ], + "data_path": "action_result.data.*.process.results.*.hostname", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.results.*.last_update", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.results.*.start", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.results.*.netconn_count", + "data_type": "numeric" + }, + { + "contains": [ + "pid" + ], + "data_path": "action_result.data.*.process.results.*.process_pid", + "data_type": "numeric" + }, + { + "contains": [ + "user name" + ], + "data_path": "action_result.data.*.process.results.*.username", + "data_type": "string" + }, + { + "contains": [ + "process name" + ], + "data_path": "action_result.data.*.process.results.*.process_name", + "data_type": "string" + }, + { + "contains": [ + "file path" + ], + "data_path": "action_result.data.*.process.results.*.path", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.results.*.regmod_count", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.results.*.parent_pid", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.results.*.crossproc_count", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.results.*.segment_id", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.results.*.host_type", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.results.*.os_type", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.results.*.childproc_count", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.results.*.unique_id", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.process.elapsed", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.process.start", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.terms", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.total_results", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.highlights.*.ids", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.highlights.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.facets.host_count.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.facets.host_count.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.facets.alliance_score_virustotal.*.name", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.facets.alliance_score_virustotal.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.facets.hostname.*.ratio", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.facets.hostname.*.percent", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.facets.hostname.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.facets.hostname.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.facets.group.*.ratio", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.facets.group.*.percent", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.facets.group.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.facets.group.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.facets.file_version_facet.*.ratio", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.facets.file_version_facet.*.percent", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.facets.file_version_facet.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.facets.file_version_facet.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_result.*.ratio", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_result.*.percent", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_result.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_result.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.facets.company_name_facet.*.ratio", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.facets.company_name_facet.*.percent", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.facets.company_name_facet.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.facets.company_name_facet.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.facets.product_name_facet.*.ratio", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.facets.product_name_facet.*.percent", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.facets.product_name_facet.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.facets.product_name_facet.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.facets.server_added_timestamp.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.facets.server_added_timestamp.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_sign_time.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_sign_time.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.facets.observed_filename_facet.*.ratio", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.facets.observed_filename_facet.*.percent", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.facets.observed_filename_facet.*.name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.facets.observed_filename_facet.*.value", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.results.*.host_count", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.results.*.digsig_result", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.results.*.observed_filename", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.results.*.product_version", + "data_type": "string" + }, + { + "column_name": "Signed", + "column_order": 1, + "data_path": "action_result.data.*.binary.results.*.signed", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.results.*.is_executable_image", + "data_type": "boolean" + }, + { + "data_path": "action_result.data.*.binary.results.*.orig_mod_len", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.results.*.is_64bit", + "data_type": "boolean" + }, + { + "data_path": "action_result.data.*.binary.results.*.group", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.results.*.file_version", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.results.*.company_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.results.*.internal_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.results.*.product_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.results.*.digsig_result_code", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.results.*.timestamp", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.results.*.copied_mod_len", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.results.*.server_added_timestamp", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.results.*.md5", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.results.*.endpoint", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.results.*.watchlists.*.wid", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.results.*.watchlists.*.value", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.results.*.legal_copyright", + "data_type": "string" + }, + { + "contains": [ + "file name" + ], + "data_path": "action_result.data.*.binary.results.*.original_filename", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.results.*.cb_version", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.results.*.os_type", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.results.*.file_desc", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.results.*.last_seen", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.binary.elapsed", + "data_type": "numeric" + }, + { + "data_path": "action_result.data.*.binary.start", + "data_type": "numeric" + }, + { + "data_path": "summary.total_objects", + "data_type": "numeric" + }, + { + "data_path": "summary.total_objects_successful", + "data_type": "numeric" + } + ], + "product_name": "", + "product_vendor": "", + "type": "endpoint" + } + ], + "attrs": { + ".action": { + "text": "hunt file" + }, + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".border": { + "stroke": "#5094D4" + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".message": { + "fill": "#FFFFFF", + "font-size": 12, + "font-weight": 300, + "opacity": 0, + "ref": ".background", + "ref-x": 5, + "ref-y": 105, + "text": "Configuring now" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "text": "Investigate" + }, + "g.approver image": { + "opacity": 1 + }, + "g.code image": { + "opacity": 1, + "xlink:href": "/inc/coa/img/block_icon_code_dark_on.svg" + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_investigate.svg" + }, + "g.notes": { + "display": "block" + }, + "g.notes image": { + "opacity": 1 + }, + "g.timer image": { + "opacity": 1 + }, + "rect.warn-background": { + "fill": "#5094D4" + }, + "text.icon": { + "fill": "#5094D4" + } + }, + "block_code": "# read-only block view not available", + "callback_code": "", + "callback_start": 1, + "callsback": true, + "color": "#654796", + "connected_to_start": true, + "connection_name": "", + "connection_type": "", + "custom_callback": "", + "custom_code": "def hunt_file_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None):\n\n assets = get_specific_assets(\"hunt file\", [\"Carbon Black\"])\n \n if (not assets):\n phantom.debug(\"Carbon Black::hunt file not found returning.\")\n \n # collect data for 'hunt_file_1' call\n container_data = phantom.collect2(container=container, datapath=['artifact:*.cef.fileHash', 'artifact:*.id'])\n\n parameters = []\n \n # build parameters list for 'hunt_file_1' call\n for container_item in container_data:\n if container_item[0]:\n parameters.append({\n 'hash': container_item[0],\n 'range': \"\",\n 'type': \"binary\",\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': container_item[1]},\n })\n\n if parameters:\n phantom.act(\"hunt file\", parameters=parameters, assets=assets, name=\"hunt_file_1\", callback=filter_4) \n else:\n phantom.error(\"'hunt_file_1' will not be executed due to lack of parameters\")\n \n return", + "custom_join": "", + "custom_name": "", + "delay": "0", + "description": "", + "has_custom": true, + "has_custom_block": true, + "has_custom_callback": false, + "has_custom_join": false, + "id": "ed123d2f-999b-4cdc-b141-a48f7da89227", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 360, + "line_start": 330, + "message": "Configuring now", + "name": "hunt file", + "notes": "", + "number": 1, + "order": 12, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 260, + "y": 180 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "hunt_file_1", + "required_params": { + "hash": true + }, + "reviewer": "", + "showNumber": false, + "show_number": false, + "size": { + "height": 112, + "width": 168 + }, + "state": "asset", + "status": "", + "title": "Investigate", + "type": "coa.Action", + "warn": false, + "z": 1356 + }, + { + "action": "hunt domain", + "action_type": "investigate", + "active": false, + "active_keys": {}, + "active_values": { + "count_only": "True", + "domain": "artifact:*.cef.destinationDnsDomain" + }, + "angle": 0, + "app": "", + "approver": "", + "assets": [ + { + "action": "", + "active": true, + "app_name": "", + "app_version": "", + "appid": "", + "config_type": "asset", + "fields": { + "count_only": "True", + "domain": "artifact:*.cef.destinationDnsDomain" + }, + "has_app": true, + "id": "-", + "loaded": false, + "missing": false, + "name": "falconhostapi", + "output": [ + { + "data_path": "action_result.message", + "data_type": "string" + }, + { + "column_name": "Falcon Device ID", + "column_order": 0, + "contains": [ + "falcon device id" + ], + "data_path": "action_result.data.*.device_id", + "data_type": "string" + }, + { + "data_path": "action_result.status", + "data_type": "string" + }, + { + "contains": [ + "domain" + ], + "data_path": "action_result.parameter.domain", + "data_type": "string" + }, + { + "data_path": "action_result.parameter.count_only", + "data_type": "boolean" + }, + { + "data_path": "action_result.summary.device_count", + "data_type": "numeric" + } + ], + "product_name": "", + "product_vendor": "", + "type": "endpoint" + } + ], + "attrs": { + ".action": { + "text": "hunt domain" + }, + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".border": { + "stroke": "#5094D4" + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".message": { + "fill": "#FFFFFF", + "font-size": 12, + "font-weight": 300, + "opacity": 0, + "ref": ".background", + "ref-x": 5, + "ref-y": 105, + "text": "Configuring now" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "text": "Investigate" + }, + "g.approver image": { + "opacity": 1 + }, + "g.code image": { + "opacity": 1, + "xlink:href": "/inc/coa/img/block_icon_code_dark_on.svg" + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_investigate.svg" + }, + "g.notes": { + "display": "block" + }, + "g.notes image": { + "opacity": 1 + }, + "g.timer image": { + "opacity": 1 + }, + "rect.warn-background": { + "fill": "#5094D4" + }, + "text.icon": { + "fill": "#5094D4" + } + }, + "block_code": "# read-only block view not available", + "callback_code": "", + "callback_start": 1, + "callsback": true, + "color": "#654796", + "connected_to_start": true, + "connection_name": "", + "connection_type": "", + "custom_callback": "", + "custom_code": "def hunt_domain_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None):\n\n assets = get_specific_assets(\"hunt domain\", [\"Falcon Host API\"])\n \n if (not assets):\n phantom.debug(\"hunt domain/Falcon Host API not found returning.\")\n\n # collect data for 'hunt_domain_1' call\n container_data = phantom.collect2(container=container, datapath=['artifact:*.cef.destinationDnsDomain', 'artifact:*.id'])\n\n parameters = []\n \n # build parameters list for 'hunt_domain_1' call\n for container_item in container_data:\n if container_item[0]:\n parameters.append({\n 'domain': container_item[0],\n 'count_only': True,\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': container_item[1]},\n })\n\n if parameters:\n phantom.act(\"hunt domain\", parameters=parameters, assets=assets, callback=filter_1, name=\"hunt_domain_1\") \n else:\n phantom.error(\"'hunt_domain_1' will not be executed due to lack of parameters\")\n \n return", + "custom_join": "", + "custom_name": "", + "delay": "0", + "description": "", + "has_custom": true, + "has_custom_block": true, + "has_custom_callback": false, + "has_custom_join": false, + "id": "2c95ee18-c36d-40b4-9a1d-889badec9d4f", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 179, + "line_start": 150, + "message": "Configuring now", + "name": "hunt domain", + "notes": "", + "number": 1, + "order": 6, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 260, + "y": 40 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "hunt_domain_1", + "required_params": { + "domain": true + }, + "reviewer": "", + "showNumber": false, + "show_number": false, + "size": { + "height": 112, + "width": 168 + }, + "state": "asset", + "status": "", + "title": "Investigate", + "type": "coa.Action", + "warn": false, + "z": 1357 + }, + { + "active": false, + "angle": 0, + "attrs": { + ".background": { + "fill": "#000000", + "stroke": "#5C6773", + "transform": "rotate(45 30 70)" + }, + ".border": { + "stroke": "#5094D4", + "transform": "rotate(45 30 70)" + }, + ".inPorts>.port-0>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".number": { + "text": 1 + }, + ".outPorts>.port-0": { + "port": { + "id": "out-1", + "type": "out" + }, + "ref-x": 83, + "ref-y": 40 + }, + ".outPorts>.port-0>.port-body": { + "port": { + "id": "out-1", + "type": "out" + } + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.notes": { + "display": "block" + }, + "g.notes image": { + "opacity": 1 + } + }, + "block_code": "def filter_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('filter_1() called')\n\n # collect filtered artifact ids for 'if' condition 1\n matched_artifacts_1, matched_results_1 = phantom.condition(\n container=container,\n action_results=results,\n conditions=[\n [\"hunt_domain_1:action_result.summary.device_count\", \">\", 0],\n [\"artifact:*.cef.destinationDnsDomain\", \"==\", \"hunt_domain_1:action_result.parameter.domain\"],\n ],\n logical_operator='and',\n name=\"filter_1:condition_1\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_1 or matched_results_1:\n get_system_info_1(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n\n return", + "callback_code": "", + "callback_start": 1, + "callsback": false, + "connected_to_start": false, + "connection_name": "hunt domain", + "connection_type": "action", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "description": "", + "hasElse": false, + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "8656f57d-779a-4133-a244-5191a6714a83", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 84, + "line_start": 64, + "name": "filter", + "notes": "", + "number": 1, + "order": 2, + "outPorts": [ + "out-1" + ], + "outputs": [ + { + "conditions": [ + { + "comparison": ">", + "data_type": "", + "param": "hunt_domain_1:action_result.summary.device_count", + "value": "0" + }, + { + "comparison": "==", + "data_type": "", + "param": "artifact:*.cef.destinationDnsDomain", + "value": "hunt_domain_1:action_result.parameter.domain" + } + ], + "display": "If", + "logic": "and", + "type": "if" + } + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 500, + "y": 40 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "filter_1", + "show_number": true, + "size": { + "height": 82, + "width": 82 + }, + "state": "filter", + "status": "", + "type": "coa.Filter", + "warn": false, + "z": 1358 + } + ] + }, + "notes": "" + }, + "python_version": "3", + "schema": 4, + "version": "4.10.0.40961" + }, + "create_time": "2021-01-21T18:16:11.375283+00:00", + "draft_mode": false, + "labels": [ + "events" + ], + "tags": [], + "misc": { + "apps_list": [ + "Splunk", + "Carbon Black Response", + "Falcon Host API", + "ReversingLabs", + "Threat Grid" + ] + } +} \ No newline at end of file diff --git a/playbooks/hunting.png b/playbooks/hunting.png new file mode 100644 index 0000000000000000000000000000000000000000..a79631f02b5ca0f8d1ea58f71d8447af747e180b GIT binary patch literal 204044 zcmd42WmH_t);5ZhK!5}S1h)`^CrAhm!JXhva2j_Sw;%z6CTNfZcXx;2?(S}lYtwKS z`|O?U``!0DXOH*%xjjbrDpswUwW@0BGbf+qWyLVi2+`o+;4mb_g%yAcDI6T)&I1(S zj-1>N4mh|+1|T6Jc?lsQa(O#zV~~Xr9Gv*4ud1k8(PBhR&W2IN2u~uOoMRi|2#7wQ z_w|+*RCW{6{EV^p&2OySt)Y5~DmgVqhN_Us^Z&R?sqwY7vD~^Oyr(AoJ+zSPRZ!HZ@t9q067AHk{lk7L8f~ z?lhDf6EEoMT~IUy>3g-eBA+(}_mK9D9v}F|CBcwQAd8n}ftOb|a}@dA<^o;I*#7z6 z{Hu2i{dX~~2s8go;E)GAqywutfuN3vi;!td>*tnT=w9SJSB|j$AB6=&d_iR1= z%xlIZZ=(l;!_jx9;O9Znw-2JqK(;N>@Nf!y9)$M(hnPkw|LBY?usk7)sEgnkBWYYD z7O9Zd1APJbn*!oEYLep^G*ZFOYh(+^uO<+t#tiPpY*SyThUgXbSRKVr5bwzB&M+nAT8E8QwH82F$ai46^`2KK$h;Xt&i<~VI@5lS^7%U(BIRoNW4=5WC@Iuz-zaC+*DCP^UrFypNU zui~W0q)Cv7_Av8q+9!6m?A*EUkwq~3rtGrE=dX1&^+SsNra*g0PI%nD>GNrWm}0YC?Vs*r+Srfjm)Om#gL;x%4?UMfL}Fcc~HRv(H=I3?>52DG<_(;C;kKsGK!4Z!}TAr(! zyw)1Ddxg=5a3V;M4cFU3SWIexGTY2lj86>rdFjDhcu$ng7HS)exq#g)93Dj8CH5_$ z#~(iqJweeAR--r%qF?z`9Qoln!Y2{zNQdX>-6H8h*zx`h0(22yyIc+F6+&*jiA80} zO(HSZ@a)L8-`&1jNP8wJ^jRK#44%Zl^gSk_--|SyVJ!zb4PPeV*dNNK7`3RD0&=OF z!{*s&9s%e2aHB18aqJrbC9j$A!i_#~#t|p_eKq*1hM^M9-sW|Umf2cc;{5iB$r8gH zM&Yt44>JCe;t}U1wmWYlx^?sHA^oLCJ?fosDo)?S!jEtW;jfY-q~b(hQYm3OJ;r<@ z+cG~U0hW1=9WN~QgKX~e_D`M_=@sl1(G@;@^b)_zh$$(`NNI_}baDlrPjYmWUn3_X z&m+R3nWDKQth>1k=}T!iqrM5oL`ijjU7KGsSnFM*S>p@lYfr`&_>}d4mi1-t%URm~ zFCkxKCCSFUcf>J%yih#JKFLuYbKRlcA=!~4At50m@k+Ag!cKDGQs#m>4s6X$x`?r+ z*9=vcOD9BCeyNO}cvmOlCXqEtvi1G+k?Ru=+J+dK8SnB7-{NX&e$o!bJ)PsS6?vRvy8PetfDaMf_q-8h6FF7%&~g0G~j?dcp54*naaU zCK${IYJOJvh)Jkft$AwTZTl7*B_Su_QRs0fUFbPs1<~0v zB0@K!EJ8Vs!Z&~S#F=4qGu*^Ll6E;+^ zDji%)=yp?#0eu8DZljHgj@B7h$A?V6Edv=R_Q}ROVsQ|XzSVkF?|$jC+?0^E!L;#d zgSEdZUiZ~OMR9phX@q)y*;~-CWq0|bioP-}OP9XV-e5gk3+fULOUJn#=a|w~CpIRACnR?ZCiW*h-h{oOeUtG9Y5|#1u$->stjx32v~=6c-|Lv^FU>21jwkC6 zR^rbVRq$Khb+imq^e<}$iUwwdy$Iv!#O~zke%?C@=EP+g#nV@$GZpHK?zSd=1i@KtMse5s-RTyR0d)(VHU(!?qBA! zL*LVjCXt?X&v!O7d(=TKv4p~3lV*_ilX|(-g3);Lc#B+z8z>t#T-jY34xP^MT&#~9 zx7!X0c25fA@&?6p`E_fo8?0kfl5}GhQJRP>sGJbo9zsL;Tlo9D3h$oWIm0)?i@>8I z+&*$Z@57oSxpXLBH67mCPa{K_MmqAVM9J}0Z&7d2^i`&qpty-hh(P^b`Mq_Bvp z^qqtBY48>i4|=k3P>|2QC>(pTEIi$g*qn*w%< znojqX5Tn_Z*^uLl6X}xdok=?LAsZ}OzA!#1Q0-gcYtkyeY^E3cQoLN@^f}E- z6QhCAxzsu38ts+Gwi(r$tzYwF>$^e*X1`s$;OFx)@$?eZXlZ
C;4m-C%XcjisI zUC${k35%+Fyfi!ehn<8R-s5Lin8-ikvQ6n&d;>4gC27_w;tQ$ zLU6z0lEplT`34Qj@@9e)ZM7F7`0om+dkf)C4O%G9LwQvmAhzB zQlozYWsG9vs1mib%(l(WnG>B;soy_3AKTArGV#)_YqJn*4-4nc;8w1~cCHw|9-n}` zS!~G1EKr|#97-J;%ih5tWvCrJJY+>0HIK! zbqw*g(12u7+q7KThMd*IxVD0RpZ-8k!mH5%stK{&a6&R|r%+dm<&xV~>P|OJL&kX; zJ2@VUq&ZjU+GVurY)3^!N-(G6#%5QFT=K>@KF=3heUWAGCRiy3Dds!}ZjH;ngZ@HI zmp69V^HmMYKNj0FrEX&rxJ8|b>xk{Hettcq=ht1==JjHPXmp-^+2yb{T#%oCy5R1b zw=@x=8{)NJ$9sUeEPJI5tNVJ4AlRrG1rfN^aN3bx>7m` zjdNE$P-S!LcLxoV{zcG*FHP(ob-N_c`RxnPLCUENRNz|vZ1~FHBr8tN`5GMxHFD?l zT6*c-60orbcQ`2vx3vxTimBzK4XHoLTHtX%uOpn#-ADF|R`?_2R8ps%Rjw*zZ&)#B zpWj?@PWVpucet}-LNkr`YhV|%YSY6GA@J9Jq;mlg7|PDSRXpxF_*vmr12xBOa+KKf{oN9jAdlt z=z#VEI3##NIAov&4}AIHiGH<3;a|cb{&61x4lWP`hxF$&vcUEJ69Ihh$NcMx7!?4A z3jBo)e8H&*e?5&snu_>W8*vBdgA-H~l8^wdiUxK@MppKw)((e{3`2n%4{gNN?cw0? zsPDh<5(>``0s2!QB{c^%8EGy9YfC0QLu-8_Ca|T=Jsmh6Fc;9YG;+`*2U}WL*>iz; zDgSta3uxcpW~LFViQJ38=EQr=JW>+`SoGy;Qu&tzr)=dyqWGT-+wzh-*H{EId)l;{2~ zmplk;WT7SuvIO=Fn1hd%mHjQx9|QhBUB9RN*HC49BRe5$OJJk}-|t=jbMW6g|IdMc z%&Go+&eyMAvHX3`zjggNl!y6#?SI>ge{J+1cY&SeL*rrob!vQQA-8d zeyiI~sVHgQlf>!i>0K`8WDESKbgt5-56HdY5dQZ+-csa5EmW~6)=vcB;E^8xZ-1H} zJmy(>_rD$eubF)w!~2R+JeU6Or~ovy5dZi4ale<3DFqH+e*F0GzoQ~>7-at6Y$-7I z9nu3*|A<%c|HZ)oR34DpV*GbZA`k@ElJ*$;#eYWyu7#@bzgx-U2T#bsPv5m7{qGs| z{zS;ZKiU5)p@Bo7KtKwACm#1-Qb7u@Mgc_5hk;T)*Fgb~6B`rp_XhcFAv;+t62n>< zKK*k6r^O}*f1zZ;1F$iq6;#1X=y`o2qh0j%EyN94RW7f;KK z<^CzfPxOGW+79xHg~1`HOMCmos_%WYd;5Fz6J+r1=dL#Cf6Oxa_tO6&)B*`OiY_ob zijMIOXDaG%g4;CBC)U^MWi?m2(TfG4sa+0UYJ|(zX@JH zJiJNtoY;H#@9F&NCAUR>KuQg%+3b2EKpyh&)genrk~}8r@BSZfgH2Cd;{LIu2uK5h z(Ec&<^Sw$VUO82NQTH{ym*vz0V5)GxL-8f|wKF>(}>^SAx^C{M+aV zKLz-j5{va8yDCAS0D^I^N}m8rBws}a4&`XmoAfuq^b~+?woUqzf9s!r-@?9EsVm8D zVZ`uArE!4dl}$ZdxA{Hh|0n9OuVyfrx9;FunppU??BF9Db6o|gFcNOOv2mkbRV0rM zL|}h)?)P`WUTpC9ZYnSV9MIFR_BSK+7jyhR)xWoVz5t2?jq1E7)n}wpdp5O3j_>5# zBM%SoP|ZL+fZh`G{Dg=~f8gz{O9%_+A=~`Tb7Ger*pq^}RF-hZz0d&EH({Keoh^0N#9M zg%sY}YVF!8dNxXP5a(Y4C}0x+XexTS(_pxHvfV9hRnnh zV2Kl)vBVF5@8dDB#23~-vHy)0{3XhN$XL2EAT7@XffxAT{zA1#gY%_Dx$US*O2&!- zb_>-LU$G-w#^g|)SBJ-j*`+dnsa`lAFfJhHI)jg3|8$jIl7Oyk{U-D0OfPjOqX1eYo zFLg)kiE5vByb{m-t7tiGSN5u5)!%IN&POq7z8Sr{Lg$OzwT47lbz;kLw^Aezpm_Xx z71;+rudgnC#<&FjGAIAbYG*AGxjepU$yEB{Q0<-&;#X zQi`lyCvtUf>bl4G6ciI8e4?<~h&Sn(izn;$S@evKu`KNSf=UwGl9rxsr%-1s)BTk@ zR&c)FC4@n{@tvoAs^X}Fn}kuXBn1um$*j+!;b;tFY2UO?I^ID`+Dz;iOJ}+$^xT6Q z+IUSjZE)>$kQ^a2pj)lh#m4=8$R9spe`fILG*>UH-sPl=AS=bnR~C4haq-}eVwy=5 zho@&hj`Zq8JQq=^))S(|DFQW3TzG!Y<-xP0<&|SuJKyS$#x=`#YyZ77uM@TzN!4w| zqJkTKyw0m@$Jv=#G;_{1x!|*inYmrBKaO_3cG0%f*?FW&w?RXhR-w8$U$aTjX@7y_ z?AC6*k5-1+oYL#&Do{G*HT}*Ri++o?CP%lr$$Es7s&4Gwv-8j`U9)rb^_3olCLQe@ zrSJ8`SG&y9#kSFXNmb2P(^K&Y{m2E;ylzf8npu@>pfPzS1~mcCn{AruYEVdM%4PD+ z`W}55dqdWjmw0@E#pZ*g)3uJ80rQG0{U`i)oT_h%G!1yrbd)F;YVno5R_MTE_3DZ) z$4%kEC^|PYBSyVO&8ZYWiYi6WMjdu%L~0%P*XnpNUN;;~h!a3=4)9GSnZW5SDcv|7 zGgfh`7_8gsmt*dN$c^p_0@(~`6JdQtHcz(ce!dc@{ zr#h0@@^tf(?dJ7zL$_X%Ly`(3Q*^tOYC5O;%7Rz5xBOY|*NlXdrU09I8N|1FszuS` z<`e!Hs~=~r{EvvxR9(Za5>?};50s{oZG!@AmjFwoLU{TR2HWrI-g=gsxaJ^+{8D( z3`}eFXZ{j4S&qKvy7!Ux7y&6^^- z0oV$4q>#Upruq^41mGUnEoB;i-We&EFt8`ssyJ!&j&0S!-c@1dpb*pkF!%8y{a|!3 zKs$!uH@|JuJl+K&pk2;?;Mk3*F8R?Od#&$>!u-%w$kPb2{W(HHk>w9=`J>^v{Iwr{AM3kUi%{{A7-H)a7Km4 z&7_qbQ4gCSQm72|dTZT1Vl-0FnRMLC+>~zStXkfvr9;XiFU!0BCE|>IZ}Mz{l*N3Y zlj3B>rL~il|I4w2M7Pt?q^=kHRRD)rW71x!x(i@}Uh~xXp`OR)ahJ>=O6^qNa5rwqg{#G=$@St8yTjP(ge;^z+Jnr>ZQ*vCkA3Q^)~EsLCQ{(sczFG+ zq!p283l)Zbh50O<#Zp(DOo2C>(aveA=af->OIpndz639ge1_f+am!kJCidaP$?e{= zff`9G7Yv5awhX7=>4!A{Lu0(YG@RI`6RpCSh{_ZxKE8;6euVPNa*!7y>BDY_R8hrD z{znJl@8-tm8QRp+u=Apqb#8SvM-r77W>%MwAZ-MH(>K?h9ODTZbpEfqR(oqY3^E55 zBb}U^YcZJxGnZi^17COJfQTjwqj+2fSX+uTYZpoT=@_C# zecWA6dUB0I`YMVjQaQ;69nmQAzmCds_ZvRhnJh3kPbCQ0i5-(VTF?PQKs86#Va5&C zjaMpoOd5NkAq&s1l2WQVFqql(vJxB#gYd|^rTbCBPva^Nrk;#BHe{_0dikt1E%`R{ z8jWuB+o^|42=-EspaN{cHM^X9BmIp{{hU)U;GJwczV=3|FLH)`6@Cl;}nY-)l5@a?dAhYO95!4r^VyJ|7}cyzDl6K+e`W?A~dD z#M*=NQL}|^>IYC8Jqqo@-hPs#57NoabdcNapRNAyinuXAE_o+lDE?IHNr%B_q4su_A8N*?M}zM> zNv;OXNv7j9FCi~Ivp5MMnaXy}Lvd(@ORq|&p<%NCJ&t2tMj3663Di=zVoqaI)2fWD zKQHAg2Y5}DmQG>G}p6s(YB{Z64 zkk8_4SDo}vBKwCqadl>#FBs&>H|B2#a^I|*kTHSF&HA}IEt80CS{-M~OCwcWdN$GQ z;tB3<(>5ic-(ll1vo#z_c`DQ2{JijAGZ$eHfgp$wkUH$%8^-48*-?Ge`OCF5wDM8o zzcaSNa1H;D-sVUApci1nNmBj|ZIFCX;ms{nkM@0KebTqgN#RGN4YxDBBOAvm$8F*K zlI?WtQD<%jTl6Ef%2LyJZCDC9W~ctBQS-0RKjIDzh3g~|(xKr8kA4koWKo-`1Tg~M z)EAV`iT?A+&Kt~iu+Z9IZ<*~7rt698SoHZLOBzvidXWc?oFgI4MPOlr? zf(Y#$Cz)}>6084C$xna5;yFver=QMq`%{r(_FQ)8P~t2X9~Ieak0s|J`4#dVB4d%Q&5K@R1#v9cBuQk?UO}L9m!A&e*J_g{k7n}L^NCI3!|7ED(CAnb=}iU% z{2QobS8nEq4f^aj2l+G$E!_OeEf$nyZTr~Xa#`OZTsa(J*G&f%)y{9oPE|^*2H5#1 zn%P|ie?4vq98E&=Ozd~%DvD5SIhZOjVCj))A+yb`AO6dH`UvCP`|m%lZ0mpfQ~z@- z;w=L0L(=tuB+W|8o4%!|wC_c4uQthORV(v}?Qdu6U8ID|%LaNVM40L50`J~3@W0i4 zrJFAPr0gaXD=RpRe=L}Jcf$JBXyeUsZ?hV2Q?M9USfNKs8nN-qD#W&^}XEf5jM0_^9VK+EJK3e6{^qVCl&&I{3#l8tp0kbvjdhgfhij)HT zj#{Q@UC*obIbm-fi&8m!}3km)8 zS zEA)w%eV>3az)oyAniAWaz{V0ElQH1wSZ|#!sdUX62m7)oI0;Jk5Fz4`+=lhm$zjy8 z+lHlmQEZp$WMWpYly1DeCOXikND0BEr(;htuaw>%+2G4IC~@379!?WO>@}`Sl^-_n zks~-YhU9M#$mCiKEu=AuY~W`OCu-H@6`{{0L;V)k*!I$!BIf!@N3x4lNiUIH82oX=h@|@o_|3&CS z2$^7@`+ean-A(2DYNmX1v@cXbtQ_EsiTb9e2qn>U0U6Z~?dj{k6^jz18S{{prCFDCAJzJR2!Sa7-Xg%ju5m|{QJ0>dR= z$LS_yiF?s5u`j`%M|w37)OiIGFgP9qZS;1*Vn#vNB8ymjH*xX%n4}GSH;gXMKW#XH zgn*yQ_+blT12ibi`rMrBgI7Kd<#0rB707!j8S2(OcENu-5Vgy#L(hEfHbLu9tWwLh zTEYHYxmds_wIqt`#e3-Z#kPsiL^xZEO1;ZnTX;H@#5qvA+%`?h=yaA!`c+ye-oab& zE7NITWb`i7=*4IR6~<1Jjk}WxPXW`vMkU?Dc@_fVF1GI#<%I5)^|Ak$J*h+`tCoW_o;Y1K-9ejD z)y=L3vR{vE4tM%x&SG&bzz&z&6zZj2;@Lbyx2EI{-T)?vdUAeB;?@R10b*QqGGBKg zJ|ECx5Ha67eX+UOZP4iMxu~l9DLKtXrpeoDEwPA(NZzi;Mh@b$`oN2~h&oZ9 z48-D7lia>HCBe-yR?U;XbXZC@S>&)quq32Afv9fo#%-NXIy|ZwIIW#7cFLF*E;j&2 zqmyQw-x`Idxhq7SoUm~H6xcL}%L%c!K0)8p)~boBXSt-NRXL^9X3O3loU~_t6tQgm z`PJwuCEzQ9#N4uQfk|A_jhWwFutesPOt0UZ=g`i*U<|`D3kSp>3@xuD>r9uT&9j|j!le5Am)gpnp$yK9SJ3Wyr_bK$?xX0Z3iYZo^ro(k9gWDzz zYd!%pYz(l0+0T`8v5%Yc7Tq83E=BS^x;Z@=v=eM}kF0%e&>`~*tG-s=6)F4_D||;e zPk1j{#Wq*F>H7i8_2YEq6iRlOpETKoWytyWcBVo4zoaZe`99K3RMvWn`3vOzODO*y z<=)?GrvHFQkk%3Ub-{!5Yyk7hq7&xn6HiIG|o0-bv@ZbcAp(>vl_==yaA`{LJE)x93J0x$Rrv< z!;T?Ihd*wl_Z| z><$nc=JQZ|#cIO}i{Rlsnp&ot0-l(SXOpV&&$JRcp*9>esY3Q$RLR8+vfOmfq{baX z(@>BS*sO8c>KYZlo1WHDef|`-t_AsMb=tck^_1Q?-$AbcqWE3%EY&6ggH#5(Bm|nx ztjHluQ_ggF^ux2H4yCCaZ8!l}N;ogwwAtWnX3%i9($a21-6U~GOaoaWF(8p`Yt^c* z(#kHTcNx&mM=eUj0)CYTjZoPM&drr<){b(8473fdk?lICgBa1+iU&EyX{+;&pMvp|xf)lpzXU(%^J1+T11`3H#nP(! z1|hwCI#^tF9$D$sy-1@B@U)<0Ia)bCOt)lbZ;(^s5FR?M4{$8L9ON6HRNA~6^tv_h zYUM8$3pP3yPDlQ zFA8d@r?ETZxe2R7OUC1b6@GNqAaVPZ>S3QNsiYn&u8u2TcbB9-k)&odBaEOO7$uXh zn8vz3WN(`SH|VK;t6TKiQKMXl&I3;%)>th#U9HmL*uY_3VoxDHsF2@>|%Gz5b?-7VS#WVp@wpu|$YL+RT2)QXfc$4Q^MI@8mQ5VK7 zy$T73s3M9`OX0D8jhZ{zgB~Q6M$VMyMpUl(ig{8{mI3zD`tD}J78M+o_hSw7!1Po1 zlkSfmTH3ax`F0ZFn%u}QYA)6>NIxgN5;=#!=!)|f6WtCVq}i!!6~~&5wrSS`h(boJ zQe<2xkGS4{>af1bf5QmG5&LAARx~n2R&(XkHx%!4l_YXDzfd`lNEVFv(59cZ$;*uJU(}?Kof?2-aLWWG~P3X6HRG zkHi#n*`Rkuu?YiY%r3{@Hj^zEaCp!t^br13FVBPSGc`CLKezp-+`13aQ*nvIY~|jK z7a}y5$ezh0BwkD4Cgn?{Q6RpA{`-!DIGrkq3rk*OO0g_`i80V_JM){@X#pr z9JvPo>a06@*P|$~#px$LG-LQ?;wwm~V>VPBpJb$CIV3XKu$(#YLl4WDh|@ie&3a-? zdgO7CTVny(F!o?i2_>H0EevLwyPvH)PKTekI6lgdM&O0Yam=&H^`lFN1ds)j3lYe?s zppd4==)60TQFiLsahUf>_whgy#*p`zM+2!t5!1!Iebs600V!*NZCOmI(Qak4J8!HE zu-JD}Z3|%5SGhtae)~!={=ZrviVH6;rz^`d46tEaTaqjNTqJX*iYVIP2csP1h@0FQKMQd=kfvRw$GLFd+-Y@obtS9*<`kXeMX`Q_L#i%BBGU8)X0G8&g>WN5fza`EXYsy76D4OJBOTArQoS|V389`>A2g{6t# zy)ErufbN@I8ZL4YmxTUBM$Hq6DV$vdcSd+lj(T&}CZDb&=b z)g)bSR=_2wEhBNb1vtlvt+;|jHhfyc*LDQwJCAWNi+x^dXNDC7ezAeT9m)qDxmDB)e)c>cwZm z9w5v~%w<}*x_0S5rdCK5@N~It_hB*ZqW2NG0Zamg88p)|lj|#rRk=d2ZkYjHg*9&8 z!~-;|DGP5;TQ>mzx>3P*vsftpdeBN62VQWwi%c&yk_n>9(NfRZ{J4F3J(4+IW3}z+ zHl~@#3q#D=QkvyjdAcx^8l2pQ#h1V|TXpbsK0KhK96O@YW>R#FyVo0e-;ww9Z25SN zb@1w3Alz%n`}T!H`lJaEi?SL-&Z9Gb)Ng zqTX}sW6$Lhbz9&MZYe!5 z@p&Y7VY~4(DG^LbR>5k@{Q>z7a}@<|Gro(%2qsjxaunoKhe-ni;`tU!+CMVyvez?s z`ijj6VjzOfNO-#!G6kQ>MC@S2)J-RbxM`%ruQ}D&v`}d>(!K|vE1}HwiaD7)>22oy z=wXeD>OLjp(%EzLqb(lixQ%9?MPYiJjP#l|W*Tnr8a@}-;jG}W=YcaF@j9%kHc|z# zCyD-Y<{ZUsuCt(XSGA#Q_i;bhGEe>N$RNaMzJ;R62$oqh=}bn}Ld9P&B^z?qEakjp zd;#HAsM5n(#GD=Z;Zx7&a45!w7aT59eNQ+h#?8mRO_V(>h%^GwA%-)MgA;=YyHG(EBR;b;Y|SJgAu%qnEV-FWKD~2a=iutoFvnts|9Wb{7u_ zYQC>JQtX-)iz2?E1p(S+*EDEnWheIIH)yi+{Br1Q=)q=Ln&Y&AsUM*EX5`ccFf$8HZwj@k0cV9q zV>$0W!@KXRqQeaY)Y27idC6RhAbUtLn4GI$sg#dOXD7{crf99#=Pmm-nN}yi?7u?m-?dU9XE5sq4F`$AvEFfT$LEJ zak`L3=PFYmI&o)%C$5`!mmSJF>8G)}KKT~Ro%gMWd*;W(?Wz5#NpalpdMFoA9uv=V zMzu&MTg%IP+wpk^wN(}JA#6ZS=I)1jCkcujYKcS20$y*h7{ucV&#`3Ztv!$|sPz+D zkmQFf%nCOoO{BN43*zqV`4tV^UGG|_&rmz={}3#4z0(D7AA;d!D$#_GCEDUmIRa$O zmSq>_&}o<%*$>B=+A|{QZGnp$z$^tTiP~SS$fb)fw`LMur#imx#%bEzK%^aVX->|k#unxg2T}omXF}D!L~fyN+V#+(7fQ@GZxah zfGk+$ZdVJ@US}*`uP?%M!0%C-jy1ZtAP36x=o(7S_{A2z6z zYec?rJj)9>JIJMA2BgNPtae~f>h0u}y>UXYKsWN{JEw>iAU*do!O9f39Qtjkr&SIg znXyngrQ@^fEYdjJ*0aJS+YW*s1~&7!ZWf1K%n!B~!WuYW*SkdumHN1>Qf&?z`@4UF zLl-L)2eTEHR7IEs&mm_*c)|Mbs+Znt9O$}T?7gC(bdDP-;$}}e{2-WRH$CTq?w&_< zRggAn(Owov>cVjAD^@wW;IrpctHPJ7Q`fka_r}e>;)@1Cz#(U>}k0}ZxGFDDM_Eq@_aung_<~$_KTZ$whn#!D4E;TzNEc2+_ zH@B|ld_MJftGUVA;+e3J7$M&X9$;DqLb1NJBCf9&L>_dd-R(mU@Y37}jymK)!}al| z8BZ`COigUI=-6G5@U8(MLu7i7^1k7TMzuVJdWoUlQ282PHKH<*$#ZbS;gu ziK$qfr}~^U$+u{KktC>Wfj|^=L{zYH`qKa_F<1eBts?G`&2iFvf0gKA<_fGyi%U_j zHz8kM;#iebCt7)JRA7&d4)T(XHSKA5^wPc?oqBjVH@*617){(YrRMxPac#6+3ZeIU zofCnzt)3SA{vnP{=o_#SAFV`rk%oVsO^JeW-ucX^Z7r7$hr*~YBBAT`;@vGx?ZH^( zy*-#~n!`=YmomFnEwmswDN`#Kf6{I5Nt&fGPTU@ zI)6ZV04-PiZ1VBS)SAgDxzRPxvU+p+;?E+QDj;3W{RzzCE4E-p>a+q0#o$r6F6s$0AcZ?w&l*bFn5C>xgHM;oBxKL3RzV=^!>$-uc>rV) z-6_F?8f-`n{QrNCC>yu;C>uMKw@_(c0@*k!0KigB;ArSm0;-wr)?;3WC?3ZkwtZpvRE zu{+Te6XJB$Hm@r-mEd$e&0f^E<>)8j8ChXkp2^AjMoGl42~~; zf*v#(EjD)X*VV$(?zrjBh}hZdN;jVa`{3#|0u6uTCWEneSFh#VuY5dRdp1(q|J7Kh z+Us`k;rne~(L`!B32^csNxiJyUevdiVKtE+eU*7_b{rq*YEV zuu-qm>hh>)75?C{`th*(PSL}cQ92eI?XFAIEorNp)KNmcc>QYylYuC*shK0}NsxPZ z@DvLT*7h!uTY0~V1c2A*q=o+FK==qhz2{O&Lc6~I$feH^O3+BR$vrV7wm#exR-L`V zwT0{rYm;t|YR>6BFWTvTL^}Oy1S6@otNtnl>`Zd%0_h8X4rB-GS+<`89gt%&8cZI{7|8gHcw+gc znYWSe)yX2qHo#T$Gv4BVCC#+au6W$1^6XrC@k&j*6>6?)iQaA0(M;Lq;!kEX5~g=Q zVg!VqGz4WvwDGF;;c!in5s~3ob1Dj|;>ZsS(&-c`=XT11n2gCGRb4N}apoL++o}x7 zm@ob(##vl*1{|bJ;4d-INl;eO3th;Ju~THiP(p)PcK;X9K`)LRFV%fkcfZs{yUhL5 z)0Yv8bIfJh^4VJ@sWrCeEjscLDnzqXro8K=yJa1=^qgS6ZzBj z=|Iidf)y%XCyR|C#}3AWZ3m3TzQjAw)DE|Xh&cV(lze#MYGHL+O2e#-`C*slvKS&4 zP`E7Uygpms>(<7Zv#rav%QLns%-L(2E5>e1oX7b!++x&#kOL?#J&X(pD+H<#BVcMK zR}F=yw1D<>`9ph-@O7DnZ!%vB7dF*|SZ^vS9Bl!R>et+golC1uO9}F2m{C4{0hf?P*|~bF&!%wqNz7irpNQ|?24E(e zn1FJiq(PTXH4pdYK#3(369iVbpKVW7C34D9D64dbTJ|8&zEK*2h1IRYu;iZFK9~_? zA#F?`yq2M5eli%be(q&-?PnC9tRC| znS5G}KHh8+m?%^u#O`@m_wHLCfCzVyM9?ZO>u0^}fVY2&u`?Ncl(zWknZ_gM>S2^{ zi>>XU?~56RHE6U8MT|VF1%0@My32oP$+O#vzY@f}!UxpDl>j6XWs>aPs^v@=s#)(4 ze~@bn=zXNwk&Ipu)Ofcqr$AFN2jsARUk>no{uFzD2SX-R3z@psCTdT zHF2Exiy+UGa^)^E1Zf%$ZxWy#agi-l`-z!~VwhxjBQizdZax5t5BVa&)6Xk`dE+FH z$E;5J=K0g|;z3mFxQ>RP0ChH=w6EZDkUuE~2`-bvcemG@s2}`C191gM>+ktj{9=0e z;oMZ_ayG4E7AmrpLo$BoF-Z`7brH-saH;*|6~;d6!N(A?->K zSZcC6kt00GFh;w+2ba~@Y=1Q&oOP0pXFO}hvkb`{v#Ep)mr8RY|>`_pXF ziWkSd%DFq}5nU~5--{l_R9b4FYDs=!WNy0ie0w+z3jlBtzhAgW*B^16A@C1N{|Of< ztrP&vfTNi%WpqdQYs3lj2@pAbEGe0nMxCe7)lCSq2ZfyRq3KPWbB16;ZMO<@j@tM7 zzT{h0J`Twx@ z-ce0vYy0qs2nvI!2&f3CC@2Vs^cpOHB2|zopdh_Oq?ZIy5vdW8B3(kS(mPR<-lX>~ zy@b$1+PCAhbIv-$oHO67_kGuI&CEZ+z_a(h_g$~MJPm0ACdn@GsWER1 z1`8_`wXzKvgxb-clj#vvTSRX~R>tC=1 zXi;a@JrBQ`ikRwhXy8d;w1`sJFD9MYcg$fd-GvJwT97pn7vb1Ks^F#Ks(okaYAuA37W$NeO~$x zir0rrYPa3W^l70rR|NwBxMvtZ-^f+1PaL?%@2T;i#{G84F;h>(NVs63AVd0Oh^W#= z!<1^ntCF#z>rF_Xn=#Tea$?8y5NF z3GI+4A%ZD)pG&}%dDbkh%*1;IE8b1!PMn$}L{YgC?Te>JRfIlqco?3$Cl^H|9#4N_ zZ^}T^@%WXkvjOY#ToX)Dtb5a?eAv3XLvV@`%xGoKE!RM5?q23aOW_OB#3cWF&nOf{ zSjO3m*bDR5&jPCI+s}fkz9()&TPb%#U5s|I<<>cGyb1B5v+vdN-oOKPR0=-j4Y0R| zsTe@%bmgD3O2#TGia+^w1p0yJ(S%s^gL*1@7_3wZ+v3o;)dnzpJo4~r&Ghujfv(%%W$-%%KCvILxtuhh1wgyTf6?^oYmdu_T zZkG2g8Vxy#I=@k6io3XWwD7@k_8O2!b|)>sNL5du?G=H_n5)yU{VxvCGQGZchxy%C zBopH6xnm;K1@>K>mV=!THDTLM%5+czEne=+j>~=Yy@X8t^x|#(FNT*pRz4aGs`TXn zFJ`wqkn;-CGP=Y@_&vb?%Jl(l=@_#0if;*dN8RsYfwkk@v04mI#!gI~1@e8>rPuK` zx3LwP zJfQcGc~hyB_k=ptLZ}>v8GZ1@$S#mm&^no+Uy-7Fz6v0S1$?3|KW035Br(2Q4|1Nm zm&8Si`hZQ3G1;)DMBp`zCCN!*V1PTht@M;zMR*S_Xt$}NZp)(7KNg3clyd*M&bNYR zof<)$nCd$xUTD*yH0lnscu;g}OllQ`hId=BH?Bn!kB-B4DodYSc!&Aa{n446?oHQ8 zmLD&GA?dH}E+1jO|JXbBJSBqSc;(OSaNd;Pi#(rU>`VX98<(ZXJIv-5aC(DX>=xDG zQ^&M4>-CLvJ|tXvn&5M!l9v}Se(x81WU^uGAg8NCpY(R)TT6CI=l4BMDN3iggfp}S zyY!07?#k$w$XtO)KUdIOy-tlEDjpB@>BOXbH9qQGT|M|iNbr>1#0Ctw)guMdpi|)% z3EtiS%DS$Y^eih?7$&KORPhmars&m~(fw_~eTKaJGNhP8m!&ouOx8dpmGgRvaiCVP zJvG8{hBsESQ3J*<+8o3tsp2lZaq9sqY+WrEmpp4w|JjruC87jScBz>$v;D(Ui_b;I zJr6QVl@}4_NeKA*2tF6zVvq@^gSBBBX@(P9m!V#b1S*l zvYcs(5Y4UJtiuQ-_1*VEg1YUA1ShAMj9~4anWC>hj4aKgC2RQ=BY)6x<2rJTPlu_n zLk#;s@XV;JYU#?r*MyQI{!DHF!FgX+Ct^FgMEOyI@<5=YM>_=fmJIdJC(3CO>6idm zEWugQ!>H}Abs?X3cEG%Oc%Um5L-6^AMv=lNlS2awVvUj>Kh!O@@E*w3B3O2m+kS-$ zAH=r3nwY7yc22w<(7c?%sUvE?bkTt@+(~f8Zt0US_1=szq7#5imGoAOR#u~4mYfo` zJ?Y3gZ{LQ0oDt)(QkHnF!<`Pne6=Hfc_06VAY+;P@PNiBX%#8!vN@|)FK>ONy%^44 z8HoWRhL)Pv>_4O}-r(Fz1k?6F&3F6r4 zH!)W7P!zTtYnm2Mh0Gnfm&45ei9?!?aKW0;ZM0l;E=uyi_dA0IiOTWw z@vFV2-Ll)r34ZA6og3y>DAz_BhK$Z>!YPpQ3j3b&YQE*o;?izwsU+E|@4TAAk|T=R zSoY+-?FO21yp6uP$9GU$x`^G5kbd_Gsj$1j1p8Rnik|3c3;1>fV1g^w^Qp8+b8>P^ zcBbSoVW#P@H#IBlV3d@7)_Q^KxtL^HP@D1k*Dj}HN@R<7sIGqEkD9M#DGv2NZT!j8 zQt0yh210qJ>=|-zEW;M)DR^e#df~oDIod1PdN#Usi2%Vrpx{HXOFVkUCLxdwz#C1- zBGR(WwePwaI{@h=otNG^w29ZJH)yt;#JQKhli8WpPBtR#17%HIK##zXziSJfJ;NDmtW~Sq;`f0YrXR4rawxYj>!aMmE zxMzg5_GJM^7e_g1-yzl#!8Wnan)wpbZK6Lwsl<-gU)u~S zVgpc19V7z z{Ob^OAk9S8W;oy47ZXGzE^=ktVYbo>9k|@*B&?aDjK0vSS9D0C1k`+TfJ}+d`bbY- z%Zn?dn>1vADY?SIcdB~|Bnsa`QMgg@m+Q(Ol+j&Q$gt53SDT?y=df>$4sqDDo+QvI z%V917!7+=QyxY8Qab&4Quh^U1w$R$9>@+`XVCTYmS3CigLEv!VXL0=CK6PfNQ^i>M`x9cu`Wv* zJXdLrHsCCaJribI4y)joT=w?x7%cJbV~+jdt?j8V+~^nZ%2t*wOk0WF%6xQ;W9-mn z(8Ai+v+b@_#Giih$&aJcDs{8nlrIwJ6;_7Jp0$NgdB3qf)!(>?A0J40`2N-e=k^+P zjL{M5!<5=x`9qBj+H}V(yP{u=p3&$We%Yv-^r+%;w6iy84G%nCYQHT~HXg!f-JCJF zN!(rJ?|`svcx$uYCk%pMya+hnzya6$YKOuRJ;ay0yKb@*ho?_)h<~~2>UcXlY6h|2 zB~{3WFr^AlR~G{j`0czZRG9DFK>L- zlXW@*lpf3P7Yg}~N3KKSENd=1i_^s%uS|P^-C1c6ozAZdQtF|jYkFZ_QDS@b>`7?P zxeELp{^~Q!Lq)>(6qkfx1b~w!=_4dfL8B=s=dB8kU<2V*$AiXNVJqL35{931Bf2lE zFew|bU0q4>+T1N2FT$qwCH*`_%|+`2C_?uc@k}5|^(gt@BR?xhjD8s%>TSqQ=RU-QR%t8&ODL{!NE+l4+-R9@X{XYJOWLHY z+rGLrCW^w-=%OAXtAqL-vkHTgdzYEGwK`n}x`$CqFKL)AKd3un4X?9JfZWmZOaXm& z-x3(M97PSZ5LKFu^@o++q89G7acslV=} zdN3wyyu(j=^{{sq=zI2#2%!+Qs{%=EZNm;dL)NPo=OW&Du3j^W?w1TWy@<3) z51;RH9?ZAE-0k4M)6T8Tb0+MPfu1vZfa4U^>dSL?Jz@q5%p7_!&)8J&WrP(g#%Bvo*TYx9%d{ov^cW5CN3@ChZ)H zXr<<1lD!U-=bGgg?uYYEm6&37x=X#;`t>h7dUMC-G$#g@hvZyV8>px@Pvscp=8zM6 z?pA_VVXHvU?Rb%7lUsq z6f7QO$_H6J(F!hjG?O)OcHf0XS#qh@DQz&@VsgRp>pP`$IOi4@Hw-m3KPJ)M^VEFxg0UuD;o zDYpuYCI{Mv%1n_lur1vgWcZv7xs;O8H5=eGfi9gLql(w*rPm?>Hm>xb?ABrBQ^If6 zp(sY3tsIXPdTj3xl3kqhn+2TXw9GuF<_D@oY&-j36xxuMm6V&jRy!Ou>NY-6uM~v( z{K>k3Be#lVOZZ}^LF2sOCqLul(7RQvTI3?ryBy=74yx5zhsz!Gws+{~J(3_#&{D8* z4l|{^+WhejuR#CD+s9`en$E(-V0E`~b%#GMOnd<%d z=LE&?;$$FJ`r33xQY1IxwD^;TNPC8F-qg7Bkw5r?LcNo`plFZK4u;Tdh?*nR$pgE< zRQ4mQ2d}Jl?tdc(X^WP=(GpCrluq(L5ar4cXFg+0}i*$7bcruR2c&7ghK6hLQdSY{)|_q6

w@^gs5Td< zSiim2_HA-#-=>eMqyCw8vS-xEGl|{`w%Y%pUo1~s2<_7{gj+tHulw|zdb-y8xhY5r zoE+iZ0u8!{xD$-NLB_GOWYqr2o$Vn8&9gB2Xh2E#0#UHqcoG$0sov9ZhH3D{qTS}e$kBW-1YzIyt5-vvO-u6{K`%yNf;O>rgY){>Flka zjsBbE4iI%V+PVz$QXf8j%UPG{SI8?r0}S2L-E4Vs|Bu{`U$VcL^MF-982{cwS$6(%CT>DRyaey{r;Hcx3=|a-QCd%=s0AJIMiN zT-B8pX#aBbUy6i&gWmq>llPZn4I7`3z{BVG7D&L(#-Hu_KK1dD6M25treF)^H})?D z)0v#CSJ{479{=SF?@*4{^UoEye0{RXZ17GM49a_lj_EM@b#LC?wBTOcC42vU}EF( z?BmVktF9(IQh`;j9|ND&i0gMhcYM&SQ2VIcP+@A+?SkN~6&!y$atBXKC z|1_7;yM+UMUXS5%|D`zqs3A$9lJW{3-TC*j@oyN@6=(=Ixt;%fNbNry;I~Dtuf7WS z^)i1?)c;km{`vR*9>Dz1^!R^t0Q0Yk_`heDGvs;32M;mq%}0Oq?bGq2eSg$D^BZIT z+fOfm2mcRUaerWt{*BOm{|hk1{nWo)`G5K2-&5RwwZcEM)!$0wUs&k>&=mK9m`nB7 zQ?CC1oUngP4=91_@$kd{vFrbDHI5gslSDqHKZdCOy*e2u4OGyJHD++ze@y*+KJsMb z*&nZ+r#qLQmRaF%{Db|qBjEp|4A)*9uopO&wNLJ`I#b~JYm~R&TziwSrXaxUe}?-_ z=oK-gxkf=&;-*zvVtHz2Y6bM3_O6webCu&t1-c@&oKF(H!6Ezf2k&quHP`OW&*;fR zN6vts_fb$D{I5Rz$d|Bc@t9fvPyTsf;nNyqI2)W<^-rt~Hu~VPcN7zwlXGx@Unr-X zzP^5zPPJ5dh4xKVRn?8nO}fz`fzb>v%W?cp@}VTTW(eGp!m?uxVH72+SBRgA;C#)* zOZuPtN?McHQ@Coe_BK6lqAvPo@24^cv-+9?26>K+Z#?(i9lW5;sYmKOjm6wyxD^oY zh3};7Oq^y%33(SO%LCn+&&fAlzn`jy7*t3uwU$5#szSFdijGF z{@nJzegxce%5~K-_P@8H>1f69;_Nec(pXVqvG z@h7*xpZ21Z)%d3_r#~q@J;&5sHF>od}UWVz>8xW{wg2&8?w>dMQ%t#`hSdg) z;1}Ba%Cf7kk&#XL)pT?CbewZxX$}oygP#|(^FJ5B{kz-$Igb1(wo^BsEsYejyz3au z5`n5&VdQyIt8gc=!b9%=q+_q|;o<1$c+*4QgGl3nb4RA8a_zc%bmf#@2mDIa_lhV*ZYS{sut)9|J%v&Uv@BwaqOr0)W5wRai;GTJ?{Rq-@Ut zk$7yU4z%ti=1oME6zLHX1Lkh(ZyAML$gLjMcpc8GAH^fh1xovV3t}|Y$M5CBZdA_I>VGM8>Sf*1EuU!*aC3+Y7#qW`>y#!~ z_uC&n{~tnM-n+*ESQ9^$s7-mW@b$;S`Ng_${i@4m;OPQxO>ZrrQ0V(imvpdvTC6Pi z;j-R`Guto1xhCIJla4ue5f+gymm^{K^X8CT4TaL)lxVXr| zx~Pt>k=U`Z4s4D6NSQ5d`AmH~w48HWCieu?TQ>7xzQ48M9VX~Mdhpk|e1KWr2`oe>kSL)?Y7&nKHA!=#Bs#e?& z;PGunJ8(fSw%7}(jxxr?9mezW+ig%sJD-d21AZM<>nySQXZ?+?89So!^0Qj6CbeIm z7?J!-el;V6K+dSRHFfuc7e}1iA0uh*eEI%Y#yb(08^^|VKW0x?5R>QEzeipp2eBnx zIUcnePJMSO)H=wFr>5?m8t*B^R!M5dV(0N??X@*Nw8jIS$up^+HSJ!YjYtH6jR%Ld z919;1D|b*vq;us@R0X0$XUjbI545KGKu&~6V=Wf+tZVO-5c>LUW_k%KSHf!*)^gbi zue5i9BD0KSXUL@bLMGM1^^bTN+Y>GHe^olqkz@AX#-0kd3_^dI1@I4X=-Kpth(is~ z*pkmG6?HAyCCU}Iexe4Wx2`JWsH)ViT1&hn*LG5Pj!vcPd+hv`c;gf$b z$gTzHLo2zNX8l+5Q@g@Fib_gmX+sR-rFktso;J_&M+8F4I!=x{!#_K4yS&B1#7_TQBf|Qc73@FB@|!f?x4Ec0Kp(jL~U5!iE4f;+}E zD*!O-HTZYE6fXB}3^A&59tdj2C7{!Ctl_WC{t}Eyua698SuQ04G58uuLCv;{nVZwm zef-YAn{0X&fay)ZQYu1~mgeV!XxnA7v3#A3M=u^tGXpdiGBNPf6w7s?Faeu_gb%jK zfs%*`+Q>2bu_iL@_ee#YP?VkMP?Oj?dPX*ZhJqbGCqU4<=h}_<{9SKzs=1pO_xi23 zixru{?2RdUm`(&FB5Q;%%5dLug=zt5HDlH7lY1(Q1dEC89$bI`%KZL%o994k%256~ z!VDSZs`qZ4^hE@|bRcUgkl@h%4VHy(mOB1EUs%E6n*qpktt zcv8MYc(0?JQKJW`tA&ThH@rbX$g#&J#&_sS0xrlVcvB8X_RBs`&O|b$$#tl|FYrgu z92<=$8{7f;?oB}O%M>%)tykaVJl_j9_SOTbp^VLgV&IUxT;p|L!dad$D?OEcey~&^ z?;4e&r~YK1;|-YYsC9Y6aF!3PZ1^Tl z0LUhHU%BsQLR>&F&6)2v&Y}x$JVZft?9dSlGcxb88T85T6`%s8d{OGu9oyM+;E^hT zRGsAC-n;}(wR@Vm>Qt;O2e^kErSJEEB(v*6!@MXU6dxee635c+o_jw*z6X;F%TnO5 zu7=?0cgc$Bx2KoMaxj9Y=N!e|pQ~^I9Qx#^)d7iqa#{Bf2BA2z$Ic=s4b;XbK#TtI z{b@MLgF@L)Ss0?7E%X;^PL(}P4Z)4xy**>Bee?>-$ma_cna6y9mNxkDxyl~T2J%7) z1TE^p5d(^S6hRjNHR?|BR{=qDA`6;?$w-#=;Ez6%t&iziql|JgE5Re(SUdnN)b0SP z>n%tE678WSTF(P5@lL+02rP7j!cNKN)x*x)fLGPXyec-Q?AX|<`Jqdxuk+@mnY%BK zTtTr@)bo+|t_H66<&KK-URNrs0jdM6GA0}a05zTgYOp+fyAkq(x7KmM{XD^-Q`NT$erk=pAaE~5%vVskgcEc7_TKwhuy^sgj(cG5vJ@t6CX-Zxy$I1t zIL>wI@K8M!OUo-8!U|-BMYY{sgaq&6EfIbllLJDcgmQ4wteo85OpdQD2P9fOZF?H2 zvU?T5k+jy@Kq-ay`vWa#->tkq$ZLOQRC5)&f2p3V&#zOM*qcm#YqYKl@nt_%v7EpD zx(d#z{d8j)9n0#1Ul6^)W)7s3Qtuj|Z1$C=R;QqBwa6}-zW)2V15w&0@Uf_=m5f72 z(!9X6?Xq)7?-^Gm2!O=DaGluvg?$vt=hc>37zz@RT_|EtWZ5*+XDu8itnVAm>$a0y z7;=0jD@X(M!AXT8x7_qFnkRbmdeNdL(YPj{Y&<*-SOH)002wMZNuAw;Q^1`^06yP6 zMPGGRHsJtehMS3TSt8PC6g%X)`rdcFd_Vx|N!SuFsoNzKdOiMBYd=cQzfi*KWEx+! z^=g?oZHhI6V@U9mC1dvHj?T_?voZvuj^1$C0lAn>!ur&_x!H6CEyR$JpP>Ubt0@_r9|#Y@JEiA3n>mJLR>Pzx=7mYb1^i4so7XwM%AI;boAByR&2FMx zz~o{oEcHVaqIW>!A9_hN^_A`G&RkjxkNObcH-FG0T*v$k!fp zMR7OsP@(Zz6&}L^8|dkM>mKX4%lfTomRZ5f)NBrL2@)pDihJ9u9B>H>yH@0ik<5dd z>vdmDAe$Ih{hXbYRrl2ig~`%(uM2VSHf(6bQLSLT7bY`rCd#^wPTT0N&DMKg_Mqp7B{NFncu&K=J*++V&YUDJ zISTveJC$PXbvl$&xrN=OJ{KNpz4!$#Fwo?regC*ds!Ai2^m%0aTf4S<&OM5_v9CjY z%#zFb=5X8D*wN$frb_LnsHE}RE(8G?>_GeM_K5rEFjEA}3D3cjwpVl_kw?*P+oMuKG({uuH{m^LPA*6q)lUvpxq)an7`(xkqA*+IHQWRdZf#%?6Z} zS5%nHj%dZDK3+Y`4)>}gJtfd&-l*o+DZR1c=D-c}=# zrPo#t$wwIO5GLJ#BqAa9Hka?0rj^=`*YFtS8N?7bbD2cVdA(mFG)4EZTj$g z@#b@#V>Eou$OfB7L0BZKEq(E4bsx5{d7w%jyAoj|PJMnne8g+^L*@v`*%j=%(aU>M zU0q!aP`4pTll4}SpsaSEQ~}cf>I~vpu=_uxO_mJ?bI9wUOM}7omcWhpXP+ zU8O$!ioObk(w)a7H|yGWc|dkTjt+#?>2rQfBio7Y5bIbt`a@TafWx9K&S3Q)e2iUN zXfI=}LaRi65X@j^n?Q@m?+`*EuArbx?M0)azQ9B|1R^u{aFl^Q-2zt63PR-$2pn)o zbFuD=x6cI}yX$I#s>G=V>A_O(hHH>=0nGJmXiwEgwIT!7A8L@3 zZeH8QJSL1E#%H+InH_+0_9PymkuQLDhOqmw}otinB7 zL<<@RG3dot%gAK9cen#LC0leRClaWF-&Ne+3kQKC9h|8}4*9hb^h7!1h(V!~Vf>^B zyqlNXEOe@r-!s{UUC~7;uF?$uE#r=VbTy&MVX|J^P~*O;?g_gIb?0E7oNB&mY;3_= zDofVt#UcAC;fUH()=Ew68l`Uhs5dzKPi5v`0z?PIP`ec*+zro#e*VBx*O?`B925V5 zRkJ6HDnyWHbe(vErnUYhu*(5nuFm#^8@@#IN2+JIVL`>KY2BAR?)H50g=G~ET(sR@ za^QbO%U_*U>eZR#=N7SaNm(~fbHY-2KqF?fd}y@RILG+oIxP)?%3p`;$VA;uUA0^a z|6ncFleG$&QT=x%e!!E)nknC3*5D` zK08a63b^Xo8<^o3@#iv_i;^qr@i@(;%C6|Ov#K(i2-h*+!_E99B_;LkcID+djt(v6 zM9G!i&m);J)=mKJY2lJ#sz5D6)@;onZQ|%>rQ?ar{+|AlO_$#?9Sr*Br;vQ$-au$@ zequ&vp9nwfwoPTnORTaNVQ6eB-Al?~7&h*)9dLu*-3v~bP+)5{S`XapYtE(b^}U`@ zgM9YFg@PYMQJ4d?cQ!c^=F;#wKWce)3q$RO-9O*UORzS?%6c5s)Byp(Y7NIaF3ju7 zCwz4cyIAYd6W&j;go7VW?@7QPyw3vPgwET98E|FBSv77@> zsuChlqwKz3OQEK;2s67fIZskx*LuB~>bBeB3ht(hi_22}x{Cdb&hX5gBR58zK`TcOj zwUWuLPfYUqu5THYog5v%MdOz+Twij%aJWxV?2bcnv+?&XEAEc!&elmRW-;KZtaI^s z+mO`CYyn;A_SZU0}RHfW!;b_DixT~{LjF`Y!cWN-O-HKEiDhePxuC0z_XF+4^A6=EF^KY>SM&o0_0ITiHL`SO=yJVmtHJA8Hy)qHcOZS8=#o{BHc7I1C9$Q!jwo5qcYu$vJIIN# zle+Eg*Eb{TzZ_y%8w!?~DX?#^+MXuUl^1v(yY9F(91SF&i!F>v#B>P!x2{U(zAfWX zTfUg1Ay&8ppX^f!(zheH*;jo~o3B9*dAS?BpP$5iMo67vCpM^KH*d(`iLRu5xakNI zWc}5?8K|R=S2VPY<=nT^6z(9K=q0`zS=)mfw!?YI9k~h4UM+DV!#xi_LnZ&h|y{8Jw!9 zo*KbUFV%mnK`wDNEZygD%NB&Wd(IKiK_%!d_KuE@5c=hnmEc&HA&)RKAmEPHD=BmK zv9Z`K6)AD;ZpWdf#FT(G2#*nEQQL;4035%ACw78|HOdS28u6p5tUo<-oqMma)~t_u zlsU-|t%ztxdlKt!(IVtcwB2Qze|6Yf#}wogknAS43djqJF`E}>>8pX-Tnz|^rCMi}uPKW2JBUE9zdKJhvq4THh* zn%QvjT1oeI@49McJbd?25h%r`7XYb~P-Nd%t1$mk??f4}5aT`yGuu4zF;;NMTKn6B z6k*4J6u(V!-V>m)Z~~&69k(wh{s(UX=Cs}*zX6{gJr~rqJRLzC=^qVu*GHwEu)ShJ z814!=+{##BGlt#;x_aEzthazroSYSyw0cppof$z=TH2Tq-H@Dq;G+;PGh>3~IghAN8%P_CV`Oaq?W@hJ`Ubjs;Gj zJ;qc!eC4o@0zoY6NCN=k)X#O_mF-ZU-T<&$+ub{#832e@WVk`eW^88U@fap{QqA?E?NFzc4MAKzBxb8)l|KMA88*>UMh#kz-)XPkMKl`aVMpcN;L`NNq?Fr^sFD*=@%|p!Og}fm{+~$zT zht)ZAR4E5YC-YPxCgh69uQUAx5-P$TDB(9K@(rL$_vz#X(& zu!`Q(QPu*@1l@|rWjz4G(0W^qMMfGtDw{-3{Gge?V*!koE@`xATXNDw!8579=MxPg zKUSNxQ*-~?SH0RPI~-9(BM#OunH-jpdHK`RpIS z75hYQ7))rZ-K?nrCN+O&X&Ap8^Tk?5yfOIPOOJwH8meDz&=W7rv=C<(o}cdcKw;u!V!ZDnkC_`84h7KU46XhOv8xKxB3Lkq z81TqR3$2Qv`*NiHQRcOUxuWm6DsR(+*fTOU1Y+Xg+;v8Qnv3TM?9i1B-Y(}?%y-zQl?fmr5H}E*O`ATlVH|KGI(N|SU_AZTr?Db zjcjsvC1@QClpUYvVnDJk-{DY3`Cq&_%EigN0$JS`( z04ClB2;rjbEp7(ser4}4OI;qymt0psHO!=+0=qxfVfM?j9CG!;!x7K#=WQos&Vuu{ zT;`S8-P&&RV>fbZT|L&T4m>f7$KKu`o^ouxkY_QGs8jA}|45ZR%U7FRDIl{e>KOjx z))@2pY^&dpU8#ghbqRSX{MNvc7?$sy#?{Wx$E}_O98e28BH^fX0%6gKhL z*42eFuT8j#u>kfmkidjmO0ocqOf%=iAbZt+s+yQj^qPhU`3E-*1#ZUaF|uPllY$(j zaqq@bgR(8iap@gU9%E4ay-K1BR7uSI6)f;?sw5%_7qFm{1jPNzq(r>+=m!Uzb^hFo zO^~(mv4Cc#gPQsY8+EUMl{~XT9N|Z%R!D~P8t5^{BbIg-vFrM1f`f^15#-t+=pp?$ zN2v&kI+$`w=VFGpp{mt8X{o6mjzL;tP212@7TNgYtjR(8!im=Eo|>6>mYjGZowila zR0~>LIL`-o2jrY+ybR3@wdKpdM9!Va)ll8N)oX|Nm&>@S9_5Y>hrU=-J-)E4%o0L# z6a7oA1n(s&?z=iC_Ir1-aFA>479CXYH^{J8m9@(ov3kl}edbQY_j-_qBgLrL&!v*% zu#4Xhx*AYT$_59GM~@xViDJ+4PoA^57wSH6wYOG5hTW3Gs2x7DZE5no9S z1IJl|j%2;`<&nua3lEJM#8=;@>NEwa(h;nqESkjkYEL)u6nUNf=s#YE60Gw>rpn=a zo|;_yI}%0!{{7Xv%NA4)7=n;{-nak2p6>n?dEo9h$yV5>{TSG4a&EltmB7QCf!la^ z`pGH=0E0ZZwQme{W369Y3E1GzFET!VKF;1Vksx#{q6N+JD8Vrl)MbEB16p?0<>Ga+W$lh1Utnjh)4_V>W(?sMowJ4j=NhBxBS8jt~EG+DSFgc-p6GT8aWheF~ zoU0+=gm;>cr_@fKh_1i+G3cmC&HaMV9l~8fcP?NLKfb1@_VWFf=kOG)v+s;@WyVgL zA9cy~2s60R*;}n-J5vJ)$4J$4dJjnjr7Aoid)D&x4_RCH9Dt`Ok#bCo>_rW-h_$P& zXoW*ufq=62m;j`3^~21bsZvn(v9VYn6-`hH8aKX47Jw4*yJ(yJn_q*D z(h2Dx=d7~fsKCU`>p)t*-USrZw<=X|%JUDFukF>m=8uT7660|e0AxgV9|2_K2FRz8 zx=IizGWh*K;cE?x+v7o5U6t6I0I!g1D~=?~pW8vY2Y8pA#=VN~woM29$tH$m#5 z+J|~9c~7htR0?NVJu*$cBNuIpud}kB`f4rHZ}7rnVP(s8L3O!y)8@U2=gqB~Nx~^r zR~{J@3>tqD`IZ z6vDWL$In>%*B>^Yh+2dOYN(RzFkeAqLFx2vGZKm9KrJU}s02jYm1UQr94Al+!lTMf zUMSy)(A?UHSGi~~@!KqSC+eE2ns<<0VA>DHtfJ}xWBg7n@2!Cprm+C+?Id{Isqd(q zf|KZZVf5=sWEA~111E6!oR>Gu0duGw2Ux~koxScI_^5Bl%FeT>)ZQY1)!lgH9S`jb z#dz1km6lN*m*#5E4)u2{bxYJkCR;abJA@MsUg8mp%2S34Y`M(3gj*XI4HcvwhAn^L z|AvT`#+8Yop9M_K#1k)TW$7Fx?KVZ!`x!~__1-rLnrmg`fUS;mOk%j=0zocxn@6$f z8MKY@m}#zcPQ}@3kC`$uYBSv&F*`-Oh(lMnoVM@3=F{W)t)qVOhA*4$eSU+B$JtD4 z)u0~r6#*5Ts_#zc_S+4KExbZ}DIC^_%I~urlioh%MvOwD8rdUT8q45Tj1KY5vDrA9kZe^>sjz& z?)yj$tBb4EH)MLzOVwUD`@$u~0!CI_LjLk(5OhFT1XQS(vvirq!MSrPCMP4qJfJTk zCXw-5D#yL^xhE3J+k5q$(5T>-x5MbtPF;FJ?k)nt~4;7-K?w2 zoeMY=s?Ed^HgAP$4VW#I+tNe|r_9C$3Q24EDPNM>t!p$2_VU=|;owwUF$<=T=UrEDVacgf!EDyz?TS*o5 z@}Mb1LbUgt3@;pqtC)0%Cp9J1|5)N;WVBfIwp(YdFSGn^Nx2w{4r4D(a%5 zmtK1;jHAAkrt=4H9pZ_H4^-H|v*z3{hs)q*bvC}l=8aE8Yg;Cq3<%B-z<v*QdK?II{`lN33)D|Tg`jn^>b)p^$?6N!kFyerkS?e-g7!3N1eHlH8kL@gfsh#an1 zz34%4SHXPaGMtZyZO;9Ir_RY%qZbl9KRa4s$NX6Lz1L!3e*iMi~4Ma3|vqtbm{i$W{UMg}>Dv96IjGqrfs{nHL; z8Ln^_>65K`j&H@uu#5fIqxE0D_=RejrengB??iklD@$dSCUi3huQWEO=I&U0GYbNU z-Pl275&|&uMSft1N9)*rpB>4Z8VH;$^^@7&q$}BAE-ue-8Gds8iRdMjmdw`pF~&aP zx0F(RleNhx9&37DdqiruCN7@%&Hn@h?uiGYo1_X`3BbJULy4&1J26-)1gI978pRO@ zb20B}5Q9TQQ_V&@_p5_0&wT@?hXq=eZRGjTw3NVe+9+r{1eEAI1vWEkI(-?2#GGs& zw!bc1p48fN&}KD-ziwmck^;ey2C-|e13DmNV`+bkA!X;RHf%!)baU>xIL)l>a@E`v z6GA}nn(BqX;bPDCk5z5(EtZ(Xee{%35U9$q^XDE=9x!S(XcsuLspHw*AgAD?&Tfb4 zc+2a2a`k*p(YkV$=dr%2c8K4i_H!A(%*T9aa*8~+I!}=78x8`Q?qTYc*+ZfMlakBU zTW-?#l2^~cs` z8fg6T`z91%S3%w%x8CeyoK!*FNfn#v;t6=YCiw(H}P)2h4K~%Gi0}&P%kV}=o`xkPPLP$>@?^cJwm~Pc9zd7YOSCW zzdq4%=Ay`Vcjf?98|fvP5lgmiNWd3T@+O9=Pg+;cZD!85e3etscP0t-E`zKHOS;^5 zoU=|o`sS9*8*R{w7zx=f(5=Zu1_9`B;fNugG#qr;#xNhDnoZ zjEUlI^WV*3nNjfU8C>ed9NYNl%m>Jb#Y0E+rark@?`1u6M9>?LH}1FQ5!R$UDbUc^ zip%h^>L38t7Xxz?#{er_U*TpphiWzvbsGWch{#!wkos7;Dyxo5f3B*8l2rCatn>7r zVXf4FVoCUq%jpoGttg;7=vmYO|14l~0|BjiXi%+MM-z+q*?ci?~(mPb- zsW_cB4o4u$*DWpS&eNM&+Kd1#{5aQ;V4L=j8>ij2cKm!@^!AUr7YD~D{Q}F#4(xp0 z(tdfB*p3J@Hx@wH>AELDo`k~3$$z$6N#K`tSWQ40L||0hXY!<=cm%l(T54Lzsodt3 zD-%GETcTv7c@whtW81panDt9G)33!Lf$xVVj94F`NbuEDnk(+s>FJK0o^E;k(G_qG zXI*ZH(oQ=ezKoey`m5ewQM4mc@>t>lIrKKm`bAOf7F zwawF^Q@`l}V!`Qn#lL;`?V~fGBuZr)_&b`GUNY=ojZpD<9=r%8tToPg&5kU6Pu3Ni zCUpHl(?a5v_iKJRR)efA2-Y3KO7h<0LKc7iSpa(eT>jH_O^BM^sm3<>TH9LWe>E8+ zElCR|$c_*i6X&99 zQ%_U26VU#nb6LTl!p>!}aI;uV3aZY$q-@&8#aWx*Q_IB7uyEOP2{Ut(I?SyFGbF}G z|E$U(d{-=vhOOr^VAkFP6U8FRE~|i9su~v@m$q)g1Bfk*-^WaG%sS(e7=TTYnh;L` zZi)q&XngJuTIs;-4=wai3!18`jCr6-bD6$1nWB z>UTFe3oc-67dxvwlL~~2if8aTZ;NrD{C_a2cf9rMYAb=ypU}FWIXgBzET8uy7q5Azx@C9SfiOX zZ)-Vx*}cuUmAH>o+~p}YN9+nFpKJhvW1#TqMezg(GJyUpMf^DxG2eBcYYI43swaGd zaUW&?Y1#@4lueXeuNTTYt&X`IKruZj>{bEDS1bZI@c3=Hg<#hYMC|y%AfN+oSq}Gp z@r~Z$`_|g(_tu4jPNSJ&*-Mih_s^BpeAWl@m3E9b`IUpxLCjM5&%qP-+C%lVC-aLI zO@HY9h)=XaCv74pZ!F|duro+jC=}6*YCtsOas#&a$4|OHg!U}z(ro%C{0A0q`P**k zU}kuN{~~W{2oK|2`aVg?W?Rg5Fd{^%rvLtwW_wH>Wvf4wra2L(lY zriv>Ju~osQ_;K=gjxi z{50+mX~^GvK+N1j&^EDaKU`wEy=Q>6rwti*nk5u^z!k0b9$JvS13BZg=3IL^K5o1b z*aswaIOJ;Ib&##7sK_TWm-(3-)cvit>*LmsB`*SPwLosLu=1;)zwv)Qbv2CPydpu< z<0q;bX*56&lE*M^+gu~ zu;fKL=!mPn25vz)@%=a;k}9s`@+JFf-EX$7p6^{XMROmU{yQE`xB!l15%g!&<-^u# z^ACCffXGDvsQ!b)d`;v;69N`LesScPTjS6&U9|dB!sa#82#K`UgYfX zkc9wtI4%wn!Z8jpx%SiXzU9GcPo@8c}0|iCXWs~zTR%V|mdZxQ#G(<0j85# zDuJ|C!VEe{KMGi_-cA%thiGTC)&Au?pNVJ=FH8m7_d0ezspE0c6}~47a)dx2oWxJ( zY*7eQV(V|u7aLX20I@xBxhJouapayr$K0t3=2OjDtw_~-%yPU~+Ytn5wU@^Oy47(q zy`=ljnsS7Tv@CB+za~W5+kyO9%2N=JCv4sQJUFblLYM0|V?Sc_qL%(t2y$=LHfjxL z8L$Ui+VT!<8t_~>X&eYMnmd(FvK#HqRir+` z%C!O<$IU`t2v4k7YqbP-N5E)T)6!JlcVGfNeqo{F9=x`C6hN#Yz4QBO>JPEYxve{~ zf!>acz8YigPp=Fjuo% zGev16H|Q|<%-BH0Tk^LnK)EWBOE$%;{CcXS$0T}b4cCtj3BA+<|g+`}zkF^UBb1M)L|l#>=_k(_D-cl7}aTCo~%}GfF(;X6WE69SN3_ow)_Db-NGN zE+$U_W9OwaKxUjY$v@T@9i-79N%0058nw*AzI`0h) z!FPhctj@KXQ~Z#KBkYW4rRxiSk!u&;@e1+|eQGV-{Mrv(m`&QWyduO;*3n;Olg=+F zca3zZu5KrIZQ54n$+W-R8dJ$Z6j#(Hr1ioQu((6j<>D)7p4s+exBv4a{{ORqgxB*d znxPo#-y=|U*=nwi6t(e)3f8v%AoCC3<(S3Mw-*`vdxUg*OU`otipl0+8v2vwAMpaA zjMOBB`DeyN?dt3bQr)@+?9QW7;(Ojfj#1wgoL3Irj$<2M`wZnc8d)=TBnhT+9MwoT zaL6e~Y$LeXZWM4%i*3iWC%W9;Jlv0rjNB(2=h^RtH#cAlt~m79ZdKw@MLJl_wdJ`BvI20XxqynC;p^NM0I0<7MJQ6hzBqGn^W10 zv~6E2hVw=x!4)nKlxfprKPVrQx_2IV05e=qU-ryV7?bY3qeMj%L0 z&f#E&r&{svRYk+Wiq}H;L^|5<@ULM1sDEp|J6aJnP9HrKANsJYQE}Kp^o@Tw_y+Ii z3&5tJMYb~pthIDF7=3{IbuvfGcVpfoq5kE#mBiBwJ<~KtPT_3H8I8vd)CF|~ zTYn+A<)h*!)EjEXHQ&?lj(h7cf+?2dXcw z02@rcN}WC0>~NxjO{`%&wfO^zhdekGR@18yMvwIW&B%025vD9tP z34Y7mx3j@x{-&)u^!99nTXe{MoZH=}yQRk4L1UFBl!T+^p$p)ljFW7SX~2*thK-Kb z%Qzll@OzO0JV{^5O-=@eRN<MEuJmbdssdaIFq^GkYf z11qvI_O}nFw9|_)TtRoyMv!5?;vuscEN122O{B23Lqu;tR5ROlbi?YPaG`t7S}c;+g*lCU1&M2K5(e?A{WeZ%L60f&t~DVW<}Kj);b z@UwVwIm~VxwP~x)EEr%2_hNDWS!$|5n5%PatgxVjjCSGJxjeojmPUhd&aA#)-&Fxc{E?)A@WiQyse_u z%NJnyIZFe%L}x!3eaUn`+p~_Xx}N2o+OEcY0K{%ZZmdW8uAIVb;6?6fwd-KuV%kLi zB|L3&42{^PcJxUryuo|ogw!uLr9pu>9yemO)cWQ`7mq3E9xw8sl9LJNOYk} zkVUUFdd%Kr3c=qe13RB>Ac?vR%u3OAwd352S&Ottc@K9lQ^`m4b@MYA(bNV-Z4~ioh8p zTmlYL;Gu|~`u|?>^FOh?jjzUQ`euKQ)Wd5M8GO^z=*~|ItsR!mfp{`xfEB-|MNoHm zXT3!PtfkBt@mAVpOe^oN#_JoSIf@N~xot{Zs?ik#iPdft8wKvpfT%9E02D6f2E~x=`0L{uRjD8=FLGyEF~QdN1Pw-9zl4X z#H5L>wABqK059bfYa`%-XA>{{s;1;KDG4X4Nl3#ApM`81mm6CGQ%*Oh)$iE=A?@U` z2;``AbL~OL%2k;c5~w`^i))^GemlST>m0OGL#C-BXHB9sGV@|hG$Nm4ic9OdM%W( zMlH<2h-1T!Ute;5IlKJEHmbL)#f-6U5j?h@V}Kz@g&$$-hqj z*Wb}6$~k0;*)4Jfu=@7@xIYU>&9$_pG}G?STAxr%n}a`>?0A?ITeVYi_tios#@iFw z{;(=`yg3hZnW(s}ZC;=BftJN?usBZL#Mj&&S;f_YE9fiZ#LxU4Ow`;5u03D{Y`)Y9 z!@y>BQ1Fv3aamLSpy!b_BV8cht@0PXtde_yH&3EvID9g*xjvk18dXs;%u;V^Kt7*Wigd{qoJskntzrBj^r0-)(hWSQ+c} z`K3hkc4^bsV*|lVwbr7*RW0X)yVjCLs?`lXdR0F@DD+?Oa$~3&>Jy-*<(@3F)NR3{ zdB%Dg+0N9l8Q?g8g=6oBlIe`f3{7YJ(84rF>wGN2hSDc10|_~7^!A>fD*YmG`$Ip& z`?!ExnP~W9LXgrJ#=!%;+8T_(xHWc9|GwYJR1R@-q=&+rWlxoMI%FODPbBv8La+G3(mVlc)RJ(b+~O(y{@6T1+1gfO-{Oq8K^E4o#e^lo%q z@9hp&gBn)rQw;_nkkl)?_H5VmcFgo0O=DFZf@;@R8;Li!W}OmL0>NnPWV~%XB+@< z)^7jJ=>7EfNUa$;NoV42j23V0mt_30=HJ<^_t>+h)^2Ti{n}IAC-cea0+EsL8O48v zW)$}p^pO*58Wh8xQNjGg@%N2`J>y%$sZ3`EDIrFmt6NqRd5aj82RGiXtqLIcCe0Y> z+G|mB$8#AOKS11;e%(f1Yx5N8p!#D?8av`~zI0MmXMy0}XEv&_CtpKIta041vF!t7 z2=vv|bmN=gOY%_ij9h{dyuqi*B@9}7*Bw7+^sRv#_G3}cep*~x(!0og^=5z41C(D6 zg_t91DUFijt~^t+sMj!KEOR3_kLx5*P;Vesb6iqF87o$|CieW(L(lL z9J1sNPLc=4$0{2Kfj)wuW}0YP=eYtT-@D0##YCeB8>-6}`2PjcAZgMqLagt2fvVd^ zP^uhGlEgsxbl@AesrJRhyI<^3YgM#7smv_w9z7BCN7w*E{S*mbN#n=mA58Uy9%6&) zDXn19E^t^lc(M$ck_)Ao9^eV^0dS<!Ca|2D`LWbxK_A0s`j4lW8xm91a^imK zb${(F_#xVVhb+~iGGk(LFyDc8?dSk%3)0un7uRi%LOZNZLaNG=fy8PfZEa}mJYAbw z>blm|^}u<)&C{@9V=_+EqD5cWxI$1MFW>_a-%IwcFd5v8^fD^9vRqvipHkaEHKtdX zHILDC=U=)&#R539pst40-}nB&MZGt2*Sqkd^ZAe)cjd+3CRwI4i+nk@afw(t~69u{YA^IubHCS-VCO`3u>OBfl>< zT@HztzA^Mw;uinkUoGUXZnV^y&!ymxyis^QE<4pUWN5&Ce{WVIHIsYfV!emm%zp-R zfrGu09gCUJC@VV#p)U=8*NsAxZMoH2K;1Z~LXO%plkYt6g&CijpUb$8rXMlNrcb$6 z0^P}fN6@LheY>6Gqvi!}JpPK({?c=*GgMdq6|ZVv-#WNAF=9=SoeU@fRHWExm05>v zirEsglK!WH7fZU2N3EPQzG%%DX4u#%9MQlg&KGbg-wd#GEtck>XI2mv>QBH@583N= z-cL%jWLFrF?gA%e+EOLNF1(hii(48CxCegMSun>sqdA%@CM3bJ75t()xO9!R+6pzh z$yDtb4&F=B874`;{H0N>m3^bT=Ucd$tXsy1)Q=O+0$;Jv85wz&|JjB8ze^(Cva@cA zeyMygkhbu3Mw$BdeLqZ!zctj@Z+p%?=f|B>)H?<&0O!m?o_Y=+jUa#TBi@)cwsS&ld0} zRq9If#wzKT6VCu~nYdzuqBT`{_T_TpN@3vDm!ny&afhKohaodb$0JeHq2IP*-+KYl zL%*H58y(siymb!4yF*emW{vKAspW==F%r#MI$WMD73Ph`;z}4!kfI09y>~xrlO_oB z^K$_w^oM6sdZW2AWy@f?CIn$6I>8Myw0z3|dXgpW#-Gej;%DlCB@>B6)z-1`7M~4a z#aM-^XYCd+$F=1?JurQ;GL$h9(1i4rV%o8(opbMko*a+%a*A*%_@vNt$o5ItstJs5 z3=z8!{{#Zk|HQ|lJX4P1a1=|GO*@T_AXT=nsM5VjByvF(qERByWW+D7qgn0JMMHnOkSeWbh&^LpOs zKGt_!_4#?{+02tQ=KdTNlt-La0qd4dPV4%?7ZT(xD!k|2iTGHpk?X}n%lktdcXpp{ zjA2#bhVY~xIa1(aEwbfQmE}?+o3GeHzM3Xzd()$X)johwDK{9~QM~Cqm@bi=qv&^B zX&axh{j)7lGgB7Jn0e>7NiRlskC^*BZRBJDZs6E2HxsazA34>Z-!8$j%z6w(qCJ}E z*}UG|b$d@#2&t&B_}t~eC8G}@Q)fHQP#JqU~FHtk~M2Wo=L#drw2u z6I=vC(sU25`*V+f-cYt2VaoQeuz(A%pgfHBM`8b5cev0=yN;^A<@PU|C^c=>Qd0@p zylqI2c5weEAEyF%qAa_m4O~Q2&T_X4&`Lo z?GdoIZaLd+)!>t9isCNL6rPaH^wz=uS_uPA?U*KeZvB9pJ z9ePmUEAQP@Q}fhJ&f{f#8X@FWUiC0rK!I zw~$0TvCOc_qWMQ#N3m}5xGpK`io?J`Hgc{>$h)gh#Dqw)LY2V#PhJRJph6Q zJX3-3;fY^7OybIas&9JtXmq!5iPmYJ1BZ0-6*S)GQW6$s780jFEoz@Yln2uJrw5C) zQv=i7QW(_B*Z9K0_D412u4146Re}@};F1W{%G{Ek^*C`Z$-99A z?bft2V6$yvOMeo-m{@Pj8Uy_Z`!SyJ!x!lm0lCEEZ@43);H8m{Llt@Qo8;Iij;)m8 zZF54g%JFXKa)tLWeL!VJY}K8r)FGOyN{1Nm%G`m(Zlxa`P41+Nu~Y0Lg@@1(z!FM_AkB%j4qw$FX(1|!#OLkgoZS&Lx< z+3~}liRG69u40_jPH8(JgS~!z>|7NeXbasRjcUgzxfClnsNjj^uN{PM`JXro5TGTZ zb@%ysFRKB3alyO(;{V}Z{`V&h+b~)dk$(7^1wW0nAjEp91Vhv{u6&l%qhQE&hH6ah z)UPyW|KEOPx2!r{2Paw?z0l93a+CfU_danh!O6HF$mJ z(}Y2b07dz61Ll{zl4VO2hQA9CF!bwzFYSwX*N20Jn|xMH*VeOlCfbqJ<|PsLXt3*_ zzTFdU8i!koSdS=Hw<+t>q#5#-w(l*!oUBWr#g`(dD$SRZ=tgiNCF6a1-`);VtRM!c zJ08QXlr@zxf)#1AC9uSEKl`yOHYX&v=Exc zZ?lS3UzZ+ZPt_3}9sR^)28U~l)bvHpQr%A8I;(xyF}Hh)QVn&XoGoV8xmhy?uW!9aSCyhxE73nlj+0G+O! zLZ=4flQzYuc=iF}yrnNpJu|bck*}_okMB;^TPYw-*2Z$fBn@}_j?1col=MM78%Xl2 zI-zEKHPUWAV|HjXB~-U$6XFY1@*_Tig37}mXkL>@%2b!g$D+BOzfn8cpgF50Q$;s< zj_NEm%y7|?q$lB9SsKJ4EGReu8Y$(C3xem$ji{_?fr5b&VDoY`T3!RoUT7u!`bB$H zGdlY9eShzEe8>r#W52DgawT|DhV*7{NzHPt!F^o)1k3ZWdfJHBq0i=AFyrkEY5T0v zB`1TWpujAKrR>?-juGp6Eog0=3|3bN=z1w#ty8rH#cMd=^X3O7x2!`w}{9v_EitYLC zgxZ}0rap^|k#!GCLq2Bb#T0skYzzggo>y-_ER?@K)f(jW1%DDU;qNuw&6-hgLW(Z0 zN>jv;)49pLd%b-V@X(W0ut-3mY?IH%Rr&qhZ^Yc=`EnBv{Eu~`$MX}o9|pR8OfXV! zqle5#cdxdi6Ao-#R0Pe@K{o5ayB4_4yhVxoHBP17%P8##7fau|-^hZHLl9|>TS@-_ zOp;c|IQ;QoS{5w;3;HsBz@ta&N`enJ(pv;>8#UfP$8gv2ec;1S^1sm{;>pz=CtaMA zn?QUGfF9)1a=@*s{k9iwgX!6}{Kr>6c18`FV?sVc-4Pq-@rxvX=k@aNW?EZ zSLa(8?>xxqm=*y0wwVonE1G`q!4Vc0-Qy>ghj3~7ey^G%^hqqosOCd;>YHlRJvE~T ziKB$X9cf?Osu-FZeX-@D2Obw||khCelcI+$HGNtDmW?l8cva6Q&OwkDBH zL9*)86YEvT#xJX-PiHk3*z#d3g|FW~xG}zQLjEF$O5%gDS5<3|C=xEQskm3@KE;Zk zY!(WQ)!6WXhJd3-yozU&yKikBaggDqa<5b3d11J~l7P;XO`seo zA!{~Q#v_d3H%0chiM;oBp;bGQRinEl-uDkPS8V358>jKVcI z>9TA3XLu*S!MS(*YZ#Wxx3%+(X3XcIloqfRWW^qYB9;TVcb^Q-bD_cVz6M5_e|{)J zv5H&5tEY99_wLO@Qczm9kFZJ#5c17=?_^pTIPY-$_AE38zIiOS5M&aHtg(veU4n#H zUp{kwfQ~z}Jova1;x!mYrsORG%KS7Ak9H#o$*p&t3etAs)eDn% zTua&6CuNQWzrpl-SlOc0avJGik6?=aeJPeF3N_vkJ;uPrNLA5O@}@|9_TN;DAnFrt z1w)3roWV%0!TgZRT_~g)A zM#2m*)sYYy+#%g$1|ej;>4q-$d%e@|vuu)1ALUIuz*m*nWrI-`KyB=<^Qn&=08hl1U zPr&PlcY-QB#w`8kgwf86N5~TEU@`RjP2e;7yvjk5dkQB|g|NvTvC0F0WvD*{qpLz_ z`w)zFKCM{gPfGcStEsF?w2ebVzpe{sg-&T8I=O(9;k=Ib3b%yi&|=zeK>`2^EEE0l zEckX0%3-(fx}e9_UR{+m~H=d|axDQ`X15 zerw;rw(-U}xt9&W=^o=FRW${$eIEwz`qY~M4VdY^t8Ab6=F1bOTlLhIg2vXjHE4R(NMa_?@ zaW3|guE3uHx3b^rqS7eeF6KT<+=3jI$`5x5~XG0{O zB7V1>^q4EW%zvPcF6t5%rYc15FE7Cc#&wmeO3W#e)iKBlQ?aPSollNAo~zUQ>rA>E zAN8YT#VTS5Z}XsJHTeym5~?k2c-!JA0;eL#YU!03QW}oVlzytJ4pO}j&C^3%_~NWL zlWeHeE^sV-{W)*SV&cidukrP}GCy5`f@NN+Qbx;O+{9{ky)%l!w`Te369bE{3(5?q zg`JnP9%M!J3 znD`!ebB2S#my`{!iC>t@?ke|)O(}TGCB_uORSh}1OUGTgI65fN&dUgTRo!gbfvX!< zHsKE3x;WhySjRc>r2y5Y5f0V~-Z05DJ?Z*gNT45+%#Z%9 z8VcRR3T{l7r~k-N1ixhjSxCHCc>3%`y<2re3tAwE#>~IU(;%lMP+CRBdZs}X!8Y1H zXS()50H$=(wD1;t{_DdNEbCP=$8X&IRc|Yblo2KoF+16mmSxodkcbW$zYaf=C@J*KM={QS( z6<*qLGL`l6Nxdpu7~I${Ep)1`AnsdCH*c}7brr6E@M&)EAP$r-S3!0rZPNTIvuJ`# zU%ULFD3J?41Ww6^bQY8ul}ERnH>~E1;^c2WSlhHASUWI2Q1stP8CF;Q9;|j%Nq_cf zCm)My&_?8%nk8h`TG+>H(9OTkuV9ULk}eUi4|>g@9Q^K-X*xOFa@U!{xIkhI?+6Ki zxd|g3E6t9%W8;KF&?99$Q3M3MSjA^Q^@A;B6MkiqFz(zFaRDHN%!_e9fkSk_XzTdi z^>>&uwTvlu-46)Xy@TUg2LX1RoIaB~ea$w6{8;?nNJlyf_~li99&8OY_9t}-QU*Ey z5q8e?`Jl6DG2dnQUr1acZLRV@wK4%yzIXAmvR9Ig0sxuHP9am;zd|N;05W}Gv>ReX z_7n!ctT+7ld9?09rMM&2?{^-%rGZN)@%GJxJluf2iAB*lQQ?nv?SOsP9-X&ypAE)9 zU-96#20e(mRPMtuw*n4lF`-ZDR)l=t1H8{En{f58!`KP%L*E;p%;oIByF(H8+at?MH99zOdx zBLB%!M3D|`uuz@Abc7AE3+CoH^PKCfY`B`R#Vv=Q8XX+J`D|x~Z>#hl&FS94U;@WJ zY5EtKzog_Y8xD2R^W3(&t#G^Pq`0-nX6fsFGXnQc^9C)UFonyXmP^dM-RxTGrL+%b zVo$!QwI?KAk(GR)k=YaQo`DOlnuMkodg=j=)`q&V_5&_!OnDWzTuCy39he+ax4nW= zjtxfo-i?nimsrURnW1oBAA0@nPCucBou^l}SO~#9oL~BJ0~(YSlNMMF@LXCMhf$tZ zqKVhE*^gJj>`Et|hxayq!IKv#e3TFkD-udGzEcRL6Bl-_)i>RvgYsBcACy?e{dg!H zJ#T>BhX-vMf;hJ4TTMpv!wMrcO*C|LsJV`tkI*7Mx}R2qRuJi|N@ndrh$~b-5~S2W zTZrUDiG=&f)zH|GOmr7ykLHxax7Ac-K9^KxOpF7<+{kM)UuH_yWGOzo|GzL-1qunkU6V_ z)XTTA6GQQ0*|HM{L(VJnPmkvrRWy<3TKg3};!+enI*NWYOupgQ&Kf9GDc;By8rn8z zHI!Sm48+QuQWax0dVFxB^0bhoHnZXv-A{V*qV*WLsa>U9r?0E?PErBPl6wR=m>jhE zt`9!-tgMlZ-ze)aJ(|WR@dJC0V}d7B;N!$A%ECX=iQ9vABX3P>9fz2wn}a_v?<_2u zoaq9Ga0V6XuLyhX8Ogn6R(_Jcm}s!>v=<&IY4byn&%#g-eb~}pkiBG(FPyNxNnljLTL5(^FDe*YWZ~Og6c6;t zlv;iln?E9X9_S~5btJolDcE;4o6ft5WFCP zY*{xiGoxa%j5$N8wRJlgO{aGz@IVIOuf~ct!vHoxS{|U~0PI{9{`?)OZhXa|frybAV_W7kNT8l<<+r8&=l=iYS3-cr-M$_J zAl5P3Q^cz9FNhV$uB|3o38~gOu5&3(0{r&21>~~;Em1iA9&`P7!F{sS;q^|w?#0%y zy91pCw?(E-S?^Nr57)%|=ohUOgr4rMe-_9~8y~r+NzPK%*10!DIj>H5J25_yUTIb$ zkgZE2=TRXd5m1;rSCzZSEgCRUs%M+2gspzvSuj}L_QV}Q(m@TSlwHQ-@%cyPR`T-G zL00t;CE6*6pk896YBVhn;O3}c$3*S;h?{i}WC}js*8k8UQh1h0S$L4y7UA;Gm^sY7C&|7mi4;E->FyZAb=GNF(Yp*$^2E{ly2}?-m;$9Xyl)ff~ z-xi4tWng=8B)DvDgL+N7QSLj^v3nD4T9@YG2QZ$&hnrm|3(n?- z5e={3=M6rs=1V*IltaJC>AsZ#m=m|6r(Iw;w~`l=LM^R>i5u^vIroj!?8D?ISjH3} zk;Pgi#x9&Th#o)w%{&wVG(BaK&__hv&FfluL1f!yZ|pvcpms7eY-8GrBie z1Ox2e`Wv%-Dj-84@|Ea&^ZxVPHoJXuVYCdSrDcPa`tgwjD+J>d!msSkNM=c%+3Ja< zSaxebvsKU5s3GV&Crw@6-{SR6n zeOyeOUP=^pjp3)SC{I=7gkdgr(k230N&KD2r$g7o%x?ptqXboQC%RXOYL5056k{B_ za^+tV&HvJV@>&2v_4mMM?z0ze#r%zoYAJU}JLMw^qWyMM`4X>=Zj;X>czFa5_a)IY zai z>((Sv0P)4Zhv~ZI^@8}C$uggmMLpGP{5LN*0D>>r2&zWNz+J5iY@c1;j7*!Vq6htT{q$ncIl#qCR-igTK-1SKzT42P z)(-Ci>hO)>*LPC-7|we3^Qj9O*S=&0B+dVHNoN7|9eahvU^TrD29W`}98AC*ns(pKsZ?jFwI}N8Zv)`Hdqy^zlc?QXa5odKC@2f0TjS(sOe1 zRIHUmzlqeua2FA3FeqnYzNUCG1QUA4X`Jr-i+oAm+s)qD~?xV%~2zN_8HaO|!ildD{n`(T(Z z%;(DDft;n80x{^SvastKfDOABfkA`X?K~ZWKfX{@;bVi$d-i4R3_dMZ27|GA$F0lD zhPwdLI=WLmZ&Gb`n{;yM^D;l0MFhPV<$Fe|KEIfn;BI5t%gM0P(!OwprmvpO`%oAV z9=W__vodXS`ULc1b%2N=0uAz$^Iw9v_3tfBt zrc6(6P@&E61A`KY9v$QXk6iZV?fBMZv};u|Q1WfK9|pD95{@JXOD_Tu{O4dP#sJL% z1d$*xLujU3>A-lc^TUp!2l$23wv^fYNIJW|k6|I3;wE`M(?R@cVU9CgZv6997Zve9WJGSJ`ikHH2I$v*-t@y3JC*MW?XdYTbd zfsDZAeCMl;oR&K8$JeA|j=Gj?<}EV;YV-7g+z!Y7s#L;5VENtGN4ggcJwS$KvKtaC zn>>Q@GUfxXX)%OUiLnDsLAeBZYM7*y6js|Gy|E6oWJODIg7e!Ge~2z>H_q{&cCY2x zvD~n?oOcZuf(am!p*NO!UpreCf5bBIb&guI(CmwgLQ`ST%Nc+J^7ukN$C!#!K7K~y zJ@E(vsOg!HH@^#=6zfbbjqmkxuJ|9UEPjjX+w^D`o0gZCbR2#uf6{lO-K}@&?E@*^ z!XQO<&w=-~_Jh|@WSY}r^Ey6WJUgoif^*;a)llTo&JN5%^mbl2d*k9Rp5v;)jKrhk z(ybfM8F}31YfW&Ss3*>y|A9<~sR-+;;G5*pkdA${>vDYS&M1n{y?w7m5+Mqw5eVMH`YWvO zZytMk9kG>xXGqnL4T>Kp7i+IXVZhE&B<~}}Oym;KvF*D14f~MuXoN+6`%r2*5zLb= zp+d1ZRULptxKT_M_BD(Gk^zMSk`VF(xL!f=)?D-WafpnT;p-p4GAn>m}X4NqKV@0J^52yY}xX1As+0>jy?L3p@Xcn!m#q_WCSm z=owRehZps;asci6K*nRn;2ZkY$74u%U5KOF^U?fT63?WxFT;B7!W+@c+Xvo# ziVmHHOuWH{4gH44>&sHZ>FU~9{r=X$w+(^lQRr}TMQ{ux?+~wX}G7(1pCIdI*s1sn(!E{ zEdnM4A6W~OZ}AiAM}K& zt}%)_O~Tyeu(r+;qYHX=AF+RMV88o`WH&jG8Z<}TY^UK#qmyWP1S@mhnwtY!>cFZO z>*wM(=UaGg@jy=^4dMD~)*j_F_ zBftp89X<>@W9U;d`uelFpf9opD4Q%fkKc;?5{UJ)Y*HtVQD%VstY3UYAaWv-KHvUl z%yn6V28e&=$?=P zZ9nwe(n`98U_m=!sT()4MiAZnH4=0jfofsUvVIQKAEHWr$x0UXsDDS^7V7#J`;!N0kg^ z@VSImX3HIEo18;h_(#mWS{iE4jhm4EGGgDOohoM)TKPjZ_eBSQX=O}LaN8^X4_D^q zx=$SXl694I$VA&{D|He}oa}*HETG%c;+HH>SuTHHdYhd**yd<&zY%regFiVk1Ua}G4%E@&au&GI{3F*;xRrLOWVoi= zOvAyD{{50PZ4#mkkY{3`$8gSxf+&WE_-nF&e`rwJ2s-$!WEeDg2@C3Md^r1>)_o|e zk$2HQ=4rcJ7HFl6+r|i1J7rRX5t~|>_)O>o=S83776tv1u}1$guMJ525Hi!RaKTY$ zjVtUK?e{-K&cXd!w|{4#AmA9`$l{3$VLmLU2D<;h40O+nP$uve_y4f>)&Wsxd*iT< zpo9uYDiVscFdzy@8wdi@ouVL0iZl!Z2#A7&gs8Njgp_m-f{2842na)W_b|bGzPNku z{XMVj-reVU@9&TI`D@tS@1FBHpU!g@JLQlG7jJ^ZOmNJLvdar?*C;wAsnb*6f@*H> z1=EC8vSbglQ(|2u2OkDJXA-}0#Iez!Ud&{$wCxlN`pPPo)hEPq4P3@l zM8>{!yk6~He_+f-XD-9aPF#UND&JhDNuwD_rn&!_Rg2Y;hA2P}3Hyk{sUCcN@X+De zFkGuNfz_bMx*dyLs#P&dw8!H*L(xrj^s!Sq%yUomy@so=ZPdcDpI%SFYMTjw2)9<@jv7#@3^J(2DT-@)+EtFRn+eQ%lu+q=U9h zu1gUvW`f*CYUb8?u4$@V8!X=ndsArHSaI3GQO0X&sIm&9dRpOx(dpt#WLqxTUWBlLFsE> z)8#Wx%ZiAsu#sz^lDUmK@F^Kjhr9*|Q~yammROW9dX#x;u)WIuu!RdW{rnUbn{dtV zj-WIkCGs@45YX=CZ!YlD-uygO--Wt2*G2%{Y#g&H85R6x;}=S|2uIjK?ntcQ!3&=5 zx6Hsevie+)O`z7)a^8QA>i~?Io)s~^a`>$)39D*0aOjSlMZR+OHhpAB1OTdu&5diT zB2BiahX7JN*wT8%?bXTa-pgu~vFBoCr@2TO`98^pY)#dtvnfY&CLoo2-M>@$nh#Z! zlF~hGS=3Td1YV|M6pz+8erxE(fNhna7~?%&09z4kMM^rA?;YEW!@44!)2;rF`$YAHI83n+yI9jG@kd_`SE-7jLgKFYN7(R z^0;bvGlyg3xnmO_?|d0u8^ec6MVW&>Wv>L!8-TX&tPBe+wMs!gcf6x1C-V98qrVrd zCErsS+v^uuv$x{5WM@Fr$>KtqVttXit}5lw7hT9b`OZlhv?f%tPsp|x%gLOB`GLX8 zyG9^7Pl1r@`KQQzd|)J*GEAa^B#DheB&0rwZlN_43L(Lu5TcNuoBPGvnyU>h4J)^R zyriENvQC@-@v&Bf@8l8CA80a!9lnby`#mkpe%Fah2u9)x=~jzSt7W8r3X&+4Y?p{8$oV??^+Vux&oW;#z_Utb;wcJ)xUafoF?`3)6$70%b{!=v$t z#`M*${MNbG;?CC5oGe~S#$Fp2xb$H+O9@TrfE3CnoPJVK%wJF<}n{i<->Sf|-KrnCAfhh|w ziZ3;Q`Dv<*&i0&hj3n9U>gP;gN$-yDIt&bw9601`0sAHBQh;CcCo3(;e!jc&L7kIG zT?Y!v2RP;^I-_`WsAwhBb3o%kLkrWuY0Ix>aPo6=D^ung@TlO;4RtG3IuT-OrX~@o;l+YLrXU$Lt^tNo2IAJxXB&BHKL8H+IGzCdL^c~t}KuOU05 zZHzS)1H=7djx%SPqQ?&})cxL$k%wGR0JFYEz1jL3Z#v#O9g)n2-K?m94;PNLV(&C) zUF{bs?GNfW>n*cG@(`(xtHt?C(GL0oeHtJ;4pi=@>qbSP#+u2Sd1WXHC(+e(NiPia{5tFiVFiI zq_I>A)$(6{QGCj;?L~1v8?8d^lpIgNStpqTKAJQDe}P#Falhsth_U32d}KzF2g{us zd0Qo3l|{Y32Xy1by;OQ5ue6fEHMxwmp7`hUvO1DXpohB4YV^BWmG_HT?({3k_uR!s z*uD*8P!*4GZp=J4$>p&e4{Ft{!K!Y6b-2-=NwZi-lKob(&dSqYCvm7y3 z!Om~F00IMFS(E(%0!PnMav=&H63$~5^IgXByqq8Ztd&bV3R|h6=(N2mmvPFb-zAFU zn?X}H(}4Nx_($X=HpF=S2!;xN+ACg8VHDO;1!74`!bofHiOcH1+8}UxjWm*hkZQb3Yt? zN}ggq5HgvD+?@!3n@x71@$Us8Y<*S)iow_Mtk}aCphNmT2A<(Qx{ib@Dp-&jd`+bzr%G6g6q*+@OucgEKKkN)vy7()U^ltJ=G-xS56EwAb4lHj zo92>gnW>_elJ3BhBoct~)&k6DY;&^Fe_xCpfF+T1eL$-!OU2xcIFX-u#lN!GUMSHvnCy}OasuU>iMR=R#x8JG~i#iN_PwbS;F$Aweq#oF6qSzgr%ce62s2(=`?SEAh;XKI8QU&h%Y(-?BT2#FNX(~Gmma)V5ik(8i~Q~02Nel! zFq`U_X?I%v$cx#+v<%a?#-$FaO*@x(7wYw^SIUlDjN~80PPoHF z>|1^mds4%T+-=aC*z`^p(R@9+H=%;ht=vVCFjOh#O;gAun|lVni`D90eT11`V4Pc1 zB>L8z0pVGn^e3L}kZ>bwKf5XL6_de+;Snk;y9x>S=^0uMN6L zmLnK%d?d8OdAE}1+`^nyM(*Kd@}O_UCy-KsxrZNP*e|+jCg0H|HzwD5JqO${YdYOunkE#VEUR@} zcFW?`a)ttqMj``_x7W_XbJkr`s&MXtjw#P85I8j{c1l7M0rP3YbNgi`(99&)HK28N zhAR1c;fvogt%fbSA4)$@@DQ3iwXJvQ2gTUbP;=Q~r1r6`+U-)2{A`~Dty;VQ^6z~r zo*x@a_Gpv6_a?Zx$&)>kH1edT~7 z_@duw_SC23z%tHgNw@M&G1nA*k=SLmgoD>)_4thi4777})fcZ^olY}+>j%G$5*(dV z8REu^j3y1gh~C9#9A1amuqpT%=`N?-K}Zkr0cl;s%n_=WSEq6^f_s~K-+91i2JKW& zZm&ptaVpY(g9}N%pgzouj65oCyW8nlK`F8NXj;B7sy7teNk%|%VW*DtZjBh^aX^mz zt%F$1>p73DGDDV<|1O699Ph_3&&$t&ZL2pGn zGaUDuZPLzm${Xm)^<+-HA&2zqko}nF5*aP+rDaoLT$Pz=J=2vHus-W?|0E*EKeU2Q;t}X((-Sp8GU1I* zwq93S-dT~u)JXHpC$Jcz1MC{!KuY2wv{3fa;M^n6;r~J2+Xu5BjHV6@&Z%iT7uijO zqLFIOOa0u&WxK|-A)6bQ)N~JR``1kxkV>=2>K^(8U7^$XwK*~~^L#_|*DhLKe(skb z(Z|irfBeJSc0(wCUIDaea8G6Lfpq=KC)wJIKW6g4koW~H>yC=Tf(K}=&H081ZfYct z5LygaOs(31+Rd@0%HH^h(eM-8!UP-F5p+Pu+A7KVHGPd3VYC9lx#NvmvRN;v--9_Oy=XTOIjoMO-!i$FL|5jT31Ca zuc`T6qHKmIeM-)?q)v^Rmsa8&{gMQlNO)p3|HWxZyEgsx#g_=7iibG26CAQ+ve@_X z*VK;zXZ`4vi(k)oelQz&xp`xz@p*dbG$1PShN7bT*E9Bam=D0De1`Cco4jiSuwPPf!Z$dA zvF#!)kh@5!2!*j_#yh6{%u=Uz*L2FdoG9*d8I^6d*8*!EUQ_efyYRC0G^zUz6mfj% zLZ6N%FS$TXeRlZW82rou?kbIbkvhg#v%rh)AOl`>|9i!m#~zmuk<(DUH&SXoBKr{n zdCn+8?KVI?H9-A?jyBEx!$_ZtRQJ*8F{kmN`G`Uz0hcGwcSb$YqK6=cJP*Z^)9wo( zmXuOIlk8-r^A)%tPU+$x_C0p$QiP3x@QlohYg*SgT)T4B9Mme$UiOcO?J;-1Lsa36 zW5036X-fh7-gZD;2!LV>Kxr66rW?A$pM;(`DRI^@vQf_CQ4jF?$E`&af)Bvb;lQ=s z7c6?UiY|(GE8Xe}1;sS7(;Q6~C>> zH1oO3Z}Zl3aSvJGHZ+1r%`l#Fjhb)x-Ll%*$8vrlCp?Mryf_a^NynPKf}+NA+91Td zgYSdxAKQ=nuA2;(iLObbz<7e!j2I}Ry%A)d=K29PWsJoXMukK|dX#4EjCj=0A6 zDmD{lEKLaS2C0+(H*Q3TD^5s(dkX<>L_*~hwEiM)K+=i~9dZeX)ddIwWW#E$4mRJ$0FPw<(>9wu#Wwj*ID(f%K{CKge^|QtbN~sc$+C~E&9AV(7m-QZl^EZz`$hC3(U! zM%b>(F-s0}Y0Cg6gXIZOfgR*afPV86IY|7=u<+-JeYgN=121sJfM7BVQWB~wwFQTc zMvR@UUZJO-^jiRI%^)cbdBcx^k~-d4t3*MbqQ4FJD1bsZkWSURHS}jnH)!6s`Xz~OrcY9Oi@5=Yle(m{p!3wNt09T0; z%}OvIGYS?eF@?vz&(9wI|9-m@K4!e`ucTX>iVVCcbwm@3{gET_1^gMG(7yM+uQ`_ohlV)O6h}E*o?|Y z$Y%+X9#HP^F)85L_q7#fG|TRQXVoq+YeilTJCMNQqxtFyq=$`x9v&U=KC!PB2FBA7 z$c1cgL>4gA(~xP(1j(Q~>BhjS)U?FdrOrj7ed%rHbF2~);;Nf=A zT8NcYzx|ZaL_Luz9U8Vy0lXe*t<7Uj;>w4(KK-=zLN`!S@`ZHoq(DxW2dFWPckJm$ z{=hc90(ej&9Rl`X2*Su`#!EK*a!f86=pRlWbQ;!YsLg9Lw2+-AuYi`pjTqr5X2~7J zT8@`(FFu;Gxtz1BydEmoF0k1sT(VNf%Xj56q+Di>T@M;h2H^P z{qP(_n<0>(p8w{Yq`AMnWTmVE(!RW)3tXhL)U2*FpY4XjlHc9JDx1IL;^BH(^A>lZ z^R>5339L_#_8c!~e)BB*joJHK*+#1k;_&F#^?u{D!(XDuZNwFTiB9JO+N^LOx}Uvj z3ef7be>yOkav4SEH?AJ=F#`pO*m*vA%pZBQP?mRZ5C+Pus!`6w#-2WDx$drsx{}PQ zC`j(}og^(jglvsGB{5M(3WF%;%68)Ygk%5u%Pd% zKV73e4J_!x6w||iIAKtglXSvj>W^@82xwVB8S@C>JcI-EJbDE(imU;rol^=d2a;mh zUkA&q69oo$si|G58fQ#OZf-u0xj#RbgW*Pgel3YZf#Ex%8csi=j> zv&{Nd0SU;nZ7%?2k6mwgujO03dHnc~1SygT2oh=dH{c&w0kF=5U$W~{)-RmnI(AAV zsxgW;poA{y3}sn$yrdf_!RYIK6xDHOev}5%k_tEOy{D3B1byn;cGHY^Znly?91EI? zc?ttHm^YB~-1$VM)3Tlya5L8}irkAIgcDdE^bBi)cI0pXnM21#T4KmG`?ZbVn+{<9 zIUPXh1RygF)6US>$`i`lcysb(U>H5@1u2cfi}8i;BLiQbu4Q*6u{j~qhub}JBw*d?Zx$4?Vu|m73&9-6ty^QeP5`S_*dNgkbjd7~FOMrq;rIiZ zsqz3JXZuaaxztwY>3vvX7KYniVh=Sza2#H|yJZ&k?sb$k?8kPvHQx<4AcjUnAlgw> z)KK{#lL?7WX5-P+GN4=1hibYg01~tS67q^pPyE4%#6eDQa^(w3av=8yIR%9R19GfK zee&U@L-Z1j0`3y0Fr#-(t^Ktscz{m(Ep0vn8U4Xf@AWLN0*EghL?Wb>(1 zQpr@$K~CP#)kpxtKDa*!y8D4=$NOa!uqYn@p*`G8oaDONa0RdJ%jV}t)g+k#s^@k+ z&jlJ-Xgs3>B6_{}02V5wz##W+zNTxP@~JkY-Q7>ayE;s~TPZ-j6xuBZAbV3mQT6!# zds9Ar38dow%{(R|%7?r_VzU^U*eH+q1Z7v)$%e;#AR5pX%8AeyOLsnh=fc&b3XiXI0atARgGu(u+qNX|Z-adJ87 zu(jc8w(h>Zsa1_O*n_O<3ZfYcX2D$1Hq4w%o-ZOt$fs3iI{EQncwgV;jzl$~bOTfphz(_-BAv&oGq^RS+&rQ^=+jOiuhSAS z^JJ&&2M?KR>3Zeynjeg7bwa_V;C-bIF=`1CeT8=oI=a}yHaJZPx4W{+BoMoU7m)L> zWP(21ym4y=SCW?Wr&@-B+qoN*llffFgq?>ylaS^NqMA@*@!5H zcr85q&Y0LG4HbSt^&4UrQFci<973cuJGJPU5>K^GwpG|pQo#30T#_4RGt%>7 zLtTzl4M0ql!jaC=mSH0|bDJm(6fLaQ?`d+U%-R^DlzTGu`8#*F`BEnINPILY<-4Fn zafAIjc!A;c!gX#9jlBiBQndfz$iu|o$j0}H8@*-R$ui!E<%knnaM)v+7v{gkpt;!p_?HnX{mW;2ju0#W;DpIbs%GZ%XZbB`C zIqdx{=Bf0=r?Z1;*QR{0@^~fg@R@{LtyhFG-hVmuK3H_kuypeaxLCR+?!x>sk`!)I zYZgTbjbTSH&KB~KE*Ts71vr0?AVDPq@>ZN4uXl`KcV%LqS9 zZdIR3LCNmFRZZKk@bj;$zP9@AD+iZ$W7(pQ5j|7ofb%Dr$Ynqt7dWG=d=E;pgKp?E z!EY{hiX5=*t7tC~bSrP?m5sNsRZ@Pkddd2SCKmLxH$)&K;h*!L+I+NHa{YdR{hHJ% zOa9UUu9K8TmfoPaG#5PdxMKN{fph8wyTLrQ$(C(4 z(*(ip44vq50w%G7&=_>ZL(qME#ln0zvDUmx#H8`s)?n6$&TLP)(&-M~i6rcja0{_` zYz9Nb%w+JhF)sqo_yP;))2N&W73%9*IZ`Sv;Hq`M(5oC~pNOFHoQcM(e94Y4<*I+6y1MQ;kJYVdFP6EU zoN!5TmxkkGh6yN(&<|pA4yHLfubom5@2|Tq8E@u8RXmo8;L<93@P@*+V2$B_zIF;~ zx5MoLc7$kbkdg4m=m8xq|J71!)q&CNJ{iN1!)xGP=Cm8%^gGsf`^xEW-^^Z>X-h4) zQyg?J^gFjMb2TW8{kiK+Z=w_OS8vNaIf&wvD7yR2c0Po&#%f8d$GAs`>O2+m!k6k3 zY%u|@-{lW6_$@CZUC-xMC+hi89X{micfT#a`z`xMx!ngl7d!K36-FX+_Cj--TJg<0 zwti`unG#V`h~4ze1dmp9pI$`~AuYM)Zm2c6c(EM?s0otw4Th?3x1&n9mKo7Y6ol4Y zk5YS!V2kbT0QA(_$Mfp8Y!etA!|e+}{?GcD?yr`&MN%nE9KVuG$8J0L$mILx@=N72 z?dsn<^`U?9;Ax)lm(jPy-h}y5OT`MkLK4T>6m!xeY9$7 zMePK8E!vt4aEt92rfzd#F*VV)bLS%JUC3V&qS08Ed-@0(4cACoUi0q0z|b<&b?IZ2 zT*e8g<%UqlMX4gr^ZbhoKfX=KoM4m3VEGPpph_Num!Ut#UG2~icaavGojw+~G-PC2 zzbRKszz2<}PGuMN#aYb}ZVsyKj^2}RMAj`)VDQVjO-mD7wH5(7Bud7KuAVQ^IwHy# ztO#Q;K`Zou9XYb{RCh5(OJvUGQ;tsZjxcKWUM1i5hNUKYQfDx;m>6XoJUf8Ph}kF_ z?){+V8Drv0jSU-Q_cwQg<+<*(s&6@EdcQ5IvB^uv?1`&g zDy%BG^Hd|mPM8M&fuXHt1V_e7n-H@4p>UbY;2g3eLV1yfnQ0Iookzd5a4Tb3ewU}E z;OAHIgpmYhZi&V>gO0W0;x32QFljR1`L5pF*ikp!zGFH%{MA-$CUW`5)E51;8L^z6 zspjTuhK&e5OT-SQb(XGboq0=jN?F;(X>t1EhlHWG$@8(5E*E$nGF zae0rE$5cd<9E_xSPKz#=w93gUujQQ89a)aV2clV4u~(Ooo0>>CibX*4sT)*EeMQK&bb zBDm@7r6*Z&HA#8Wee}aZ2@W^6dLk-qsl|&PhLMucG3VRavv@n-L!#R(s%hziM-#>0VenrfeqX7n@ZYE_ z{k$DIiQabBQ$()K=~#`lzbUk;EpwWy>Az%EP9^HNt!mNU|LNg&TT;nWrL;mq-IY~F zbj~Y=in%O1GAWjB35|HKI)8Y+?yFaWm?>@*$>NK52K~=W#d=)%N|?i!<~u~cHIH3>NonZb6}oTz#K3zCTDjQE`~-0)Fvt0@<{Uq zB&=@P3B&Nb^!284=18mjU3bE6Ol!SB76CtLg1Q+c$&IDm!~2VtKky~x}L0xg^N!ex}Dab2<;rd!`tb3Sc~h(zLy zs?yQy^3CA;`sY-Cnu2H}r(4C-$>+xsVexr3oc4wvQ3l07=ofKA#ZRi7j9nv{mZJ=$ zx?O(Q*W1k!$mc5I&w0#dC2eCD>;pquM8}#RuB8%+Jjz6HJvjl8PVq^NcUox|^_Q#L zK6dJBG0M&0`^xvCEAT$KL}4GX?AF3#J3{-lWiKX#Upg}#d7bMEJbvK2lej4OP1e0>_2G% z7a7>>45-;cd16=BZrVK0=Mog(vcpX-`AKglOOtvyFCEWu?+cQ1ws=`5H%7x8=RDcR zG?#k(bnTPiddDRxbJI~7W^pUJw6Pt-wXnE&@LDbr2dirRRshZzDZSVgg%0ISHKHb- zEs+vwznQS#qxU|OB)TR)Vs&S@eTqoABrFZC2dC1)PWWp3*-x|1>TY+W_&=+IC3P=4 zM_!5MmN@0un|zaAC)mI-GI(TR3F+lJR0k(X*lp&lMR~2Enw*1iueAU@$f@O=aIp?> zl0Gl8&>P%tS^N+&oPxXE_K5KaBF5LHYhmb6k${PVjWo>WcCHPI$Rv;AINZ0U3K!(OWvHO6oZbK&F;le2O;``z6+le%z_Xmo z7U%N0q#CD`?OycM)a*R8R(XEIX>+(k{d=WV{puOA(3jlS=ePjdT)uMH=&X$Q0iQtV zOyigJ`?4FCniQBWDw|MaF-+2xoNZ>{Rnc1^ z@m0mzGI!eg+nkSR*VjZ}**&!_Fi}_MIU

FfR|cKLorW6%WGJFv996Rks&eN@b? zuO@jE_U$G;b0vOfD`2e!l{ipmCGNtvV>q=aYmUq=nVo&OV30k>yfga&KKI;3=k>i2 zdK2u=DnsGh6uPetNo!g8YXa9U%)|N zQ*x^I0-2H`!gy|!@}hEV-^)4>&z4Dv=qR=BD^y)TTPRCj-H}VIgjki)fXylwu$rDdP)y0eyoZw!5?FV2OMEa60l(+wzSy(+4xvft`~<6Wa5*z6dpc zxz_pTyOAN+2tvVUKiCI`N^Lfvj-@8J-P>L(#s@67Q+Tm14Yk$lL62^K&5|oUzA)`g zPs4mn<|FS(pR(-Mh6B?i5DA{M|MMi={}U$>qpzZ&pQJ6vF4zsxIZG5}m3X{wg_qC1 z$pzjICf0W+68_RaYTANP&qrN5?c#juciT1(3M&J1uc*=F1o7RIBY2jwQtYPPc9sc+ zbj92eHkC_FZ<90GO7-l(Gn)0uYYCW&7x-oq#CR%&|B=PPSm|TG3*HnEyyHIwFC6BC z1j+kx|k1vGIvv6~qblGif6G9AYlqb$ZQv4x2ap0^^5 zZq_rCqA`=btEu2b?A9qyqZlLPin<(a$ zM=-}Xdx1_fszsng)>7|E#{(lX^4P+-;0My)-lPQo!K)aDIK^ll7&=5)+zOa7!aZKb zv?4Cxup+zVNrP$0z}sm~1Q8w~b33iMl~7m78(6+t_px)Qce-i4L6GPPX_uQPa}OsL z5*1cYA2G;lS;b}~P+~l_1nWigpi@N*uE*_nDtR4nD#yFY7DWC0;3ez@D&eXd!0w(p zS=14iZ8g%=kQzV4SD~j1W+?T6zG1*Hm`K1~I-SQH$;+!LP`f^uZJ#3iB(Oq$l z;8HK$?)Xq+U!RbRtD^W(ei@f0)bn8XIgeDMF&2s=okvu5w<&6MZ1Ek{i(Oidkxuu% z*L?P2;`^vEqDFcypo>GbccZlEptv9;P)gSmvq3Oei9^Pco=36B-HLfn*5%}Bn-Ptq z-tXb)8FF2dSmg8dFc|~jM-*Pl`_g?MkSV#g*mBCEa+$qc=-cI~coyaJZUJxJ9Xe7Y z8MAbh;zzODxUTz>lH=4C>Qeh?GD6UB$fwTJqufRE)RwK1FM)k~0Oi~iD84d2_2$dn zkK5DiaD?;LMIA#Yr;<&+UZ-Lc&kb`^P{uo?vfFKkb8y)OmlmBw?rseUte5x%v$;%u z+-~Gc&_||@g`jDm2xMX^S-1$lp0td&Lsuc5)+C#gF_Mxs@9e~~`tXD2%e|`^VEF_> z7&>5)Nj=ErQ4~5lreYQQNIAqZpgJ?BbwO2#Y+s=>2STS25>iEVzu3Db*}1-V`V*eh{z3mX)Efy*WBXRW_^(p znQoQZj;)g0*nGAUy~NsE+=DIqxtG|QI5f5=(6bX6PRoLqw!^P2m#TQ3MJx&>%*QXH zt7ckjF6DT7Zl{V91aSluvbK%i%td0S&TB<+BzPCg(p&)eI?Vsswc1gCI2{d_S3UGMp0e9IoGFQRx`yLakd`ZV7@c8(R8bYR?1OL}qwGw(0= zEhJ&6SQ8lcj%tFnZa(m_JVf4RyumP8<`H{(I4{i8l+Ej|(D??2g4vRFB-4z@jlXX2fYHTzY3DoqBo)Q0|Hou=hh-uevtrs~io!l7$m+HoIpK>$NPe zx(1ZjJrDCKJ->W~Il|6mvMEGa@HGpJo3wd!C$__N!++0dWD^L2QX14B8yy;kzBVj* zT+&9rMCaI!Kiwn&AO2wGV><&JoL`>q4eM=Bd+N6-p+x=MKs@8@FJ(L-2jaJwv^DmOS;Jk{TL?j^GxA?Cp9uXs!bvez=^+u~*t*6}Ie`BzG z;j{~mlvgZfV-k-lz+vNIFP)KNGO)mnX{g1Lpy|Iyhc?wOJD#1h34{ zc$lB3oBI4dviI#>aT~bnq-@iz)zRd66FupL=lRiF7L0B&qed^ZPt&ZJ>8_{|UJi)6 zH0z1w(rnHTQH2aWRQjH4e^+#|0$D??s~bo}TeH5-K?%>U6;c7JllZ@O(q0^vzpKQDxNyIj!lT zCcD3Kz#tvvvq=j4|EgD~sC?d&0RLYhW!)j0=-lCj<68yvRfa2py}`t<=qHYreP~Y< ziFIyQL$+jYPrr^67mai6XuxDQhU%Ftf#@x~q*LwVnnkSry*wB3#+^5Cr3&DH)n$in zAT&5bfMr(L-W0JT7Z>xtizG=o2jN`dZZ|!oB3{K-7wiSIAH&gGF_D98C^+v#i7<&0 zcIU@ow!8ajQldBPfcNr8-xU+}p98#itNr539uoPZ`qYg+hh781*wb@Jb(K=L8O4di z%%wljvV6;!PNNqnAM3b0WlWiOHHAld0J)=D@c4!XXs%R9S9(r zO!ZwF^(VTFIRrFs_xDaEac;sOEML^W-4ErVqB^f3Q60&%Lcduu=o^lKY4Kmm2|$0F z5~KxAid1s69R^y!=IL9(0%f2D%EGc4+5oPfmkS8anY|uO77Gk{RGm3JT_DtY9B96- zhd)+0$IG$I`BG9H+@g(N#?u6p|ev1OaQ+g3A?gNM?}*64g$pCnPuBALlwY-GFc$}>}^~cCz{j; z(TZUJdRT)tj3MRJ>xT6Y&&W-br8d@c$3Du@Fx|RG<_Z}51nvFNjmv5ZgL{U9^x_II z9MU=(UAIY_vt+2jW{l?#aqg#A6@XM41~yy)PR13m8;xouyN@pL6Ebi2FYqC5ic7i6 zc~|4eN~But=7VFwaRgyi(s$Mi*nyE+Co)V(wU~?BH#%`A%7kav59*Opl3W>iq4zJ2 z;(5et*7wB_z(mA`37k)7vH)EKEQUX0rg`P)y`qT>$}ZH69!T*02YQkKzglgI2}|4v2W(ynaQK1MFV_ z9fEz%bKgUhL5ENr0{H}0SF_`k@~XgVzpcvgot@l-<2Sgk9PFJUz2nXcKdT1Ddid7&7 zmfgB`%54k)D-#PA7nRNe3kvXo#UC`dn?N%7E6tV2546BsxQj82h=%#~A)*sBVGQRO zB1xSaYNCIGRY|pa!|m~_p+JBghjYW&yCIKl(tzGksNN`58|l#7cWFOhr`W?zU-hom z1dHGD?~Xa~lsb&zGv?h;e@%23TZ$Jz#0T%WwTc@-4T&S5NDiwcx+QBnkZ>gNqb z|C*{mj1_@eC>xIhANb2nLc(%dcH zKgBTk#ttx2`PeS+?yT2Q;KM&~3p2qrbJpOu?2M7Ndlvp4{9%vY)RSn`X7o#y3Xk5F zWf2y4^r{2n-Y&OafjwV6$3x($$RJG;DuwoS)H|tx-f=G)dVRpB9mMcAu&z-ud>}EV z|J}kFTrT0RCAxHyoI9X9StwXQ(Wy2Yu10*C3mXy4!?*pVKdsZkU(g6(c%?pXo zoV1X7>5+tr-E80;=~ zj>NOzAC_@$EkgKcBLmdnt+`K0L{e~F28j-rIdynH>m{HH=z!gYCM9}N%x@hVaBW=)(=zL7TNYC!- zOcmaFPd0o^VXIiv3!8ujx1GVCeR|^5`|Yn93YdGNM4a~^>`a%wYe8?xy&pYwZmCu53|quCXM`CKcE27LtkGfY!&wiv7v$( zBOV79u_A}*ZCJVrc;{>rmgWtgXJs}B~DVaCb3ee6@1{cPxaC`5*{FT$n*AjNi%GqV3F#=OL&|E@RTZ_W5CoXFf;N z?6lNuE^g%HFN1mILDM9Sr=_{~lEgtxEKkuXWQDNv*NEzSZ=;!!tvN|FvVgTmaw`COY+>(3|$ZKj4A3!7SyV? zZ^*cay!o;e27f#HRpqKLLnY<*N)Yu^D;vV!`C&j6Zq$tpOz?Rk9iFW)V}hq%7F*_- zWckaH#}O|uin(m*>Y}QwUh^#){)pzYRv9yi>_s60L-)8YQ%g{=WM!w=kzN{$h!nA@ z!HK)qKH<#v3ZQVw@d(1w)qe7QK(h%R!JrHg1D@?jJGHFp5phr&_lYD##rWbHFCP;R zL<_urgvCTToO0HjbXk8gzf&w__Uw`NL(Ddz&WsEmvyA6Ju?UxIqv2H_7=y(gqq*X` zO~#7L+SAxBNMrC^N$oieCO5E|n>?s)zZ<9)yMk8B9N|wYNR&QJ0E%Cl!B%6E7HJ;& zgr(N59wE z&XJ09$V zoL>Ab8LO=^Q7l9l6HJ?PC=ELBwtp=K;z^?!PE^iUdVsG7T7_)&YvOkVTj)^sT_FVz z-X!1%^7D<><|`Y!(v9-Rq@JK}N9TE9qM}YAPNP2Yn{Tc1@?P2&Mfw^wE>7rZTQ1w< z4wpv`Hsxe?4UcUfbLK9OHqlG}RKLPFukH*-<*ECIj){DKH*btIe|MOr-Y!?MuM*d& za7-%X_l0MrTXsf~5g8uMsEj+jp;N^m9L(pyLIqIT{uQE0*~C{2hAszZ^UeAxC2iT4Q(?+44+d#*V3R(-s5SBMfu)IkRlh0cg|TV-MpAp{J$ z7(wl(m%9b5|6Du$LzRO+*7#HnO){77S55i0Q@?r#a{qdk;`Bb@Fc5Ebil7;Ucb8F7 z)(ZlEZB>x1-dh$VtS`~Q9*}cMD1daHNGh}{h>p{j7rZKLlrJ5Hl4E~raQ^X4HG-U` zm!4PR%@XGJI?+8)jJf}^zeP4NMFzOGV{^Ndgpr^GzP^6be}BonwF_=0mQ?AEsKvas zI{#k~J1D(9wcNLhOZp$h?Csu`g%QvX*IElI>+I-He;Huep8y-2wK`4IK@T_qR9hb& z2b^%_2GmZV@)z9p5lhe?Ux`UbT56ukVt`yhT1o?Po-Gu zd*z&3L-9j~zd|&CVLmFZY`C^-S9tZQ!#;;e{v@?QDuxdtKeQM5ULh!ZZM}}E-9oK> z!#&6f9c8R<{X0SU-wob>`~N@;A2b()25A-pFOwIYQ^lZD_aTxvEKnt89%{t|wRXxD z*T%jxhY<7aHlPF@XKIhGS|rZBbM*bA5<=a_pRJhVOOCseF|}yKv?QiepQTPDB!LAb z>QmA)`5*mRF`)0IM?2OIWPvDSX3gLq0q|ZJKJ9ml^GSY-o4&4Bm)gijxg!6#f#Lv3 z4`-((q^96ujmw6+qq;vMAb0dk{w~IMWRV3??4rXr0I1XQe~miQgpn=%Us4CO68c5N zJ3dNXo}OObCg9`BnSSdPN1h-HSmX89bk$cn>K?N=P|k_inPjYed1P^6P;$*?C75lh z93@#s^TjG7RgVQGBJ>8OXKz-%GUfM`sSC>WD`UeADPtH;} zoJq8;bbEnZQSk`RliOkeb0)F8KP6`+u1FH6y4{8)+_m3QN(iz$E%M(<+x*?M-&iq! zHoOX?9f;O9iBg;wGy3Y!{ zOWuGVfB7@>$5@Q_bR98=8>~FpvaaGqjIwzZ-a(&Fcxo3b{D19O$X)|9O(rU55(v?^ z53UzcZ{-W8_Jk^x|gi0@nCld&vC6s|XY$ELGcmv{;FK8xDT$ zTP7O8e0%7Nt^96W18*_|<*Xk39Qm!VI`{Li%kDRpfLok#6*U~?b8608Y|?+#0&3j; zzBB3^(vwC)DSs1$&1-B)T z1cTbDCMeOoJ9QHO#>(fyvrq5fo^Gkz)AT#BQky<4aiNP2Q^`^c;=iWdew$v@Ol;m6 zeRBL(F}UW%5TIrBU`Hi}hAReu9j?66PK&RT6Y(0}SswP3eyt*r3<`1o@P_{UkG2aw zd2>Mq!q&BCpe8_nIZ~o4^dvOI8RrfMh6cLF?^_r8C2{XZ%S3I|Eu1QCr({)ydYa1E zhH*rPNi=UA<)8V1nXX$zT$JhH|7(Q%MxRzzRf1s?hQWx`K_N0y;oQ2fOlY;}vrp{N zCQQbN30{w(iD%zpc00>!z=IK;e}gs72!IUMz2{1Bfa8B*JrO|$ZNz#zz%pH(oWtel zqi_BkqyI!d;Eb_sz!_g5&M1T0<(UpnaSF(=atNv-E*|Lmi+DIj_f*g1$FS*~*g-J4 z0^DU*k}{b@F3K2&isjX4|E6q&){0H7oZUP?w2#NmZ>uqE7@B=b6S3X`a8cO8c=T5(-IIw1fuZzO63*WQBiX8C=9m%u!h-ia9vP3f6|`$U!4^b@*xZ z#S^~t6(t&o^}K^FQtAjtq9MA!1~h2w_*fihB2|W!3Bao%dDuO$|e78M%!Cco#s^? z=+v*zQh|ERK&usjVfvttl#d?!;a0D9+Bk6*{2eq#`bX(nd+j2kYwE8uofy$QFw7Y8 z@iORQ`X zliC;b?47MxpE$ILNZC%KJgM>*V?pEFJ##@8(pN3c$*^hx+mU|b25M42G34{`sG>1Z)5r4e&wdA~oy#aj!Mu-?o0$&xvM1F|tiFliS}qtC@*x5pBJ7kzMy#qdX+l6PYd(JhCbs@0 zz5RdaxLMk?Jq~sO96Sp$E}AYxu?f{c;RE#YyWK1qrOjCY??JF^y!gJ?3h-~QetQcThZ)rS!FY-(#=?i@#GyL5HHkyPzt=6=;9$^z@;H;!X<=&#j`NuYB%pA+ zSDykte@%zaA^frVe{m#P^+3BrUQ)Z@Kh1Cy@%UC$!^Pjt!bNRXFisd;*J%$UdJ7OF zyYfKkwiqlO@(JEkn=C2(CSv!)tDoErAq8EHkG4>qEfV73A+RC?*MfTsZyqiWf68@g zI%K-EXf*Qa$Rep?sPqu`b$!c@<@Kn4;IG<{H1iEwx~pNyrD18xQk~)a@066eORW8E z2~Vi{_^}&6u}6_=0UymCdWyLO(6~|n6>&W7TA3ZAljjyJnf8a1>fmauuotBt)r!~j z99f$C7hNRdK@{&iBvg~08b{UQHR(|1A}ltWcFgqF=I&V!=(5aNfp1&grG)De{d5eg7*ppAe{MdXKtDDHdL9RP9eL??$ z8x=j!XE!oI{X0+vm6%-&RF(UCDJO&hEWz6b|CQtffM71r|-; zL)EM1J#>41O$y!PJo!YOw38{oS0B7-GE$ceLQ0T+5E%Ukm8f@rxi#QoayU4HB!@d< zY&HyS)w2b0l8lbJ-k#b;60g%HcEKx7T_lOiC_QkC}4GLYZD#U7-yhbaKZ#6F%#79_7Ji-N7V zJ<9=X)sqC~ln@IJl|OO+0s}*F-ii{~yWYHzKA0?|dW%#SqPzWxH*oxFD9WdsR*o;QFDjXI~HC+YAt#Z<`c$h@qwxOL+o_k=5)3r?L$iaW@q*aLnqy&=!s)YVb$^q-ZcS*#pAq3}#Z)n0x~pAzW*`X->qTNIj58GmidW!SrbB)=Yit zS^EQ|6MNqEb1p)`U!Sj>;GGV-jKyru!_L=B&8${<9s(1|pTcY;$sI}2#m*dox>Q=L z08azQiN}i3=VxvecO;csoZ9Dz)%P!IBh)9q&@{onoqMsCiA0H z>#SrwKgnnNvevJ%P9%9c44`2w27pA7pErHayHE<9`uz5HHCavtgY*RaZo3mCn)H~{R{T1frv$%;7lN2%Y%+vBWLt$pCkI(RD3R}U!$ zr{Z@G0FRj`9cZqbc(C(rpLfT;;x*d7Za)JT@|unYe85PbJ#)YuwSCI*N&SgM8PST7 z^E|G?1~iT;ZK{QHab_6v1Kt|b$-FsTVqrC2?@@D7$>s=+VhM}B4L-B3bH$j?C-w)3 zZ){$fx9})p`cvV)Iq7(P$O0VKCc5AE@in~7L*K1yb49PuW?b`MgJ{|Q(AN0h!lIm# zsyLoJEE>j_OAnW*7A1BW`?;M2 zyUM`07bzp0@Rr2dFEC;5%Un6OnW>Zd$y!)-JsyVSZ7fRS{kat4XkzjolqcJ zdtx!RPr6&kh@@xso|{FSR?Noko`@~Q4}Y`s-!$QVH(hbGwIw^V0Y42Vhy6aOIf=WN zL`=?=UJ2ti>rJgP1MeHn=oFk!ckMTnoDz1z*m`=dpPHSY`DL``N&EnL{mE(K{2Fri z3WHsqT9al#WzUx9<0Y#Bn6ss(@8cp9de|vf-o2CL_|sqLZ;Q(`5X`gyS$S>7Hw9D- z{zh&mllP*;9w>nK;-JF269U>#xSRx6zeCpt->`(v#9H#QG-Wk-bs?K3tPh+#d%~B| z8M&-YO|UK9C7Qjm*ShEBx53yQX3>HiT>Tq(Bz4_JLU4$vkNk`EDmcIVOSlQLRqi_< zQNEtSVW9`>^_2Re&e_^e%X#l`Gex}l9%8U=a*ge;p|R+(CieWpquRrvq%c~Oqb@{{ zf2Fo>Wx?`7Ui=D@o!86j@W@KSV`8(@16kGJa1p-!ruLllTH(z)=}ZftJ6rox78b0m zY<9kod*b%Qa{nP%`jh?xC+Cx!M+)61BrmVPBAq@-T?}!3(cQ)DY*w;?;m~^k06SlI zgGIi5JqcSzn_ppC0;cwK;k&ufj>J&#py9Fbq}9lWU5uuvF)J7>_5+`K`hdAIGb4Yw zJq$lM831UJ=f$t`PlwEFEvww8jGF?#b-?ftQyDmvl`RQAP509trTsuoC)Kyxw6pmo z@uYC&uV*5tpAhfaiJcGm{&6jKErM?`Ns%$VX59Ht!PL(l7e1GQ_17Ifm@nWBP(_-q z^GGUroi(1BoH>f@yDe@|_!$IrK?aw-1Io)QT*H(4eK&$HW_qm5=SU z&dz%AvI9=d(mP<>dlfy$@T7&b?!QN^5>EVm#kfJh&8G?$+wkdxrSCIYlg!a+{+1+X zlgWM9?+8>EbCiE!K%U>jM$RT!!J;5Q6f`XhuStTn(T~mxb2K6APRpH@9jBZ{|Div4f8rk>GX~LX7Vrjrh)3&he&R>b+8u#GIWI2%x;9UE-U*m8 zWN;EOptNrKyA*j-Vs%CQynWuH%-hcd2KN1XUE_wBKPKSV1UyVa{mN5IBQ4K(MN_w6 zte`sD)zkKlmf-MKd?W_8GK(u+f4LAS{;A_=KtoUedTjF@py`Sccc|16Px}^`RO9ko z3>Oa^!r&C`3jKwy3+WUh{*IcuW@OGPo&5u-`KE$8vXhc79;yC*l>-Gokxbeiw*(SO z%d@iw!{1K;Z__pwmh#3hmI4aS2Pa-Q3anR&gR%(k@$=Ie`|f}GycFcqR;@7CblxcS z+pBQf`f?bEC7?lUG%e#3VQ4m6@J~kxp^BdARba#lbMPdvjA|mV42CC*H>9)Iz%mLI zG|oQ|kaVGL8M(!y!RsWIJ?%dPo*+tN1;JiYd03j9ym1ejUN>i-_zyi$@Cvxt%YVB` zErHMrzZcUHRX3$sXrTN^URH`=pWvP#zh_@NFA=ZL0q;T7ugG5bSrI6!oW6#;&^3*J zXBP*PO)T8lP2-AO%-#YLK~K&G@4`Z*jF+jHr#Qe5n?H_@#0nAu=UJvG9+-2m@^Lg} z=?-en!hlK4mq&xu3qAaq3`U-U!GcLO?}gpP3Esun&@e5X#)6~i|NSP5x#J@T?Jx31 zQ?Y`sfM~w}3UW0ltX-aEgQTzrTmAHzIo4|lr60RA>#N8_~HL7B;J$Y_jCtE2R-uIy}@3PaZ9ZBDYWnk;i-7n z1E9YR3^cK41L<7y`{n^D1OKf>GtfrWmhd=RKJ!cgDtred0uD%B#R1)CAW7|e(H3tZ z73%(%3WW%PSg)v>Uzg5Sg(L}10O1h=9MnHh@DGrR=$6DO0FW*yxuytgKLvnhu{I4j zGRJ*rrA45!C3=vN)=Uv3#D>?8I2;0c}YCujtFyYfaF1%0mr{Q_TjbtXQDW_ zPk?4q+9M(S5gdNAfJ6s!o4=){UIr~~^uLx?4QZU}(IOx?2e7p22P2-|mw}us{w?PR zK+cJZ44?|*K>Zfk`Jj??{mmk7HmXQXp+e!57=QHSmEIG_}Y;*nCrAoL65+AT?ye1z}?hbf87DLzz9U(5cQtl z0s_|8*D<>h-%MeX_Q>-{uxUtmH*KZz@H?;2ap5Z_$S7oiQN$4htEp(PECHkV z_SiQbAnglS&X2)i53n3C9q;7ow&H3JmJ?O4*>4P%o!0=3(P%f;vGr zPY3UYTR+R%L-+tI6UK)uvkZH$3723W{Jf8# zJvay-dvvN(MzSKY_=IcR!#?1i?~ZF0LA|@9NjZ`lrvzB1_M3<^5dO{)f^Sc&Sg!*B z(EtE}lm`r^aERf9Cy+R(0fY}0%>TCYuT%eJ4)gTzoI}9Sn@)>l07?JiPkN~0z zQ1Cs`COzMgu-hU@=HQDKGIcAQ4T+qg+r5LFi50ZP@z`|}4Z z=^I#5woo)X>|Lij!cXD5$+xO7nnzp16d=oHS4R7H?Q2G}G9%wUS zQ9LF$x(*b(z0!a5GF6-)>dJ>*0rYC`Fq2n7nIxO)1kBygzQ%m(<@@kDq#e zS0Lp`)g3*N;&qo${_*!SvrE_%&Xhq@%${nxsd|}p>h2pw!HEu&+Wlv=VLEGj>a&G2 zVl|pn9#jM?tQ&*zfFzSdVX|;GOAp?DExd4#R4a zQ>5zHa3G@b#=>MLiDFsP0T1`dK~2PtGZn5h7Vax)EG9-7Ym0!N`~;VLWQy~ewz^D5 z@s1^vH)9Nfu?T9ju=X1p1H@WJr#_v>^_BzZGe?sVGF<8AdLZ1!DR-GWUT;b6%e=RvKv_tQ z&>zo|mqv&NVi6q1f-S)ee>S}&(#mpw`};RiY!oRNj6i!}a^1lXKznm4-Fzj|G|s@E zkB3e1`3+W-f_tpIB#S9)P&Uye)xE(YAmndST(J8Sl@pyW+F6ZI`j+dd#ND z`=B>z|FlavOjQ=jTskHSPZM$~C>gdI2u9C5ij0hu9sgyMMNO{f=o?z(zEVl^%41{t zL6*vqiaWQ3@6O?Px%vJ=w^KxT>&q|`cfu;$iS+k+Won)3*NT|L&U5HZ`r?exiTq>Q zOG*i{Yd1E1MGss#^*-G(;``i0;V|`wX@9V2xHZmgZ6x!n`<9|=>b=}oCpgDeXy)o0 zKdFv)Rzl5Q6kxN4krs4BGZ4twjXAJ5-hAiSz~t$(I^m9*P(Ja0Tm4Q~lwGXUlK>x^ zmqNNTjMjkA;ur2Kk+-yMqKl4bGVE2KRUiKvS)|X3#G5$0aIAel=gG-+LDF2xTM;k+ z9Q!fk@5&+Nkb4-WV@XAn_sCB!NRLBW999&VFTwg&(`&QWvHZyW`cb;8KBxvO&7rvq zWR1#X0Aw*-AWH^97RL>8iq9$1Z$o7$dKA>$?WY6Kn_|`|Sb-wU%;lmpC7zAy{rN6&Qvtst%py$*sB zSUR;f$>>DLw3jh;hU$3xXt}uwe{E=fY@p#umZrCNDuvU0SyOpKW@5oSeub4v;qFp5 z;d}tM$?d1=-ld;$+p#Z)hK}T+F1KoyF|SaqB*(?&GMvIK0)~yy5;xM*q*jP~J-ga? zn}mXFM?cCWnRw?o{~pNs<~DDk7nYmAWti9@ff31=-Kf+^b_-9da6D-$k5BQEXSlPm z_r)LGOQLi~$aQIHNwW<5!5Ag0iAS#@!+qakPr4n!^;ONU_H8e}xDP3@SQOFV&$Gmeo5`^`c}J- zprS<>A{?=T2Jc~hJ9|+4K@TvUPeH*eqdpe28GhYX3u1l71n3%QJ4qHiYE_ix#Lks4fl`!4TZ(v;uQs%!7(- zVGhXhH=n*bMtRbCH~wlRjwnO0%`gWXU!LH6H1_m<`X}bwRyU)0XI7RA&GcqWBQowu z{E=z?fICn=|1*(Tt&X3cH~E9aqXF=CVj8dQN7D#P7x+|39wr-+aO)@bKIv47M)x_Vs@I3XGwKISJm;gu|N z6xalpas{T`pD*XNn1xvR9`l@5m@DhoCgG(29@k({=3(SldRf5A&Q-A%e^ku0F38Lz z=AVv7T9;ls5$0sukyluhp@eGSmvp1IIL+re{QKD54lD%T$ zov_@4G4@V%{5o%-vl#1gP;z^?DVq@G&+>8hURVMBK$!;z3?X{Ogk9;YYU<%l!D16V z2Kf(9>YNa#%ukZ{O-FvRu6A+pP`|1jTz#ed>20P^k6I!fKFgdYWC_;aF6WQaRo=0& z7QbH}a{14+4A!xv?;O>!G2-i;{YJ6b4;&A+0oL)$dK({`uVUgxao$i}9e2h5i`i}| z-MX23KFfqsjmH7R^@6-M1?!%}qxI}_#NRh#KF&l&4xqO@rE;&ZumCT^TVUo3+j|o& zAV&oJqz^%}=W}v}UpP3`RDpaPt!sLFvD!?GWexjxswDSFuxE4ImDgGnvW8xoByt;u zA&y*ZIkwiFRP%v<BrxhEs zw}YWBHl7h}oks+&~)H#g9V=_eIM@i9aa!3Njm>9ymX8Ra@Lkb64Pzt z<1WYoiSvxV&;-y$eY+m?NQ6414N!-~zC;rypPG6w0M>+N{X~MJ1t6})Fz!K(Z9TC) zDt+$vpBHAM7SYUY2{O`e0O?$%_nS{P`3R?e76bwhb>JQ_DK``-KC580X5*T1Rqtwg zBqYEQrd+Vi-PH@`xpV06PB0w~Q_mrnOuZ%=Q@uAkRi^dsA!(@f!{LWrhN3Jr+hgqe z1Lpl9DM4-fzEye3JWZ)*Vs45r+gX`WvG`ks#u9xraVHf%V zP2kULxXpw~_qR_p4()lshb8o_BNe{CJ5M=m>D=G>MfFa7HKZeEgys43cGi-d*JW;P zsyaiP`<6wT8Ix5Z*)P|Hhqfeq$rjhl zMGz1C??Xc3jk<6wJnpI~S%>Xi#SXJnsTJie(YTxp3M=VmOCZ7Dmy!n156D$Ocy>e@ zz9HR=1(1B{Gliff5Py|saI_F(dL;K>=r?x1SQP*ewpK6JOPYI~s)~8rC~rnsHkYP;_UL%Lv`|V)xQi`=$IEj{EoT zUtv#LI!7b9R==qi4y9JD%gx)0Sw<^N-%E&(XM662lv5vwD+nmIC}R-v8WOv%J!FV# zP}h0?I46ge{OW?^cx8$sool$QXkJI2^~Ph~SJD*Qbl7h8o*!FqG@gn>15^xY4{9e92yor0w zlpy2S0Q_-9Y_yh&VD%=J8AZ(dpA#9yK1kwLHQ#xe3o3E7RHMwd%miedOTPkpO|1MXZ8c#`esWXZM z9;5vbmq(99eMN$qeSUixAY7{MiBvj`dhQQg#;~U{%^U#Ld2JNPM*yS8Yp)XgbtBeD z{zAGHK)NhaY|mKk6N_m)pb*Vx5hylnYu!_~!GN+XnrEUwKaeV(097wDu5^@N^n{{U9YpAwr7X@B8Hy z!U-T?G}2G(05zp7f)*B-pY}%w?{AJ}X&czSr*Q8c$5=1D7i>igdB(ro=b*WIg=nQs z$`>$7d1Uyln>UF*;2C)jn!Y!vdQB&|f4sl9xK@886&lmdR3EKCjL71)Wb&T*>L6z1 z`i;94oQaCckNp--gz@>am1m}B%)8Nle4_ncBd6i>dDptrFs+Fn_lEL0ognj?#jQp> z5aHNC5l+?BJtr@IYnuiKL44j7|3^xAXQ+y5r zQYNK{4dn(F5^atvu-NmqRT5|hL^h5?0{oQ6vj{Yk3l6pf`20XaHeH`0P*+fm{uJGj zay`@!{4)o2G=uBsg!Cc09~5W={!tp+213n~i%?S>uue~foDzj|6jn%(kbzV(97Hm6 zH&dX{pQ2%E%R4Z!OrJ({bTXD9(K9`W)>use&OH3uk>hFE4tPiJo#VsP8sIgxLr#vm zWD_`buKY>p$iq8WAIgt(B3f~Aak1`k@EC5ZF{X^EsHiAG9wiZBPT)hHZMS50?dT`o zKmMem2fz0468?Tpem>iE8)IYU0|sX^eIYlG|F5*` z$GJsYcEOQQ$6SGzyP{1rNVE={*?|*ntn#4I3J!#%xH%v3^dn^;Lb#uN1Cov1UqWPJ z%Setm^RYwS26=BiVEL&BR7U{b(YBe)$Ee=_xDZHt(=TL%Weyiujoo8@kSj|;xiTN* zV)r)QQsG`>1tdgYI@Sw?^YI{H0hE(zT0M_j=M|9#Km4s=FeRu*Myn#YaO8zNmF|!6 zc_LnUV%z4~M*0ATz~Di-abcXQjrf9NYG)SNHh$dfmOV zgd64wp5;Z%K7k{I8eo%*?JIFu4)Fc$erFyrZae3B#fx4@xAp z)C;Ou!HJ`WSiwo7^f&Mqfxv#^^W>o3=&FSxgwHZ%iJ&^cexngvEc^+;uH}z}{7c_J zeE5dxFJ7tn%Y(Y3q@EJu-T<Oq8>B~m+k?+j(Wm5J zbfRoWi~DpHzGkL85&b^!ROs22&8YzCtCma65g=$>DG%Q&V4nH&Neb)RW2)%L zd(khcw%O;%`YRzVO*xpCUZyh!M!r-E?rPC<;PxYw9fj@47w4#TX)MG;DjS6FZ!>Sw z!JmsbW8vTcM>_W~;ubcE!K4B#IO$KhyxK8<;0N-jF5UxZc|g>&3K5ra)Iiej@rrYI zL>Vv%Z^`OT^IcKaw$Dj_g^76=VWJbthomkj@Gm`F&tSsMezcjbACG^G+BA<$-v`2n z{Rh(HrR3zEJAys%+jG)RUHFOnfIkPM|*g~zkZ(SbO{&)P6+CM5;lNB(BReJ}PM z6XUgxQxBxtDdrE+VyhnB0;36i38++=t$1OXFh!QdwUH{j+XImS`^~*CP^6`#q_nyV z5+l(nyTM4 z6C4|3PJ;zl=GXwtZ>`-xDFV>44)S}Dsr0^(<8=LtSTa~Ih{YAfo{t0Smw;GQuNn&ps8G-Iww#I>+63|%PCOHw;lz*ksbw9IdHCP{TyNZ z8C&CXI-oJQR#KR;%$nE1YK(ZpE1u=Z)=@3L%_#V4l`s?h-RKMu|Gw0ydn zjN*t^`0_69lH=XqeYyim%Blq=Sq-HnSd5A;3FUbg*V-mKpB{2pcI3 zCA@C)ZP#=3^j=td(L+%cTIesXNn%-;n`XW8DL}TI9V z2Ke(7Wiom9IF^l9fmVds=HDt*SJqyc4-C~Uf14|CwU4bx2L$q`nf=yfKa=N@aY(@j z3Ik}{#}s%te*k1_;Os6#APh8?;>zQ18Rg(_69y&#MIvHDk&!2Kr|5JXA&LlIP_a4O zCI9_1M<&D0Yac1rdG&txUty*g&av?s0tAb-kjJgkZT{bxC5XS$SOC_ZYaUE(Kl7el zqFGn!y=LCmn;MRpM;mXRfMb?5+8`g2+u67aYdrsBH&Uy4={oXnPFA*1N-Df>qDpLJ zHxT-bV|{fHRM%4adZeD!p;1!Oatcv#87uhaPK}XxSpmizz9XwsAv9^S*!Buu+-vvO z5F_H>dKJtc!gKeI4-!io+7@9yx^l^HsuuDhjtx@9D|rQ(B|3W^xza4>50070eG4;Y zYtwVL-*+3hLnTZ5pu8lL;q=O>NZ&xl+%5Nbi?0fLN0G0X8Ecbl;ZJl|r83W<+f zGxOfXWT4JD>IHsKtR2+~t)yS1jCVD5^K;HuWzT^j9Rs zVKL1FrRU{|>+A#~53yRCMGSaT;Lim4HS@pYe*?Zt+M+v=GKw2&VEAGF3?okxQoIj4 z`WttLDq@o1Z7!ZW31!J6AJ|CK?m7=JYMro(PF(<2(((a9MY$#R6~p6b1*;+)0Nn8V<@wG^aPGS z3S43McgW!PUVzsy`3P6xb>ZMZ*^fsi|0fMutkjB-&|#m|CXZCU-EaiDPXc5^8P&3n zWSYsqJw`d6{d=R*Pooun{J0(8aZ~3O8=Hos8X3s(wEX=gcM@(*f6nn8HNZaU+0!Np zuIZGDL5Gv28!YEJS^COO)qM2mT~YohCghe)om-p&uYI&uUC%s_c6kA${DFZ*gdAc* zg$?I;n62;BJpltn$EjD3)nT_t41O;@x4I)tV!Uu_R{CJ3ha5INu=VG)Qt0BR6@ zA{=nOJ6TuY3s#B}%)4J3RA;y)#qG|Kbv0#megHj4e;p6Hx($-c%ija|$8=w1?0$2V z1U$<*m-IGVIAzR;)g@W=;l2xs;uKgxhoB5s(*Y_zr8|oyIb|RDahv9L-+b69wy)cL z{6WoVp49hnKt?q6WylxxbPAHIqp59~BOF_X#Sz2@|nC+JhQf>?4>*+jhj#)Bh zYuxRft!u7M&d%{ZfV0op9n0nJ+HIF$%46 z*_F=W`O{Taj)v)Kb^2@%k)lo5{5ee6L}UA9kP6Ge6;P9ff)~=y4>_2;6@ectBUYP# zp_ds&ZpXcD=?^}byjlV}Khn*&FRuD}gh?9fBVBq^(@{CwHQS4QijJM?BSpa#+1*@^ z06MC!^+CFjJ^|=AG>1cszBA%D%F6+p923R1yD#q@(Du{wF+%o%Xo0_+(rumBWal1l zW1c@BC^vu7`deZ2y}i0^d_RN2wm`r7Z4yNKF3&6s&pGpFObXmPJPmFca7O7cQ#&fH z)+hhcwG*$be8hME*pPayf*0X}hwE|~NFO_iQUl0n_;-0;Cx;kDWNB&nYi{L$-e~Ie z*%Ll%o6^$_MW+6iZck*u;9-vMAOYY6#F!;;ZIC$Bp^dHqaaaOzq^RHN>!={zKKne{ z>bQ&#x+ov>0cA5WJN^OINgr3E(z@~e zV5JAn%+MDWpfWFmM-Ojx2fWC=!e8cS05M9a-+g@u!}_TsuX2Crafu6!((MFJ@kf%F zwikNza1BX2Vdle>m7*(n!;-$irFdcJaLU{jw=J2BuLs1+cU^yDD$UnBK5y&e)i#>5 zCf;%8hQQ!V{WlnH4;Ay=WtK5{Qg6QSgB*mklYM<7I}8m`E2l-_u&$!;IPYt#J}-F) zAfW|$0$Z+`#Tme#B*{TlO|%`WG)&?^IN1Cr9Pnf=y-6ypoPB@R4RG+=fuSEA?j89n z$B_rN-`G&IkLGrR;oA+K@Tfdwh9G4r6f3lsjAz1+Qg*$Gy`YPZQ3F)7A=M z*uC|`DoaGh%WKOsSG>z=v*VJ~-bs9`=}^dvRwZK3fK{t5R8xhRd)^--pK$iqHAe(Y zjAp8@E-b+LGPLQaAJn&{cun|VODijNxltD?H@;B$Ou8Zy9H@LI!22l2*ZWauXE1`? z>J`O>z%GG+X1x^4FT0Q8*f>L3TyAmjre}b@-3#HpV9?O4hWHr^M-B4KYNNf#rUv&N zP80FU{DaYb53z_1b`&yf< z<9=MCSUaWEThx?&c7vUrUGtf2uEw`ltvFr%{YBtSr*?wXw*|YbNZI~Uyi?;L$NZ^T zRFUU-#!Gjr-y?Ye`U{?^@PTs5(Q5=i+gR9o6aeii{wTper-q7`Rnla$e%syH!O$Kf zLTK^0K|SArcQiN&?5F?KwP>&62IEI_?TWbax2txr_e;mjXh2t>`~41zliWcC z^M9=+oLW!u?P==K><#J-OJ;8x3XKP}5Zuo-XT`aejssbb2ne4aUYo~k57AZbtK~i0 z9ujj{8jS;8u__A<9&kZ6Ffa0BCR3-=9MtC0+H*&1u3Kw(tWK*K(@FtbLLguXAmCX$ z0pTRN)WP0TR$j(q)RMUKb0|`LVX24>L9m&o*7(2n*r@r2Md5ulSnI}W)+p1AUE ze21%Iqy7z4Q2(6fCD`INWF%6RxnjSuN>^jt`Lu}kk&HQ^wMt;sN;gD6K>!Qesow6Vn|meY43wip;pxD_-9#in+G^_l~*2l zqG*DXfB5gZ)xr1DQS^@*1?Wg0%^Z?@%?(8Kk8E|*BzU-8UeLS1C83z5xAvCve zJ|%KhFyvv>WeclML1#WzwRqR{fW9m5{w4sDeE>n%fE4n^a?n`C9?`gYv*78f2b7&F+pbAR7Yd~IHB;K2vz?U}A+p2tdxXrirO4T&ObmneQHm41JG$ z4t@`yjUDdCGXkfIx?l*tf6(VOImWJ9Rg7ziUD=*&=R)7#(2EFMaI;xU;{y?$fGf& z7f6BvHs7=;pI4Q<69iS-IG)`L>_Brey%ogXN~=ESGuYPJ|MNtTN9_|IuxClU=M$6@~$wUNbwhfdD5iH4`g5Kh*m2gC(F2aTTymgGIA{hr|C@+|OV6 zp1yMuvXY;c(kvG-X9mbf7G`lXxj>6YV(fVsaa4=)x9>P9po8|dH%1AVfM*~u0eprZ z77s!Y9#4WrG_F;aU()bPX5VilXQa`AtoJg&fXO{`6)x;eTJ7lYB3szEl+=BQ$Z5WJ9 zsbrD(g(aGrKr3)ywP^j|_PW{u^b5y8I%8%BCb@Cu#w+`c3XEj!K=IoWU|~q%@=}_R z zGFKp}CKG+x4>pph&+~{qQjkkWDzar{8$7kRIXjtYtQH4;eZTpOG8yK^Ov#{roAo0t;6K_y=KZ zZqrBEn>eF$oIf9&HxgaJoo{Kb#lIk`0%%!+B>zZ+i2<@KQA3fZeykoXo0N!sB;1#l!InGY#?mxiNmT- zMm7!wDOwhbVZxLq2Sth_=XRk$NOFNahMlD+`>0P5&`D=uyFWU17o6-bN)<+@>#Fd-E?gL+~Rhvyod)R$tBCO zW&nLS@&Gr|(GH*A51{daF0+VkMPl9i62vKsWDE=~zAythKrZ|to8`(f-CiGCo@qSY zM|NU;3FpD~L*;bHYC<=G+_!6Q0>eOE0`2!)KhYhX34St2Gf?_6_j=ti!RWAFwTc5ZF4=XzAwi8<|G`AK zaChG#3mxu>ko82Rm-6q)3fRw&I-M^`Yn@PzsS@Tyn^tAU<9wcLp}H=GQJ|6L{NNL` z8&hFm`1O&;tWv9(@v6L)eLuMWNWKj*efEEjT*h1qfG9-ICszo3=?t1hL{?X639R~X z?MD?Hq$5y&4{H8kr4P3`o94aEMSX0H*I|V}fR?n=c#Qx5qAgByf#tkkLqChPx?>+B zCLY8a96jc|bBE>GIT7(*iC+Hqst^7tkpG^*ET|g6Zh&}O1#f=d<&SqYNtDQ;m1;BSkCTZHhbBx z3~~uM8ZI5O4`qfpqou|&@1#7tx!VVI$dci1X1n%mt3LfgOhjam$>92-n$mztG=Pbz zZz=kuJL^s|AD*7XF(1$Jaz}atbH|0IJI@Wk4B@}7kvVVFd9|fR?uXj?BeMnpmxT%# zv!YvW*0+;|)hLQf01ot^X@1Mq?;a;MvTdq_lpHy;3BmMbR;(&=B(W^_`YG*ZEldlmEDwW2df6cq%rT~dZ8NiMuUBqNTfyeyM9ni~*bM+8i_3@}7SHgz`I|wQ>3anR- z#FuIRE&=sXf;jGe^>=z)73x4fzUaQ4kQI>a+ydE7ja`?uzs>#0c$)K~o#GunB_pzR%C@>(?ohQkrSNe)XF~)`3 zSBP;eEU)FlmV5F)veIkr{^_t0CNuV)aAT|fI@{9i5`E06yYQalxn?ERSl>cIt-p>@ zq;kVm8+K04u)0Gok1YMX3Pn>fF+piZDdxOe8JbG4{{-3lp@NYD{OUi!-Ikk zip;K5C*P#%RrrvyW?lAvErJ%Gn%aDlqm~X@ls=njfjO%TAI$I3c@L9A`IR%J+1f|S zlV7|N@)DFjytw&O?3`7J$K+Pm%V$oa3zuyN-!tiy=n5!JRH~n&QIeCNmz@?KvegTN z!tU`8fFtg<%bvPePZ(A@wd8&JVAw!(Z#i+r`g}H{()UPKfkd%{hC%BzN8ond(@hSYC^(Sz zd!4Di$2nRwljSev;_oJ=e?k_QI5*=TfbMRn4qTVVa6@b_7KYE=uItw7>$Z{AUgYf5F&o3|@16dP{7xXdw^6R_Cj%Ts=D4{=pWV#NZ z|2WI@Kw`P575%Bf{eQS>)Bxun6SgYu#n-(&g_A3)5pl4aHy>h$3}4)x6UW`new%1B z#g*FPW7hopuk9cBeCM>L)A?8gYd7pTjfxsQ38TjjQ(`=WXK4w7 z-UMWF<@0KPYC!cU_%l~tF&rV>)0~Z+sdW955Z@S3;F;3gAbN_c3l3#WD;0Bqa5@n1 z>7(GF1#5F1(X(~N5)cs9Okb=*#?xuWZa9TB^Z|nmU8ngnZ>(!gP_!>jUjPekKedl zri15Vwc1=@lLot9RA?8@l-~<;&p&yW^69;aI1wvT?Ugd8BA!H~& zw>bBadFRHPh={9r7j*}y8iYl_0TLIkNIEf4It1kks6HYIeDy>p6&Uq#0OM8ma%+kY z1?#0ABuq^gvpUhi-K1r&T*!wMl25J8+<=MGFd_@)qB^snLs1o^Tz*HF1h<5SQG3xY zfV$%KHs=w~&1w_<<};cv=fuS_vpANb1~QTHFeRs&wFoQwpPp@d+wYDz6oV5RHV+H$ z!DznpN0<`|TD$H_cRl*3|6J%99$SlN8}%w5j0xEoU#-sAW{z+9&OcNC=tScZo?qF+ z%VrmX@w*UA&OSyzr9J^=wTfwvPfGeAZ+ld$oAK3cGr1g$-Z|dqEhWJzLD4L;enP>u zR43zF5Bx5#`jnvVB{HF(ylM!HQE19s@T(_O7^@Qc=PZxgDqZUnS%&wiOU9AnO)+BX4B~P5 z6<^z|y)So8^9dI%I>B53^veiW$?wv(RxdEf&OeN%6XUh#js}dNy6g_Q~Cm$#E-VWLI4@Hku6g8E7(d-Ho9^-Ow^|0 zPa(jZCV#{`s&+grGUH`UQ6@F;rb2f2+=l$SyFVgd?L-v)k{YY330CeL4l>F588cTQ zV4HQzQc@~jKO2=G?|hM3ok3-b0K@lwFs`y^%NTmV-^O0Bx>NnS-PmjtbuvPIOT{a) zAP4pGUiRclWJ*8zQo;ZCw?T`2)KGDAudQb#{0rN^E1c&S70$$etZ0;^dStEIFOuZYUa-6XB0S5-Ot3U|qdPwtxlW2R!&TFnO&d{GJwbkn{gg>oMA zkxNbIqFGB!zt3HC91Q$h<0BE~SOstS_3(4U=$Hvh_t&o*B!$5Al>C~x+?CkomcIpouAkmu@Grs@uys;|r z^}bgwdQYwt_wQi`U@K=(NxPKkpUY0&^jV^|^aYQLiv(amoUddr#0mO6K%6cD9z%ub z$*;MNJDl?QL3pKiA20?M5A4gn7uaSh{T1izD8%_(H}Banr2xwdYOSBIdPhW1>lzJ< zoiRhLN63MoQ=gLTz?69V*&aH$=t~$&a?}kPi={8^@h=Wd^EndxCcsA5ii>X#4G)*N z!p|NT8GqB5+EBNbn|k;4ZoeiKvAI-#$`MD-c;MqJk>}6HX32QZ1OJ?P!rgIU8H0OX zRGWKpr1<-d3^XAZEo!L?XA=jC6x`GNg7FX zXLAoikW&uM{(Tc}kN=^S17DyOhE1RqLH&JJ1Aj_Z26rR^+8TkJ12ch~ zzu1sUkNiHpp(DD-S^B(v{sFRO=w}Q_mv7h2iTva~1PA;+c@9VgQbK+9Jt>2|jo z+dyoaXr(}jnBi$Lr@%G-JxY@`Fjk059cL{{Wum-Gg(lil9|{vr)sQi+ru#Le$C`D^ zAPc4>@^7n!Y6vw=648*rJ{btZ zavBKs8{-IKKuJZq+2jJz>Z}l=?fj&mlWSZknzC!4gJhsge#EO6&h}iWmL# zN$URyYYs^Y7gBbX1!R-}6ZjBH(~Wlzf0}+@U7zvZ!)rj=osXIRUo{>N95pxlYx?{5 zm`+ZYYR9;ZFZ10U$kutdgeCuN9;xZwTTz)y8(x7jU9wf^c^)s@xmI~nR$@OddEFQc zo1XsZ_MQCl!Xf^oCrij&{Iy%vadaxxIW6%bC2u&*9;J%HJogiXEIT+5#ivvJ_=(69 zjb!<>xc;K3kguSa(f)ynod}Q3Y$;FU>g00X402jJg%Ls0zP}!m(oem#5*`Nz7XO=A z1b|qyz_T@SfMZWUMJ}C&H2OSgv z-u@7pp*-ERS;pu;AzJ#|oiXnW0Sx!nB>we#yP#L{ujbN)5=S%tnR*MN)-%ts6U1J= z4H5_a9V}v~A|}nUg`2)Q{(W*^kW}13VS4>)84lZW{)ER`2o9%8R}oB&q~O=kga1R< zdj>Tbc3qTAxG86-Y#u!NQa6P|YGZj~IKX>5vLGhK# zogY3bF#>bh;~{_V*GRXM3YV+;f~=1@i?z}{*L~J=Mu)VO>QoJ^qZ?3>4C5bxAZ9<= z;L~lqm%UWOEbI`RaqEG=gKXbN-i1V3CS6M_?#5Z|+JQ2q`6Bk5{*{y@2jp4Xq`+3b zmLPem)k(vZr(cl@a{m9I7bvOM?lk)+74w^eS_g>rJ%xbP;hZ^x#}M`{Jl8%YgzfSz z&Hr>yAAlgImbVfo5ye7~fFfa=nOmLIW<_%%q>mvlL1Ms?kpv~kedmUBI-`Yo438{s zZ7|@gHMH4p{iOuB)9oY)=9jB4?l#x8Fk3W4>XZu!Yl+>BzwsU5Zj<@|$%~v4BASGz zcUPv2ZexJH`$CHm+5)?o>}*t&@bNBBIm@#NZA;ml*J4gOf5{8A!?nHvxZHMMOC6Ws zkqrL2aaR6(cXxD3**G8r+-|kw5LBvsg?8q01ASCFLo5ah*;Noy*x>hwLYBXuPr7`~ z)+rn>fu!b4Zq?h#y}I~#V&p?yeY~-joKCdM6uV_l{w0(-gN3|Nn6Ks@KC@BdfLQ{) z8<+AwVRa&V{|JoCRBty_9zn%j83q}EGh0MJH} zm#(csnj!DTo6bGq()$e@^5&zPV&}w0ZMo9gE0h%fXHxz1vQII@m*b@RG~i!AcKiIP z{Z#GSZJ>gv9`e>p%N;ZT;ZifkK&oG@$r9TaO*2HDCC)L(kiJ``jPc{+YPzw;K0aoG z0Jmiyu6sE7!=EwU-!eDY@qN|vBV}s1xUt{jeFb%O^*lGo6`hW74Y{dhO*45qI=aL} z?gtM_ZKm=+bR+!dd-K~@BTDSkxxb#BwXSy4y@G5F{rMzLe z0v}^f_ul$*asHc~cs3}V?@{*|;@8=mJ3vkrC-V^gcL@2O4ZOEOyUv zEvzRgAgjEoDob11EKP|0T`osP2`4~0*hj^$p3|gcfZk_gELJ)AO7(ZE>S4>)dk^PB zyAEmpva74#_#Z}y04dO$QH5X}#X)8L&&PFMe-iNmv~%yD!dW`g7%%fUC1*h}wQ$-q z8G^A5$f{G|Fy^C@?e+y>)mOi6C{u(Tx98i9f#Ktwc(lWsz0|8=f1AgKfDra~40L|n zc0i|%U#cYJr*2r+TFpt5?>EjowkIy?VS86L%UK_P>yO!s|10p$8EiR~f0aq-ey*Tz zNKT}m+%f%RcN&5hZ@R)v%vvc@L|1=%nmfPQZhG7N%h#z`upyNUvxZ24hh9^N%5L27Eco1mA`u{9PQZ1VWnCz}D&P zKrWtWJUV*$Rk}#6_kI<=0QGAKLh69&n!dIhdK$(6qKZ=Z1+WS+S9n04}I?hX>VLv1!Xj#_l!s$tb zKc@I1$f*QC_wtwzAZE{%)x8E88?0-F7Df(tcjw;Wx7!#t-B~El{Belo3_M{H-f9r# z&^o%qS8@;U#{HUO+PW`(Y=EA3EBl)J`1@QaW%*uTQnB{=6{@X)mDCCJKHw|JPO1q0 zm$J5JxeA8er|YQf=4#hV6!#^PhlZ|^(!8}&9apB*_9Fp-(MIQ2{mMqLBZ1~0s=jjb z05DhYG-YL67g+ixc%aaWt1?h6Hh9jjdfZ>HeO~)P&^j**@a@Z`TyLV>_VUymFY6?H znHq%7{2C4XmVt_tp*gSLsPwTVz&r5{n3250!%KIYC&Pvt5}dMiawW1CA_hJS2qZsi z`v!7V-I4D*Oi$MoVy(e6JzLd&ASeby&Py!lf4hIvl;iQ^F|SqgJo65mR!=lNcLEEW zOh}gR(|rlo0UO-kP)yffxz+FoDDUqb7#U^q(ayIV?I;Ni!m%}Y=5iRtJAYDBuL;2B zSr3jOVoCQSChc&rd_B1C<@vPPOwHSRd0m$pGaPle(E^M(^L37Ec`(Btf6~8{S2HSz z#6ef6dMC|I_<+YdDQ^DGa)%Yon4h!RvWPz{zwTXegW@JI2>_G;h&#(8;0f|u z_%|G~Hvw=SI~@T_tz!=9QD%Z15ywR9?8lBqrTJu{*bQl)N^EjvOF2LfFfz3%%Fnmo zzdJWG;=D}>tYv|E#rDC&tD&*y%u1Li;pbkK#XYR*#z8{LOs5-Vnyg8om@rH!&6SY_8zfAS_HNp;!Rs=GM(y@-hV}AZ`U;(X$Ou7Q|vV#q?IwuV7!h3HJh#}d~D$#5R0K^#A z1V0c=An*+4`@#)N5sW`=EEOnv;B9*^Oru`Div3XStM_S;u&!-I@F+`dPIP)yQT%d% zKGAid{T%?;b$v9A&^xSWEf9HQRHLIWQRm8OmTvz%bS~QV@r~D@@vz~P1OVGB?ccW7 z8mybwF4ZY@F{`>Hk)f5;c-y;xE{r~g^KsEra@x!5yRmQfFo-WqXpOA zNrP&={yaavG)*VZ&E1f7(YR&|)Bd9Hl}vx`py9Kh+J#!!)1BYJJq|FBpN{!~4f31a zEDoj#A7sq!hq5#_>z%<#GT6w2woQJh9%TanB9j`Jo6P?cX4M<-DkAk75_;< z|L}ZGy8rh@fx>JIFqa3hQkbq7q2TV6_nI4ljG1lM($c;3T0CuyVS!Tgw{L5O>N>Ty zz2{=N+MN7W7YBoeZSz;w)b(_oS*-@AbjJU&c-njG>?2C27yX*{RAih$xNAX&Rm5$xj%f7&= ziM}Q_R+Hf6Am~bXx_IVrr!w)m!Gwy!M_cI}_MCWL*)POkCE#L2K zvr4nRSxb-7)CnsfZcTo$D7no-RcO}wM%wjNTQuWm)x)dV_09PrZ~E)jHrS<1e9<1V z6ww}*AX;@HrWBctXBmxSt{{gNdFy&UK9D+)h+a}aa{ZTQ}G1m_{0yzc?^u7 zUj9rtL`+Y<~cH%PY zlujq%=WD8vQC^9aY|K`>?B?}Q1A*9}ob5SLE>6yf)7R7V?A3W!sF=pH{T7*eFENSU zh$<%M0OPY-y`@s6{h<$~aKFiOs;*N~lc7jRLAJ#IW)v#zDa>S??`HOZx>707zqx(< zvW@2wGYty-`zZ#f4V+ikSIe1~f@WR~3=MsmoYb?l9r>C{mA{f|_VCOt!GNrnottV8 zXrBL(-Xv6jGzHKZR@C1!<&_};0Vv)VkoM-kM=6i|+*h*Oxc9?<4Q-%+Z3lFX(w@8? z`{p$|^eYx&1Nx=%Gs`q|uR}aug337mMUqxe0prz>3KyAS~B)MMZRtYAij zIeEC2!ZbIRTY6Z7gWnIvWNj_^SNp#zP+Zn0x95+{nlCD}$1NMK<7ZquNBb5JvzE&~ z^i1G_J<4I5^shPtBmvoQ#xbS9-BBTWZ|kG?6Gnu%b>D(;Nm1HZfrU0adBSLSwz%2@linrqqMlF8=~%`iDR_ zdY2S!7d|WM0b%jeNvh=(L1@F!SCo+V~tqsKL zyy9MiqK)WQ)1-ug@PiG8a;vDjC1;SeMl21NMfXNbAnjS+ z!|1yY{#7tqS~_lS?kHM1+Azx7-}>KSu~?Uo`~KH zgj=Y}TxV=`80#yYJ$9&$^B<2m{&S9b34Z-FdhlqUy|2$cm~Dw4j00d*6Ksv8V(BC|o$$~jX%cy6aVmDMK zFRUZkn}*|GVDm&QyRZIXpaD-NC7hzt)gB8T=h=l_1$y$D`(K1uI}V2+HO)_|Xu@8k zx0;m@3M~|)9!pUHW**`5u&I7uQNTHcHTd+|{Q0QNWQ`efgPKFQrA`qCQ`Uud-)Z0E zSzGtnGmO`m#gGjOjlYl=l7I2Y!BN;)JD+!hH!u0DV(cHRe-Uq(22FJ0a4qgFGer6VHhoCLtNwEMVT+zM^$Xa&rswq5U(ZbAWQMI3TW=g+Sn0H${EJpg@$Og{a zE&i8RE*kzrM2sFn*mlne`n>eV5MARImuI&3q)Wp4YQAw=WPFiCMj-E1N>=5vm!-!w z!{Dig@r`T1F3J(FoXa^7d>jI6)`#=%(v@3Fa&S~FHKz=G=2J5?_Yglnn}~0Xxw)F) zrWXm2hF_C7l^0)0p>NDfyu0A}|L;#hmxZOfHp z;!;t+_OjT4wOtdp)!P?BK&*{jEzK3sZ3LP5?UGw^lD^MtWI&a_2W)*4-+o59Wi(KU)`_ZDlpjM(J#{)Hg0g-9AQcJ zS&KBj{oo_D&S!324i}YG-JR(|N_w90jHz-tN3c{SHx;Yr0~VUri zFuGFTE>xQ+*>(G(7H+NxTz^sMTy^h3mbAxNvt2;XF~TQ;icQwg971&-^yh+^xK*0J zgdVH;#uX~&u}&iE7jir%0?__SB|WE`8wlQ?_xr*s6;uNP0*!$n2VC@?vK~qzND*&+ zYqMr2&UV(X>~9b*+T?LKky8ay+|DzrvK!qj@!ZvpcGzo6trq%~Tlw8Qj6R<7Fl~%0 zb$^5QS`oXOv_yZGXNm8)h*K6!F(IO3gI#!4d-gKbrPn>|b=lCIqgB6m1`&r*4y+~*Keg>PEJaq z^L2gp#j(yVIWvhDzcf{} z|AMpx>9h$f-Yx>t=DOr3lS~mCc{sBxZ^I~^Evp@noC}aCCo6rX@NCho;Id(FVnw<| zc)gpaDy6XN{6{nru0&xZQ$Jm#)HhRM6jP>Gsd}2;e|jWIP!tX4SRs9U;a#IO*;@$okg@{V41sT1wn)Db`iyhy6G(A9DX zTP7Ar42&eyZXU8y^z<0Mu)qXt4F`DBu)!W}u+8%oatgB-`soBh;I!cbNcD_=ff9A* z6y{7+adX71gbwfbcDNY3f=71s(iONqiUTY6J@B7>EH6+DIJ`}`tKFGEszGCBkxw@I zpqyC~RZ^&sEpiI<1OPmIfYSl>+UoX7gG-C&o}U`IB@``s6q$;J1s&wk4-)Tm71+{{ zJ%S#8OL|GY&>*p?T#dTw71#9}KqcgWC4)TI4P-rXK2zcwbe!scno}{7g(9G~cE9zM z^jp#&t4|enO`N5kCLQ2Y8@e29FXsz}+Ns;Kon2j|)vc$tKMJlw*E<*&%euGd^+H*v z+Se!J^v5F+ql%`#p{5zsL`&(tTD2~Y4T$(Ivr`aST*&s2(;I1KU8rJ%H}O3KX1~G` zLrhh@<7)VCal#{C!b`MBrSVmcyj{1ud^cW(Km5kxM%j9t_oG(D)x__BhC^I+H3}aP z5HML{?uybn@mZgz(yOt0Jmm#?^ZPBV;>b!|>iCzn_s^|oUEep~N=w2_B^hVaGIQJ(2K9{5Vl9|60k-mkWF4)FI89g$s)&($cHhHh}Z zCVi-QV!3Dt7}G4n0=@OeU2F zE)JGWm5o{OMsw(ih!qwcCVsVs1@b`iR)97%ifAr|&+#n;r07Z%jbRL^3fp( z*R3mbI8d$+g`YLJr2k!zb*g%PXtH%AV1JETF72#esq3xtR#%UtR1oHC({j$;>729U z!%kw}Ab-o#p|hS*6#P@)964Ktu;U9|8T|X^uWJ3DsUODQ3rTkh%%Kpu^_SGd;7wF; z5SMklVWrJ)Oj=rruSN4?^+E4?84BF83$qIF$p*XvPGb@*bvj0--TA;z=2q?^$C9U) z*H(j}d65k9G@CR68dMvrj7LyMdc<}&cn3>{b*ukZHAj}*&#zWBsY=7P>kx)&M)DSk4|1&LoCZz>9?KqIJ4h;Ua zlh}KV%SxkcT=$on0Sn}_x^A|;K_B6nB~vJ`D0|>+2`qk+VU*3lXLG-4+)%Jn>rRxk z)j6i!bX4l-cBSq4I$*XcB6v^#Q_t#2o9&Q8#!+k_n*{Xf3~zO(3f0`tcPY%d_D5Y_ zqrZcYFcyiE<2r%gzsjp_vheyzV;yLv-oTe?U$gJoT%)Hj*t`cg9a@egkV)K>eE}HL znP2SwzOrrKSO^Q{PbqwhQVu7l0FK8^lK4ip`4`irA<}P8#5X4jYx;*{tBebd;n!L+N&JJ zwVWZj3fHb(>#}K>0K47|OhmLH!L&Ej+JA=0Tn;Z@rCUAyoZyjG)waQ7B%VSsDlMbw z-zvdYvYsv89vTXkxZN~1bhkVAhU2uq5TsY#@{ncJeem;eeaOBs&#(a)0k-8fX{>m| zD7~EoCUjo`m||>XzJ4w)*^^6P^H z2euna1l<2LRx1Owmyn1* zw{y_&*}2V_7J@@jw5rx7miW6i7>)r?=`Gc&dH?ikzp$9aI%m98%ipe}QMyD_aVwNK zA@?J>n@V$#NXYcvo8{O#6>(W-hwacpDJ7x5-g)~xB>jIa*8n@-2O|bW!%Z%8a`stc ziIoSsdUkH6JL9N(=~$qMD4%tF`z&?R0Y$QQ=d$)w=wW-S`>Bj6=6ICOT7y?ReNMmE zG!N$-RsPM4VM8v~$iEWj;oL0vtq78Wi|sb<$x`Ks5Bzffs!Rts`QPsB1;)ZK3W2?a zw$u@qDb-WHUT6eLzlQ(rtOfe-Rn}bQ_*3^1cq%{r(ChY(P(n>|ZC#xaZn_&t0h{XL8U`+Z^dQA>$OvZ^2?^-qt#lL_{+=bzBQ<^FdP=K{)1vR_+(8n(zN z0Zthcin8OFc4};&MF{;y>>J1^zCIvVIG0&BUvW(S+v(4Ma{cNmC(!e@y9A6#e}o5JI7zE27|^mUirRi{#)`;5PJ@WW+M`W2Mu= zX{t(Nf5Gpn)P)v{>VvOS+1((Cnus_JOKROe=i>kpRPT?fu7@m$lxf!${ifg>sapXo zintI9Z;!5wm+ZRVMq^Fy<$RX8Y83os4o?S9NYDCMOZR;G)Y@l6TWFPL1C{JdkNq`WlqD0@zu+eH(h|bgvLG7jV=3vJrrF-6f444@{rMo3mSy5!enUWE1cYTE6RId4bi|W*%eRYn`vlc~Cds8xkLAih&8ot6I+q-f4gf@>MX)Cf&)1gD+3c z1=hS!782v7(O|Na&FnJP{{w1uIOLVoQa@yLihn=AHmW|;F ztv8lIP`Y@*osnJP{@ujWFD!8WmcL|k-7k$^_P=ug(S|BoKr3BtY29F;m_4PG41TQV z_J~&0%^$b1fbFK(E&yw8ZYr$Oz&FE7oU55=o+JN0MKxW3Z}JMO7&ijZO z)sFDQ+5Q-P;9Xi;TK}dW`Tk-K1y8J!fj3AriCF8;O>%rBZ5L*QYU_Mg4J_r>BQ51^ z*Y6xX1w`aJY^V$pJ>n`qsnJ+q1=tSDgtmbtalnza1$`|MM*N!(4x=FR%7$PI8TxVK zSk>Zoww%nk(;`#UuV~ikd}IJr$igR*8CqpSeb=P^FN0D3QH0gWuFQ+8tB`^5qdZh( z?i%&Y4amUR18YPt{x24J9Y#ruTxFZ>jQ3adH-iOs{2uLu;6)ISf#5K9k5y{HG~66R z7dfr}9Me>4_3fTj*ZD@Ztx*_&^H?gpdRBSr6qcP9F<&k=^4fbu`w{8fmL@3Pz50P9 z3b)S_eI(T(wDhKry>{yPCwQakMxD4b-*9|(2M{W`&E8@*a2_7XXB0ilzeDFdtCmNZYM zyB08atlmhs`vvXPNcVQL&<=zk?{F4z`Kkl#%qWoH0wuP<`+K!#{rn)!?eW4W86QF^ zC+qc?P?F1nJMFh}>(IkgG}$wJL)ACakT3{y(k;s^Q+<~YhZ3!rSF zXE6d^jMo%_)*7eXU#7J9R?p?7mB$Vsz8!G6QQk~{q#a|hU!vNO$C(vo>+;}Fb>a0{ zo{022o=`vg=lk@XsJ$GP9ZWh?*&0qyjZBaGpdZ^k6|0k;V^hv@t(@)I zPa07ck0TmUW{*`GJa~4qIgRG_)U_ZQ5h-#9j{D1TTNfgnGiwjy#F zD0#!n96b|$8d{99yS>sj;nx4i4oP8(hh>YVR&}CzwjC{VWePuK+Mo7PShlDrwq%C{ zdZBOk=7znNe#Om{1hC5Ao#RW*7V_xhlO5rKK@X`wL^8{%8K4o3(Cq8-7YdX5^hGcz zdKK71=Oz3UxNc_BdUROs{#zl{RMpv_I`1MRNCmu&<14TQ;T%`2oEDo^x+%o60*!SM z`y)-6O7ItT_QN;KEQDBrj@xzCN!^KAv=bGiJuFmsht2Z-A4TA>0n&YlElJhV@AL$a z1YK&-P!e`He`Y7~9u|M&>A>8VtsvOI*p5%;B|+S3ytF#9!=%2o=r*MTp_=6C!O_UxfY5>vce=ZPH-aWvYk z`*mh8!c116{aEJ5>?2`n)RY1Cj2YJ8F#RER{ob`g8o$$fS+OR5l%27GSqnz5xK%-Y z7Ws_v72lG~m0H|=M-o1h#^vM>9yiG5fpNKEZc98A+Y`w3;3iP#=m1T>CtwzL3AiWW z{*5POA7u{*DiyVd%|{hlXfyu~iArO|uk_}dFSSt)-efS-BlsaGl1kh=FLu$XohGSu z5A&~%Ex326fMu|0X_b5WS)cs3em`)6C<@MrH!;RnwQd*(9&T?&R@+TB6S!+@RjGSp zq3Qf>!D8o)HqWR!{3DNVqk)kFr2f4sE*2uQ2#zpl-?XG%eiCTqDKWK0cm!}I2l6O? z4Jln7di|&>Fu6}%S)u$MNn8YEEgf$gt6gpJc!OaZrhrLg~S={~pyLnJteA*!_j zBHNIRN*jzxMX8BcV0Je*#{+k*!fhPm%N$=28UhK-QDdI2HtbL%?b%4fRvfF8>M+>3 zfJupoYbTiSK~6f23-bQ!-T2MEBeN#A%D>6-&rGqnU3Vxg+o$!S5VwQPOb3uohFyUp zxYQ)|j({1*CE$_)89rj$uTKEsP#eIvBCDOc4Xx+vwITX#B*<~qA|&=Eo3uJG_NLrf zss}g`!bx=imxZqjn&jXL?AZ%NTo=aY8=OmkPWG!q9!lBim@@mxG7UurG>a%@1}V&; zho*@CxqAr#sQsl0uCEILUXsDqw%T<_^)Pqsc8U0Lhls?I{rfy*kBUosCw4OYM30TB z_p1~U;m;%z{9(x7M!!!fGp(e!W>1LKs4_n1@F6LBIsxWUP#fecGTU8dE6BAM@Ts%2 zo?+Yy5?5K~9Kwee_Oh1;ieO2UDd@O%?vc?H8|kot6 z1X(+dI}NwT2lazCmX^d|#(>)cuQF8BzYAw9>b`^bRn*0c-Jn0{V_b4F=5Zw6~!Aoe#I{wyNE9 zAhosHKk=dXmaoH%V$v&PVk!Q1W7CM-m@t&G z@s-N+We9EzpCny0G<3rW*ge%c1cqEMt@NL)^J7Dl53mAE8~_`+Kd2kvb+*r5@2t$&eR{ zS2oxgZ?4?u>kx`%5;RD~a&h&tSIQ3ZG0%+Uv28y0(&o{3lgwaT3IAXK;xWdS+@>)( zSAKf$86E9HRP+28iQG#ZrPh^Qj`|xe8(Dd25n$Dcur7IQE_D+b=a{l|bdMbOtfT`! zDj{BfP2-r~{cp2Cm$xm<3L&lvOx7C-20{^%$FuCz*Bq@KL4dz#UZxu?Y-E2r+iAK? zfwX$=?tc08UTLXgaz=(zIcjU94OzHw(417C^PS7qv^oUxL)}12>qWapk48KI6jU|_ zOepTmRmP;$U-64|s>qAu`lB>3iwB@`y@gF@*5g zXKykcmUBWM%LwV<5D;EX&}U)WNgW*|twx>ACCC30dUT~(Vt`KY)(zl=2~PH;4xPl* z;l=?PZhxt6K3oX8BE6e!q`UzjvR3S@IN;3pV%VO!aGlrwv9HX#wgMl*=NRYAsrr9n z5M@JY0N6(R$YpZ;1b{)(j;j*0fIjRiu{GppxL&1`u&NsPdN#jd6^Qw|+EW)$?Et^t zg%lQG0}tGIqdsU@&Csh|070gC6_7E?-v2_v(#SuKydDymzD7AlqNtJViT0Hf9$bCJ z2`GHCEh{{g)iv{5LuD)hcRile52#4_Yd&xNzxy8#A`0aK;_vkrgi=tK)t7=CCVFGN z&l?Q;$vps5)>7U0PZKIPcfGbf$`@@v96Axq3CNISxdw-c}_1)#SZkx z(V_|G>N9X;@r=KaE$+t7Vj=H;=lc^PkgNV0+_qosWBW5+o~KvC%M-2r(d>b5{@B_6 zV~z~B=qM(Q__1zUVUETU_uyEVlZ)f$$X;4rCg&$5Z{NP8(Yp1?Q{c@CVf4vd$EJ(8 z{lebJ0XBP737NB$J(rH$OAioh^O{!8oa$!x(bkc=))0glu<0Vg4601I_fs+@r^XA zYCoUCbj!yI00$6-NMyP2kokxtjJQb$9<FVS z*Gs?icX@H)T@lTFm;h9l4$kRrjlgTl!#a`mToXFlh#*NcgwO)*Pslz0ICTl#+61G95Hc z<#o{axbt~Hbcw*N$?BF83m;UFxW(JsuMr97yX>)`vz>m4OSiaSFBSzvq(gQEp5uSG zGqAm7I;DJy{WVCtfv}z9WL0Q!FyfmX_bWMu`&(>Fd5Ufe+emIpJLC^k7a4Lq(c@t8 z@vcZf_aIdlBB}=uF&zDg+tk0x3Xz7K_TuvIK&yD*jm>plDd86>i-~jW=u!vOLeI6N zdX%MxxdwRmy4fYeJCEWP)`E(meG=V&euS>C&n#C2S4r69C&-giYqc=c)j5ejLhjbm$s!>E!ZOFN{iPObFTu9!gOI=onpj?&J7u_PGY>E92nv`EMp11 zKzz}%Qk1C+L5w-VrG5r_R!D5PNg`i)fiRhTjraKCLFfWunlhZ>LAw9iX9UFPG7v}e zwf#E^!N?PK7(>+a?Gocpr!eE6d+Y6pAbe`Kd*{A^IDTk?JmLR0dfYRL;`D%c5nw=_ zLs#*kGQ6SFX4O|5aKNRd;OE(|>Z)*5C`d#2++a~32K_R9CrU|Wbwv?%p1fUG;D=oH zJXGQQl^+i>ZMw)QeO&U9vCeha53T}ykeHjL{fbchU~VOHkm1QIE!{YK3x6ZUk9QgI zQA&;$t6E`dL5KuM$NQi-r;HrYtEZH=;P~1P=KbeAUrT3cE?&~P^BSQ&@WmzqxH$FF z6-O?++`d-HVEu57k~62TxQ4)8TS9j}9R4Qhp8xM3)A^sL*i%Ezho7Ui#^I*?efNUe z+t0?;JWs!#K&3#xqED{g*D`(g%fiKbn}ZE>qK4gq&oDHNCxenNFbH(0$MTzh4nSxx zswkQFG&oNa5{vb6x*LQX7^XKLeKHKrMR(_S^npK_xV7mTo0!-h+c6gwG1?)L+^DZ4WPEgk+5P?w_sfv#M|AP#Q0I&r zcb{r;bP_V|1%HQy%*Dh-DQV9iZCS@BSr9iUv0M4^Yjg{4>&XdGN;fZGf6M@!@&Izq z5>`|PL-qD59!!*BtRMNql(wx4FIh}JeKFkn)IAdUlWV;W%!)ckR-Jd;3!Gg!Jk|vd zp!)7HzVhe<9)OVU{K&kNww2o3aS&T7SYXi^l2^q7LY-P44AXiqy*MAoa{4VR5c~&; z{nR6boD_aX2#CV|GTBw3>Xw5* z@ioB+;g863Qlg4r?!ln_P^o5tHD~BrwOx_lofc5FX)`~w-M*-)ON=L~!1uJK3wyMg z4gGo||GJMYC|SMi4Bv;eg{HEd0715YHegi^LB5J6&17FS>j&dAK}(B$`MxuQ6&~c!XYkm;-!X=C;WyZ{8GSQ0Ek%Yug0_D zq3&lgbHulyR#K>6Iqh{s>7c>nrscz7IP6cWKkDI}+b*9o8oN9vbL-?dk5RB_@Pm|J z`J7!Rs?D;_9S%F(s865f=Y$eo1{|+M>@7(__bsY|_oockK82$F8W(KgZ@O>UX9xY@ zhc8SN4M?wIyxljX$ijdeF7Q%t-9Q=00+5Mb47cWg-&n_$<5GvdkRxwmbPh#LUw3r zFvE+*fOr{Tnz&ROha3g%;t#VYMvoy~kcQ!&PD1QGzq2Tv^X~it)SLWM!t??%u>;L2 zPzMhJ`z{3Z?I0$fxQqG*X@l+bt2_MQ3d;fZ`+mbJ9IR$|JoDN_#65tPBB=vk>3ojm zV-$O%wZ_T%xS{;wn+}zK(bMuaAm#a&>vp|L1Z)QovQwbPl_aQQ=v z<6fJ6FnHv2c`he&UK&q~OXjVDDNe4&H7x~R*JgOJR2@b1f7$EOmfaw+AEjhL>=j*C zk`Y&uP7?+D&Rgz3TkNaGNFStL-~s#8<+M5?)7WKrN2LY(CDh|trECt9x5w-3!Pvpv zgG6KwdieX#a)?32E1KqPDj+yP?-YSNR^gaxE6Db_$NgMkexp;nol*zUO$t!jD`xFa zR=e3bSOOM0)2D41;l)xY<%T4d3DMTAyN`RR1W{Xbl6zd3Gsu1t8Iwk$2iro9zn;5Q z93-?TFfSo6V`68jJbU7>(2!#=aJO0jvv_WZoi4TTnqIiR+PnV<+JOn#-T!ZqOYZ2$ zIfHRndrR<50kAfGCgLAGF<= z>bzYY=Rpjm9&B8QO~Jr(`PvTZ4+FZqyFL(3C)Wxnak(&FPyLiE3Vm1c{f4xJ$Parmo)q{StV2jmg<( z<*LBTJO5uV@BY*&xrFn2Dck<}07K_}YU!tA>=o#Mvr_wtQ&=D(Vg8v4XpswMh&e7f zo7x>L4mKyC{>&r8E9v!#_&)adK?4(aS4eRsY@yMD6uamJ-t`jexRbM>-Vu}Y^9c)N zLbl)Bl<~;~8}Wr3?kCk$W;Wh$(hs#G8Gzx9%9gC&!FV9WYZv5~oEuPAer7#s+5GkO z^~HDLz~4+2wR7OkuWuQS40)f6E`f1zi)Mj0=QLZX z7hj>bJWMoXkFxv=LiAs1eAn*0l?OW(!$tnAR8jW5xNqT7Lkby(TnHwK*`1Jo@@t)? z&yD^1ohRR@>37^01up7sgaExFj!qgApdAl0sLph69m6%y?+!zW#Ubz3drb&j3x*-r z>=rp2Q^Kw@7`WRpUc5y4DGRyV$a22J?ZXha!85a0%n!g@I*86a`y5C;r$Z_;h;K|x39T?Z{ z^FwGW&qmljElSA=ihp0&dI7lbIe5vduCVof;8A6h$$BZ_u_DlH49II_h+_-roH*{3 zTHMqF-h#q1a}|*diyaNg^Yt-D#|zXqHJO0rGmejSM;a}Eh7ZaUgBNi=3Jv4#h%xu- zX5%=q9fx${N<{4{+B&Nq-NlzJD|r_cjBa^|utV7S8P67+0NxF37>@om(Na z8?Fr6-T@M`*KU!aC?crZcA^`jE^#Oll2kRu0*8mpSlD2s(8*~1^0lK}N%Ne*!)r>$ zJ%t!Ux0|N!9VZn&Q(%w|Z(=VBZG)YF1(cobS3`Z{n0+4r$w+0Fu5ocM;sV+FZQu#^ zZAE6hz!Mz)?VDw9{^q{mxFdy5QE=b`Z+JAeT`-2x=pe^tI|32Q%R zJ=#$b6avHVyHB4ne=%ut%Nro{XZzJe2hBd9=E~}fk|LaAmUu0QJE>VG2Vsta z@P?3IO%fe}tx16cx=KnBC+x4MWSYN(+&FFBCEgE;&;4WLgHmAlrEfS%czq-|+VO~8 zboP73P$7p;i-pSmB6beBy6kmZ2&KF}D5ccM52Yy)coA#?FCH^E5O90c?R)9g@5kS} z+0AO#VqTD4Bn!Rde_46wW)>;#n>Eijn${y^2&IpkfM#GI*2~=>B&99WrKac3cr_Fn z5Hzo61pReux2XMJZO8k2&EMFaF`tZ$6zDw8^Vzeo@Jt}JP6p{a=K`cOKKccSzJ>p3 zy_~eA3H~+enG#d23GS;JA~Ywq2^rrCVagJRbrDm+jMk6;K!HU5>Rmm4vrA6vZ}`8& zT^f_BbPscxQQ9+kk=P`;K0HI*Un>3LoaU|fJAClltYbWz1P3d3oIuv0f;fhOL9AwP z!M)Q}D!@BGR`fFsyJB?o@Ko53>mdPErhdanCd%+^{{n)>*PP#VsNT$10cFM6n%NSC zhsR?f&z*i!WoJIw9L*KTtpHt~3UNvRii8xOvIfD>Ru}A&A-tPC(5c^;{6Id!7(1LT zsf1oUNy^I!)H~OChTnDX;5)~aa{l)HHIy!BbC4ze+Tu7@K->4&oGr&A(MtZIxeOmCN@-%$93V6^x1QOLy zHAWoI@h^x=Es%~K7zE;rtLer3xmQa=Mw@RpW*IF22_7wAch9furBMz#(}Fw79BHU_dVn_`%m67up{lb)3WAYM!o{hPIetE>1HMNtoSC7pbpoSc8d@rP*H zp4(-*x@p|i*{yCr6ZPz`=GTiE86;e+5u=OO;~=%LM`pxmdR`mcaZ{mTwfVHq#S^m* zoNT>$3foJA_2yNy%z%-7@Qiq)u^1+m0T}SlY8x~mqtdnmCV2-IxSdqZ#_3Yx;~KB$ z9(>&$nT~W|-&2YpsLN zV97TIqOqmS+agRY=w3;g4)<)dnK+(8rWW>R*8VIf$4nE~)jzEf$;ZbxBI0v2KPb@g zsE@^~Kpi)8efmS@wV(qIK|6InG#0b#Zp84i6TPl$gE)u!O&bc7Sg@uaS2I*bNo2a# z%bsvJ8!dgql&cBUxxK9yT@G2O^hBovd;@Y~$TqJs&5qb@_M zki!6L_6=e^;O%TRMH9isBLE_r`aE~WMzY5zUJvmpJqgo3Q9Oy+c6vYApDUyNIrz-u zgyS>Ki!Xo395JJpH@}=xU2689yHN5dGu>M+F?`ZAw!V*AxL;ADRh#Z;DM?>Xzj4;H z9&|XHG~Ip5C&H+&+ot&JV5_n*ku)EM-()dJ(mW4BoX^#*lNy0ZI?t~5IBB#P_QbvF zmhg(*CQFlh+FF-|*+U+5Q!beerxsoKLGylm4rlBbHe|!lp3hEo>&jufSBUX5m%0$wF(mxDlZ?KM{^(BX2{OMp zr``a9mn6IS6OE4frQCUH&9p%FS87_H1D&4OcSh0DR>E zTe4rj1y|zWwR!*Nlt2}*Ge$va#7UVAdmD$!C%(OSnA*9-$-`P5!e`Q`9s=pFu82bI zMCDX>;G%^++5_1d?uo`3ZW97W&!-DGB}a)v8IOYw&?

rA~CGK%6A*Dlgg>2?DSp zgO63POv7j2&Yf=e^;X7b%RqrIPW-a>@#rx3+`R@4n0uV>%{U~yq8me(N&e1Q`ccLXSxMCM&ep%F(|)xKrruHX^5w7Q&!d^CBVv&P=fmrs-84#5!S0m< z-`=dqi8mYyv7dCb;!h$n-4wtSOaJ2qkO0BRyqKJbhG9>tTSX<2#p=0_J9z0LZ!SY~ zGn}vO!0w-zHME9kpBvXZd<8v4h3pb?cZmQ}@#fEu>3Dn@Cx?FLq)%uB4>)Gt<%ln9 zDr80(F)yCpdIz!WWn6O%S-wOY`Ou@D4RMG`<0Cp2qKAdNdd1 zfi};^;ip!`#-005x%}{%_r!q0FH$=(A~{$$3epW27)>5xk~8yPa<1;Evtc(%-mH7U3n=z%H2&);hBml`iSb9JnW?Q8TD;aBXL6$h}2;zCmVy0 zAh*D!TP0_dJ2Rstmdd#9?TjIRT~%P((-A4xE&W3p5N^_5|NM3YCEv3Wv{zFs>~XdN z1vxC87T?76NfI6f8Nk?}TWr+7QZ)&|uhqJvR`*|d9B)ohqZ?N_55m9nl-C_RXt3RCaDt;;pU{uST{#${28=esuTEiKjp?k_tWd z4}D3UB~it*UYb6Kl8*W!{b#acgvf%#9a63eH!0QO0&w~jX(2r=@8Qnt2Wdi=uBhHQ zx13xN9#& zFz9!hC!3$_BP5>Se&M(qYiT0-Fca=c8Ft^|b!_2~P9CQJ&_Q_4{lwt8V}~JOVd%Ld zI&cPTt7%IiU?1TU*w!&jU>LC(WCuFrEM*#r+T;ZHKaqz0ivuByR5xTOzKod=o%ME_ zOiFzdaL4xZ38_`VqtrpGQM->iXly8$ z3Vu_a=-{APz{i*M13q^XDTtXpJ>@-j2ClsI^Fefj_-_A#ez9QoWm3&kjpPym?;BVp zawq(xFOYOdiD+2PX7DW4F!p8J9l^6)i~iW!MTkWAA391!Gc=eN7h`BZ2pFdkl2_9>InC0L{AdFA|fXH<2=m+PQt0T!VCxG_j!dJ28FHmx{%38 z%YWg~wT*N7#maQWO@(*1I=a4;jk-tPs~oty+`}Kof*ddL-Y<9viNka~cPhGDV{|5c z7B3`UTa$jXBoP{@{)Er`u2^G`x0IVt>~d<}N8vk-3JH>Ksi~>5kZn1=@~tg=$fl}f znJonqp&4p%+H)V_G|Bhx30*u4qBOFQR>~K z!e4gAjNMb@V7xY@oBV9#uM!oLP@FJJ7Gk+WXv!Mx^#?Po$VjkhN>0LKL~6Svz@dMw zsoX4z8tr?u1*?|Sn8FRW1a5-ODRm*!-0;)2?cq|(Z}6g*ZM@e>^qfg$@P{Tn0nu~X zL=WLwUs4U}G2C0haIFqJP46w5wyw5dgA*j=e|q|YLxjZNDWSl^ zsBI_99K6r#GK=ImH5esE<`@M&g|}0oNN=c7Qt>c@M0oOEg;|tmLHy<1y*i53tqp%h?}5yau=2;b^t1jpP>wz0{GNS;He`#EYTC6d2CWEqqpZ%bU}E zg_Sqj;&P`~-wzRV8p5atlfS_zDuhv|6TeO97k85l%M4s_7gW2Wp#^J&!CJ4PvnZah z*NRj{?K$NUyKmuvOYf?MU&$bPPnGELOuS|n+I3M_)5K}hq*c*#AOtapq#>@7-w$*6ZbEejzpWUYjh&~-p^tje5IgE<^ z6x2=3Oo8(Bm0y}y@bwfXAlz?NEN86z<(|xi>%?G3_22>KPT!Wj3TCZLB9M9ybcu>> z;3DC3Ca5DI`&UCK5|Ym#y@Iy6VSf;jnm|^npT^0?ps`{ab~q2d0gJ42f3_8tHmvJd zh)CYRORdpm?ki_K_G{W(D8xxKdw@zBTm6o|OyR13-*W6cwefq|7NUo2M~>avB2Kxz zAF-7z;CSvDZc^hu#*Ht&HU24`a8mHMNb>nooAdF zFX3HC8kLgTffG_meg#soK_Ibh2CbJ4~*a|1n zaS_3zUnmnje!j?OF(KeHd`))p{3SkJIifr39l)i%$`i#$O*juU7G8^=SaPdvWkg8g z!bF_e`AjF}hk4o!w$ywENNRf^lyReBeWO$k&m*+nYplHKzoFTJ#I{T7`z?IVR+!Nd z`WhG=KIh)>n)Ni0oT%lwqr<}=wW|%9o1k$T&j3kY_1t6u_pmI9j3eOUz@=A+TbbLb z_$;oN$Kf5oMzKOgU^7-N_h*VQI1=zQAT=nk{kKm!Gpa9RsT}>DVE%Ob-pzCqosd#b zW@ANEKnoVr6m7~51h39;>PQUU+|0jNH=m`GiY^?;5F{i%CJiL*3(yQFi3g~E}C4m3}+}iIHYeS2K4$oCy5O(J4osU zNBKjDC?wdjJ3x_?0?M^?>^~QhddpgY)CSF(PQX#40HQf-yV8kMap(`s-j-D zMSLx0wjb=fXSDk`0g)dVt$u7Nx00g&2@E-%@E?H^(=COgFK&01SZZgT>CM(*y?}{l z@u=A5*nl$7o#{ZXHCitD|9^Nu`PfVY$RRiMdvqifet-ca@lm0EL<;lZT~By_ z@kk}t74*qmN@Ye5ts}~3QI!0KgQoA&1B8Pi-RXwQSzFIk@_?iEQ?5?r2YPCL-ROrq zT4hHjvwD3>=NP4|D}NT6(dCPP5qNqYCve(TMl;1lVVNs+g2!-HWlWqO+;@1q!Zk&> z4BbDAE`NSRzJI;RV*iqxgSlkg=hnGn3rpVE(TK17h>ytgtn%Qf4H{)^IP|&I?-*v$ z>Bm}9k~%MV&)TiUQKYK*)k z`2v67x5+Y*rSOESSV!!WvgM(okM0%M#MO6So`US1lnr#bTlvtOR(D%>Y+!1u*}~p6ZqxEDq;41&Tz{DI)XkI|I({~W z+WlmPJZEoq%kq(gAmc#}T*U|SF`TiL3OGh-X5Kv}8uU&qY4H4vDy7H=#dp@ole>nav2XM%#C5VpbvF*z9j*Iu z!`-!arNwdVv!|E0v3GNxan@m-8KxR0eqFYf2wuvyRaR=lFn%4LFSM9;h7((BrI?jH z4V^j~yJ5s?G+qb}fH_eSq$y>)K3{lmTEN^=k8eKfhPjwU@jVqrjHU_~s`zL2XcaLn ze^yJ?;^l;35*(9yO|xzr)Dbp6SK$R@S(QB{NfUP7 z(keM$fd=5jrN#4xlJ*TtZHniY7OIRpse=^yat$V9Om}3SlF@&?cWEly=B6s)gB!-> z(r6~8p^5fqnc+>7_CZVy>r3rd)L9^yGAAv^A^fW32&&5z2KKLF4JD=(pjPa@y%x9| z8W|sBT(jLN(jFEdGV*qmZE6?0+U%HjW6CY!FsxFdvV%_7joM=~)2=uhJ7N&8_YC57 z%l7-v)muM>McvgVQ_=1@$K4s+zvgWH%$|yzZD3u?a+%e1cTRSl)L!l8Zz?O{6R{Yh zoLspS_crexe|5O4D)@m90op4YwyZ)AZI(Cid``Z6rx40MznlRsO|Q2x{h*4tfHPX7 zRc0e3F8fX?6X&IQ;nC10YH|$!1&n)3kz^i?cdw3iTl$tulFLjmE_|wiHI!eMn^Tf$ zp@@CZHFSG;{1E6xsfi6}opj_L`FvK(*er`XE*r{$i$UT$#v2XSs>C?oS73Hai_7x1 z-vreB6uo}*;>51#P;NPPYWZt*MH?>rxX)s!V$9CQxe7F1eghQ>e`6o3%TcE=Hswus z1zck0vqOzqXL^>ud#@`Z1&h(`vA{KK zpI0#vUYP}T_Pj<}(~>_o|Ky5g$&c9|hixXyOeN~{IT=fe9rDl@U6hp87j9JaAY3jL zqb=X!4xJQhj#Q?v!@4ije|c@mUl3nhKgC*|@u&0nG2a}IIFD;!fm>5jhWuGW+Ipcu zH}b6eoWFNC$B5TvT)ke~p)y@{r_7qSaIK%gc$m-Cxim&_<9m0P2OFz!e+T#Yr)dq7 z(AH9iX4gsfsis5r7^hLw5({zmsFoUBb7Py#HrP zipzB8upBx;ziYMq*)Mx(YL~Y|?&+Nrw(IQ;>z_5@J{%p18RhuEpIIH&p4YRdvzYj` zExWjf0RPsW?#+pDnD6Z2UXKnGDy&?drDq8D*Wswi?Pa&vU{|9S$RdJ!KGnfsZxKH#Ocv_(sQufWUUF$0iMy^kPBkS`7ZYce z-xjGhk2sC!8t~4yG^|fktZW1|cb<-u>S3XT_@{`M$T8C^4z@5U<7~{T&`5z#1AU)^) z9fALVy3|7G54ok+{I`tIi`p$V32uR8bYjB;4nqNbP4sy+bJcw{(&#+Bms{_M&$&NV zGh#x%VT&t*2zGu_Y_K)D?33}75ehusg#?316<@%cVH8E`p%xpLNVm^eJw^RGc z5npx#E(TE|zme4nF7h;|utQ*~X@C8tpQrg!O_kbFsZIOBu3T5KER^fUfr^!g*|_yeTAxM7!=WBG z2^xd))sa#zWK1CV%@L8eJbTLm%_O+=ef+)u#8Zp`$Kh`t9p!ds<}RZX2w8MeSn9FC zq^wcM^*jR-DV(gobM+>pI5#;q3AJht)W%Pp2nAOhcg0qcz46*i58@tWMiR~Htg9F7 zqHsH|aH>+dhDX%FEgf(+=i#Pi^fs6bc-R4vcQ)P2xjQ5;sW4TC>wX=sW7+YSOiT6c z2Q~`tww^SNYdbLJ8do{Npyj#5nt1}p3Iq>8qR@2wlUfqV%M%!<*nSF$dY9Q!-2w9+#l)|Uv2D*3zyQiD1r6XUYWF^4@kW?na(HH51*m;G}tP%O3Letc+o4Ze5DGVqv6eKB^_ zU^DK)NY?WBZBDT)504)9<%FoNxOH=W3QQXBRd+>rT?lCiBf?80<@YK4H?B|T6qpzN zBQe`wodq7&oPH(aa7}zH$t0cQR@!q|R^Z^2E#lJ^z&2i7pNsI99$l(2m}Zcyh&gqC zn0BtLv$vPKE=O6cbDKy5=h?7cO5~wJb!+Qfh7i|b*nS6Giy?y-;!NoLVco*+b7PFP z^_#Q0*kEz-CF?`x_4SwSdfWNzMx}N>$~a?p+UDDy9)ojOLz>OM8(y!@$qp$PX=WPa z!u9+&G9FKE6FM7KZ*>zqYvzctnWj{u<;~(`YmM5@MHkjCTvo{gPy&ez|iN z=S4Cy_$>dsVMxBys^oH5+z)60FvTt&ZzX~d~$ z8`{OA&#k*nx#=E;OsG-_+5w#0_v`Gc2q!B*+wHE{b?^g-RSG@9CAzlCq!`IJL-l#E zZ`q{9cqu7puB;7H#!<%|B>6CJMKa*P7*6n5)0N15C4pgo%G zzy-_3Av!w}9?b+)% z;Xz+)Z7{`<3I$l&D;h2&Yxac(l33CCjrv{y(`5e)se%E^g#9L4wTG0}86_-ikAK>g zUZ`C;9wq8#(Yl!e@ZeC=5Xr;9kh5W;2N8xCfbLc5IFc^#=l0%$K)n#)_G%G>rw)6) zfO-KGVk+sq>@U*?8bM8P8q$Taa`wl9@;{fd_efVG~pmoyhHE6OuD)10h9> z1Y@rF;(;c-33wTV98HLm3b-JzsLI@qt+lD!5itI4t5b`P`m}p1H`}mAtj2F!gtN9z zH7<-y2=Ua9*!2*td4**3q<9Lh${v129qX`(=i1hA&|8KPDykE zoRU}SRXvy9sXlQ;oWKs`pf<_~*g+6zCJ+R13NIXzrCb~Md_UMZr~Sll92cZ4*Gv5) zAshbDSN=Q$K_mIIM+aa#^<0n*PmcC}D+7SrAkX)?#AYDQ4$rF*2o0n_!x`ofSw5&z zRpi@WCpz_)FHRY^zWI%`-7$s4v$XsGUPufLOcH}r<}cabLr;9UV5dm=P(ck&S6Ssk zq_C%c4D!sBq1gfeH*b%P-Ous`{K&;)XAy5FhqwUCqrW4ITZFQ851UewAH~@o>!ZB2 zWy^IF3Co{DdRaJAluMZminJ%p*e)|408KeY(S%e2JD4FfAP7Hufd)tji}61F?~&k1 zC|iS&Kp21T*udYApbR9uv}L=(>;;-aC?0|+@=4Hip|KFhyC8@tHGAfNQxKYoW_Uq# zPzM-Y`mcgeWCnfQ7nDNW0J`AgB}awm{eEyGWG_TzI1m!f*;D+RB-~8o!jteN^m)?X zkpQ}oK=ERNSOy^h(MwRrr=X5>M)q9uK*FG}=svEDrnl=4YJ?op&eB(8SonF_*%K;VMtn7x@5!UZJ9EDuftFt?zo z=dObH)Uk(d1OX{^aFA%I!oM$LWrr?)VzT1TCxg#>6;ZZIpN5?f1nt`{diI!xo$}oL z7<*{oRXZcKBY$0KApKk7xiioJljfs%gBS~ThfT~UMP36L^Z`$~L}FcN8Y{^UIrDFF zf$df^o(tbolDPkl3jjG)r3;&*NQW3H{p~Hl@>85s01^@#6S*<~;gfdl>Qmx>Dkn8X zd;doK$rU9%idV-%YQLF(T1igm(38(#5qaPODAR!pwkHwia~BW_F#~*I+!A1~t7n@? zyez zXO{?0kNE3K$kp#e04Uta`%RT+Acp#DEk%Y>1A6{cp9CvY*#4FDP@zM=!vrI*Y&;Vh zI4QO4|GE;M2|B=p3+Dzz!VxA2iG)LCkPr?5+Vlc03nP$2!((I5f0GG^zt-Brrg9v73mKT+89V zG9fe=q%GHR>UB4G?o?|-ZU`j~AlVDsakbTcAg^Fr!ROy&0tcl64si<66AiDT|HdK( z0HWPa5pyM6-E%29to3Rt)Xa#$EwP))WKt+WG4MFO@4u%BpJfQm4XTYh)u`hHHGBR> z4vmN$yzR@?Av6oi6wM%mS|j*`3Yh>!EfzfLkCouxb4$_6%s<8^S=U?UbS@af#8)qt zkt(N1NjF^6l#9@lS4CNd}I42SjT#$){$_$k}FeC7!IR(Y- ztuJShNaGX4Gr~m%Tv`uc0|PqtDR#&P{-anbs-tK38}3_$i^5@Pxra6(oLuT9&!QFw zv*Y6DD`LG4NEQT1A(9!|q?4T#zuEYFMDZY*Zkk+xqP)N6Q&L5lPdfF67sL+GR{Gh5ZKv$EWx-4dlwfqKzq9I;uHG>>sML2^pXC8?E=1xA(;7Mp16gH7PV&z_ zJ~tPi{z!29)!!++CLF{XlWavCh&?`%d+i7Ih~x?W5T<|9`^#%9LFBA9^DWg5KDz~< z83%m$*I}#k!8Tsr5tHveY61_pZ+B*CGfhJssxT{_2%=+t7n$*WO9ccPVD<}N!4jIu&op!f&!OE*|+MR46L05WmoGH^by zJeSatb+y%x8@dm=Ba(-mi6=y%G&c2l>~oOfuN%eb7pA+havM$iAq~5CKQ26se~NZ| zjs*ZTm(-e$znquLP~t;C*9Y5pY!~`G5}z}axlT3_ zy`fg)(_33?Yv F%61V5VHJs%+gM4%_TJQ89CGG8UG_|Vv`NY zCWGB&cDxHO=bcJ9GT-w)j_wdPS#Ejqvg3GJU_$%$$8BKjq_BZq9R@_kuI@Lfz6xwv%Mp=jn9$0j94yX<lSmZ&D@9e^?(3}`OD}$r3kdjvAv3jo-a~9cO<3WhJgcmTmyx^^LhrX&DuGX zRs%>)SL7#at`u=pOvd%_?_K{-FdtFke-#j zs<*ba@=p1(rr(V_*2=HZ?rE<00=eDd^ii^f@+EFbChL@giz<@4!(R5sQTNCg&Sx$+ zJYqPR?r0sq+}M&7f86*jkHvs@bG6x5wDWlQls)~O&9y~-sht7-$)^~U#`+mKT0@s7 zb3!{B0!y`3lUw#4Mp~x+yk#N$?vt9LyVVJrn~&HpYjqcnLc5vovqh4)-BBFF-T6z? z1-?n0>p9QYl_JlU#=m|)k=*fo?xiNeHqRq4pXSe!po3262b30lGi{BE7U>x7q4k1h ztcP{5*`mr%eC>B_C;}v3yF>T(22m&Vp7g9#kP15&YE@Y443uOlDm3ozRLCaPhz#Hh z@_jaXW3Es+G9}idR8ZY3)D-=&rI_Oa|zmAqgLbr2BlrTG+v=`#gVa8*@(b*|?O)qSGw2<4;-iK5=>qp933Y(4n z;HU^st9ZH8z!&;Kq^BW_f56weG9g-_(tUDTUc%*Ph)MX;J;-tzzxNZ?(QvlNaj~-+ zr##`KULg#v1iWg__M{VVk6p<=NEFaSYr)ugQssl6%h zNv4NayGj|YiblE0{WwZcvsVJGEJI45M<)G8U-y7)vV@ZO?RR8Fvaa1OOhD{0&$?pJ z1d-0*g-1@r-)Z&)TK&H)P^MT@p-jOI`^rn?pqi~M4XnExSevJu#Gc?QZtL+-6%M4& z%N0NJy#3iw#;EI`CCVM%3`UIjgIK3Wfzh@p9C8`$GBuH#>c&O9WzZ#|xtJC|krMws ztS8H*Gg$2ITIlm(lYYy$l6GI&BlWU+CfIP(a#E60k#;{`J=2>_Q*l!&j75hzj0JNG zh6ZK79``ta)K}McrXxzuXI`cbQU=fjwMMNmXXUiJ#ap#qg8kgvF625T7VHT@KCM*Zp!_D;i)!swi^4-cJ%@zSplq%1o{)5@Hd(8gy zi`fm@?%ZGdzS531+qARbCdHN%Mtp{|oNUaeM@Q_m>ew*7gWU7;cej$n0p>9B?mu7- zT_uq>Rdv6te2pM={}bu(ZYVHw`@yhDwd4M(8m)jMU1_y^7Gu}@BTpuNcs`=j%`dK1 z$5FQ&dlqYJy~fSkqQ=3HL5QCEwAk|bgWI*ycwyOVl3&xK1tx_yxB`6TGg&fK<~f;K zciPFacrCd<(i4#(y!O}`Ukgvm%qiv2&NdvemL}u)*znh7{F8^f{C03iS=lu&RIJVim|0_b(2}BqXYVj^ zrDl>rRJD=`YRi_gDB&8nGvH)OH1J>1d%cpk_oYki#1Rx9<@U_P>3<`EDU_o-C59T~ z6i<2f^oxMKljK|59@>PXc3Feu7oO+%0Dqsayg}uIaO;su#Xdd*-aa7)OKy>zoQOan z%dOZ8DEW<$;Bh>lN8f&0^z9UD^d5eyZ4APji3A9MPM$o!=zE&pN=&!gqlbSjEGbb@ z{%2lZdXr)(W6aICPnEu|9}GAZ@(gR@)@IBV+ad(mTB_n#+AXO}0`@RMqeF#=rx`7JBt-oEmqxb! z!=L9|d$k2#LpF&QyvB;%qSc<)a4L(xi5XehmcU?K+sS&F6Mv!5*8h`>da}$~n|Iu| z^wS1yYfDYpueXi3G^`INj7xCd^p-xp=c1y;)@kKemWPHWu(IKi%Nr%Sf8y8TQ4nTr zk+uN7H(h*fLY}tgoWA=Ta*NTG*ZqVG^`id#!VeN`^M$5avtuzt@%iRm{p|*$&i13> zXF^d&KMg`-(Y6$rgrNYvoOv48#C2b*xV5Zz z=%`BiU0C`!;_go4y!KwP5Kj9#mFz3bB3|N~Q^VXXUPy9>NS*rQoh@Q&8!c^Qunp^` zz>?dzhbk3DUMf%F6^c1%N5>=QB9fK#^tAR8Zv@@0tqXEBT-kQh7wx1`g9j>nu7yEy z18#~pn1cYO1;^>nvt+x0SjlP{*W<_%6$g32{%7_YB%SbQAN^>+xBf*-+sWp_7R>To;VLt88zmEgro1`cyn;B525pFyR1Xf zC;aCngwD^w-8HP2nBK-ZHLQQl=`X?}PrTPoK8Szf*XQ@8oEz5fPbz53AUtLfI}jd) z^Y=Es2{oEZWM%;1BPe}N!>;$|NGmQA$NI0nf9m?^dU6^=#%pqr)nWz=J<0XEG_BC{ zHFI`{IidePXVgQ?h}}+wlv>tIZDBO}*pz>O%K?m8*XN|2J7a1R?4^_JFXVS)wGBl1 z5GhH!>=DZXh_trbNW_!E{TkWr`BX0G5`qUxq#5BlAhG1OCVIjIU`2k%amNi1DSf{i z#)QaGnr%;vk_)CmSjpT|(|%m=27Q^dL;-t``!C35DW&0VK^^39I8=)8JY-{y5^1;; z8NG_OgSzsSTO!bB`FCau@~hG+G35pv3YeY!vEuKPuajI@QZOlBiO1=w4i#J=4=t;) zNv=}_M_o)VF4iR0K;FI?D8A939B|ass@-Tg*lj^mwbR0U+OSJ*jkKz=#sFGg=H>v4 z3Dutc2bLjSXq>2k=RW0ubM|}#+a+s$e>Xxlk3D#Pyf=CgzaRwpamRa< z&>sJ3MVT{9VCbKX0Gz3y0SyD@79q5RXQ25cg~;4Y*qNx!z3w1mLsxIFuJg&(uFl>{ zaWmSS*^#=P<<2_Byr}Xqryu#$LBpsYDM(v*iP;LToStlT;&OKqjz^WBbY<|*P@#&k zxP2jflaC}+S<>zM*X3k;ck_AN&*C%7IeBqZVpi$ePpQ|;ipUu1nt&f7 z7R>wg;7V(t)_hSAzVQkytymNL&cYl((;AC)!puM9m?fR zwD_^tCv=p>)F*%7jIL~GU+U$t(HmNhUh(ynUn}m9C_^s4qif%=c-3jzyJXAyEG8#Z z0hX;*K~3MQdUI;bPt6X|7y|YeeGtH^qM4?s70^roMUkcXnB~EjNjr%&{7~HF`N!uM z{_=Tb)$lNC?)XQ5i1tt>JBy&{bLG9f-KLfZ*&){I7iDjI?=@imlpFEo#222Jdx9bb)L}eAS=_fUA}aZs}@P> z9W8Nf{ELajYQ6GN=;HSgdQD8$H7(6MVbnnp<{Fqx*YvZT3>lC5??TsWH+2w_V{mLS zx6%LcRX=Jwf$pc??Xlo1ZytFOI{$1xXm_0rzoQp~&Vk^#T|d@49=ya0Q{1i-@ljw7 zb>_c%j6BCak#ZGL;;y}P65!6a6DcwBGxIZDH3ZS%MS+y|UyxQS#d{S=Otbprx!5UoNLKa@?Y<}t z3hmYK?Kb8R%E;JU8}1@k(wkkL(aPX`7Ke8Dw8YtDZW_yLKUK{y&+y>Z$hawhk7*jM zgJ$gSbcoG1_1~}RoBCP!0Z8%enYe%Jpn>~ zfES>Qy~J@-EL8(0Q#(d_kLm!@Tmrto@c7h2;>Q%s=ZL*DzZfi&#fl8s>CwS-JujCT z^UE_Cmz`@hH#9}(`#RbECsREntm^`{osc}FOAJHoDr9<=hc(DW7ah+&jzT;1IC{KL zohuJju3oej-5pLKI?fsd3VqHUbuWF*Vp;8_He$d{20tS$E8PPmm81F(c`+koB?=TE z7%k~~^nZ{|@fWhyV1|Tr;=qCBQ;szmy&8zmHG{>6@{&uK<*sh{f}TCJ-yk~kW8U47ZQWmqBYI8dc4=l z*vtDtz#{4e0ZV%D>vTfrwRYLHq+$H$mIv^uL-+`N@V7pl_0@Mms$&H~spEOB%b(*DhTFtG8B+fYKFnV+tSbpA3X|y& z_S$D2GaG%`Yc{GeESSx~Grg~MdI-PpWIb?&0MGZ}QZquG^>*2nSJikCnIOF>P2U0Pxd5QKr;jX_tf}UK?m$$ z8p8lCMRY?U+-azy^y4C3DVw$`0mvNx9eu<7M@^SNoI^_U zJ6ih7Id3-wNR4}>B0mR;A^d1P`=STDSl!RF0HXhC4u8JM&lr)w6SPWC@CYMfL8^}y zz%kSiRl|Bf+sDlz-^E#6eu+Mz&RYAVdNMS)!8$qtzz@rIA!v6=5QRVPDSQ#qH@58y zG~Y%>;QZg|6>tI?2MMJqzY&`okR)Nd|rR+C9Ld=1XWKyj}Ov7q7zriTt8 z=_HEU`VR_*orhY@O=2u0!BMb@dX8|+pw&W~9-h7xB7JhjTGuwYR5-SNfQ-97Evb*}? zG*_R4PBC{VF#Ci5bhqMxEUp+my$vTMavK;YDL*E8@C8MbaloN3bQ_uljah*M_hLm! z34@VC|2~bi>4?|Lm$he2P#p-IL{Ogm61bOSi~^rruD)>nL+wUrpypRS-Aag#r-wYG zRSYzvzSZpJesXt``$EJfWNtB$uEG=QaFmI+&8ev+*v+N$35=&HVi) zZL#Ysd?AZV8%FOUpMM^zW^0H8mfT{Mb6vC2ajaU%CCJ+Sc#hwh*sl7PE!KPk-eiOI^hB!7=@Zz90*3Xi>B99 zbtM6|#H|2PgbyP3ayuwKBtuiEoc{j8UWSW+xO-I2Ir})HRH8{Cm7%8f=rt8s4@jG#Lw z(T$Ra@m0@qCaDn4DESZKW21h;O8lAUiqlsb=U;L=={KQv47O&kc8Uvh83F`Bf?r!N zzEHR`+OWRn*00NlJW)|xUGjCuD38PvF1GYY^aJ2&3LiFzetffRFU=l}T_0V{zsd1a z#noL^Xu0M3dI~G6%cCxcNrtjmcC}361U5`q;~ggWwtjqNeeO0G%$>FUz7d@3 zux!wpVaa%+V{a&wq1Y_OPVf^cBc#V@YBwWsI`fNoPox21bO@Sc4MX!SVMOWG0u&vQ z!+N{Pxg?}{1bz|`Pkc>ZEOykA3YjQ+^UO~kZ_kCD3NpEF`~ZP^9=vX>N5k+@mAAR4 zYsq=uyPF`qjC_-B$WUHa9)ENQ?uBW{r4K=2pFaSXzPB`NQING*prv0K_0aB~U|q8i z+)!{+OXLXr4jE6BMkXg86n4JXqb{v0CHL}TZFAvZ3y;!vAP|~Xl3)~{?^D`!5${^z zoL>$_!GIZXs+!3+@H8U=!429!$JX|;&RqI+q9Y6sw&FrM%RHs?@f)x0g>1wB`k~J{1g$<`3 z4Ig7AYr5jFk`hXG0w`&x-FvnB*kzC_gbyp8`w)HD8y-vr=7-#NqeHl1BA9#)&kdG6 z{lp1MnKrD$Ju`9|?9#MrHlY{|h+oYYtAI7thASv!9-ev1LC<p=E!{=PZHT_Ba|Uq*3S>cp{=1p5)CJE$4Vg10F%ieKKu@}gA} zmDg*$GBE^0<#qIJH#vblGFr!a=z1XsezeXwaJ-DEOx{RZ=)Nh0P&sJ1U)Ma9@6MC& z({fPss_1 zsmTKHkp+a(t8ONM;H@b>8b~8`i3C?_jeRhYARV!W#IvvbTmRK)eWoZxI{=(;!L9vfI4*gd$Aywl#K+DFd%L9@Ua4q-aM)uVkicV`bog8$^iUI>a3zQ zaSDs{trw)p1yK|i>4yZ5L90i!K0q3pRQF{fDBuR@`1c`^7l1{jivSUK_f{bQtB9_0 z17e`_X{s*B3`R;!y%jl4gK*LgkSHIY#CapW@(92t=&5=}ym0=r%lQCG6NHFHft62( z6%?zUIamLDC*?(?2n{`rf(ZamTqzM1LN36a098=95-bkqgV!o7(j~$!k1(GOfnB@` z&tL^;g&NT4lOq>}gxXtxw_3K@e-%+7ETElm(ANY22FR#U!(udWiK>jBcq+{em#B<$ zCu2ywiV9S&ynzLqVDXqOqQp(a_>}>jhQLaJ06}Q6u{_A(io7%hKt$|TH#1=@%@Y{c z!H1?+$8(q#9@p;|smNZ2v1d&H3XRErlYyjGUxWZw?dl6-Z+Ir`YX)8Xs?_OGFP(NaXn0-3d9jAB%@vQ0Br2rszvZoB zg1I6!d+OnINYG?^nc-r!DgJ=o=fwf4@S%>3D9A*H3!bXe2y?R zAp3dF)i}fy?*ZLK_rGx=#&Qh4%B8!5v-2pZJ8TIWUk4hG9}5K7vJ)~KJerRrI8JfJ z*a$VASvh1s8tUtWnf~=+W>+uht&)36hN&0*amhwC_yf~U)k-{qwg=sR1aH~PZWB*% z0z-aH!SMr>KWg=O$`&{rIe581DYqj6e=h`FWqV^(GU6-M;H$}I8;j5uy~CFcK6x7% z7j5&2lEUXK1W!@f*GZn*oak!g*s-aruqwVo&xIMAu+bhF+)X?=fGR z%daA%9}t~ZU|1@6wh*q#=}ao8Wgkz=h2?BE*MKrrm)3Yo~5iwOje%_{i} z@n8Dz?|c-a_;^tUu(?6Xa)husm}#=)=28r&E5ym*=LNw9%dQyN5D8E+pZoY&w9k94 zqWw+bK!l!abG}Q@Npn<9XHh&2&;|304i`Jjo*t=mS~C{6Y!q~!V_J9VEkeNeAejFo z#{rO|scCC4^3R1J$H=h6UV+z@ThTJ z4|XFL{o`Ps2%AxBKa%!=(60W`2GhqBk85G2rNZW@9z$Q1A(Pfp?hWe%M?T>DxlKXH#z$^#VwE<`Fvf&U>h?R~@H6(3I=B#+ zI07?bf#1pz*aLNYpM8x~X4bL5UmXzZNl56QP~pp}V#+zp$wV9=5 zxU>DYj~=g8gXwJQ&bZ-zhMs;WuK*29g%jgf?^POS6qoX4iEo=}J$RC7&(`%pq**&{ z>5qGF`H9ry41Q#JQyWpcpMEhj_XisF3$p(dEN0q>nu%?tf&7<1*;nw{gkQb=Fsz@g z@7ophi%-;2TOlNDO064_pFkV%Bh!#xeL&}h9E0}IiHHVm;G(4=(wx6GGa}!s<78_x zrlzV>fv>B#1VqCRvWB>w`vG7rJhsU~l8I8(-*)H7sp3F~yy1T9HIHz5Oe8;wn>XC| zC9i>Q_TYo*q{{DTLkaHf!szhfoMjm?$D-}#aI0`m7*E?-GNr-Xr*PDW;$haI7Ut=t7VwXM>l(UnUqY^eG)dgZlG3-scW8Q2oEZ9A* zZ>yUC!&y4wiy9ls2>bPqp>2?BHMW|LjK8_f7c64bjR0c3Xy`dF1JYWdZzeD za;mG7lE%pJKyRk?J&|$R$up=aMMhJSx{DT;UFG||V{&U6DmS9q$u_iVY>0@c@*usKVTzVwZhJ%NG4qAj;^)*RC)xAwC>FaFxN6;?<%v+NmC zTIbaCpkGpQOOVrBvSicrxa7X(cG8OX5tvT$4YJW|Xo`E(cMrSY4tuozhQFWV)A6mh zTn84D!SKA{xif#D>(_$ha!ypo{X9}iQgop1+|@TYF5v1dSkQ<3BuNh@5cN-sYk?pF z!XA}T*AWdp9(aU0k^05$$6@$(DlvR=Teq`{e4W-+B?<1se%v>HxdfX3f}&W#qbN#X zaF38>QmI$O_8FAGjjb_U#eQ!~J_&g&T4v>J??#`RIp*m2W?gQ$WM!p?p~iHK%1pu; zRB^k^+UU%R7pg>|*kmioxni9!8uiRi^~mh5Pr`_)7Iyu;ANgY}Ke|iTwX>G;jegbm z6rnG+v={7&B>^_rm2MG-8}Box#0xUc-0vF{KL;M%j?ly{F9w}c-@$#ETBLfw>wY_R zYyDk2hJ9{O7ub?-{nNb}%6h#%JG6Mv)ejg3RI4utADLNY4?^ZET4!w(t7R#JYUD?d zj9Zxiwdw;Dq&$r#a7V32Z2d!C7fTzJ`~7aQu4Ao1*xI7`lf3Zj53H{mhkB;GJ(z?Z zkPhyzV~(<&#g8mVwymCf0wFc1S_?n+^2+J!NLUU2|M&jn6P4G!q=u+ynF=lohRdgD zy~NAzYrqlK5_{E_x?zSl0bh^sL;h8*?ML;;_13i96Lau=UHDL@dX)Y^xt0S z&llQyoS#A>45Z>$JpmPYM@at7e91>fh5qJVy*Q`=GQnYKo9XX)8G<8$^z&S#gr$&H z<9&k+1o~~x!EXb!0T~~aAXDJnWUo&&Lrig^`^{~n;{CfDRpCIU_@~_ey9^YJ+P6+CqT{V$ zKtu-m8+++uUiARsd{15cQ zOn?BU`WGHdt0X?b22=gLPkJXY--0VbKh+jKY4W?gTj2k83S!u5q>vOT{y{b|5b|pb zr-YG9({HL=hcO`xE;T-K&5;ti<$UE23LTWaTo1XUe0*{4H&=uA52HSb!hf7WLAdyx z1CigaA@mlzcn?2+_xCmmmqbV=G@Xo{VY&4J^q0(n%_mTfK6X>%Z`R^3_w@UiboMmK05#!hoUr1K0Yha}RDAsOLUhzZygSZWz`$`P zHdA9!^ork9hU!rQLL&IJJZaB;|K)$Ay-6O{mA^SSJWrK=n&3_H$&+LTr(aP2xb-6R zhsxhP|6f=5$G>>4`?tdSne5CDHF=%;*gFC}4|zYZJ;m~O@BPQO{`r48ZV`_1Tjvuv zRS{VzNdHKGdhm)i@dT0hi3v6|_1|vcpI7+D>%MFo*?aEuvLGR5)KVICBq?V7@+Oht z)U$uVihr?=;7iyT{k{4TKChEh6ylk$-gM9qiV~0?6eYp@E3W>Fr5@JxpJJ9y)Fpf* z-xK0wKsZl~UbROB5$qRk?JJ*=r~Qzr#j}DF{yq9A%ua#a8tE*Zt|s;p5d~RT$*ew; zmiw|wZb&gSpKm`p_HC9g=)lU<#Jbhr>%hODmV&wCB2XG|p?4unItQ58GwAc3-0OM$ zdCnS<(b7HwXMY?=fd3i(txI(_-v4rue~9Bh|BqKAC55;}Y{7#xA`2Cea<80>2eC2H zQATH(=O^5hN5|I5N9lLBh7y+l53%D`d)XrWhd4XA(Xl0Yrod-RF3kU@h=w7XQx~_r zX(xC&q;Q(zwo|PeZuGyY8G?bHU)08*mt11MZV5au5oX!E!pxdKeRuzOwJIvC>}Dah z%bJZ6#WW+R%_R_q7pv{s;U5(VvQa|he zfbge4_?_oPRczP&5yCHWZ^|&U{`l#3)GztkMP8ewRYo-byMqE6}Qn{(<|eV*O(0~SAtMtUJf~}Qts14oh8D%*i>qTzQL{k zdmkn)_vU!ZYoi|ct}nJstm5=IZf4DF>3W4#=(W3R9bvQ*wq5DBeip|l^rc zrlnUq&VKo9C9?Giw{Bv$xy?(Rt>x&RBi%flV+wfmAYsgyO2K%Wjjubs)v?1U9SVPx zD{lm^UWmbV`ls{XLuNK31H(}+brP5Y)#n%I%I7j~RTN3sPGMhe&2?3bWV+E~99I9| z-JC(0{_HkRKy-U2f}}T7tnLQ$|HIsS$2GaF>!OMv0tyNOD$PO@1SW!jlz@||2uhPC zH44(3)KC+_g3_WC5s;!$L8|m7M5IXv=`|GTkPun|3CSICuDQe-YH^p~fzw3;V-^?uktNuDsbMxh*-q#h*WfYV4TIy8r&S%}rkC zk=_{`bWC`&-7o%9>Zh~3T=ZeCHLKvoQW^%+vaxM6`_j2VN<@E19^EqPnM<4z6eG== zB%0@OqF?`Eiy@17wU$gJ#AYrhLv7tEjLDwt@xklaZ4v|FP@T7h?(q1E88dvVrr}n5 z{>3s2arotDEj9nM52e6JONo@$S@gD{~Nf*P?ooSkE0#BJPYjq23e1TKWZD{6dOXHD;5~jIq$Et0DdY=9N zYoXJ5J6HUuHOjhZ^o)N=UVDDYb$`<4vPs{BJ~)aPrJDxnt}?;p5GyyAtXGCh3gBav zYuC~voWQzn!&By96KBGju7pK8dVEdzpez8x1O!JEVn?NG7K*p=H$ev|5P}lb=}D_8S4CEZEI;LKdTnC z_Nq^~YmiRlwXg5tv2{L)qx^`CNk8HnMzgq~GyfQ{|0Qw!mw2CU&s5CHZ%Ij!BINLR z%hMm~%>kjIoi!@@nCNi@LMV$(#1->Wh37c|aXIiG>c5s-s&yVes=Syuy_k2X_aS(! zN@NU#-Out)#FdBBqbxOs6CNa@vvvQ*d4?J0Ure7e5g^d)2&lu<(yc&nT=e;|QFWKW zcVvCVW6E*v_$YN{I=|x)@&i|#_^+j(YUwq!=LM2CQq@#gK>D;kzYti*e3-|_@Ng&D zarYR+Ny0kqU*!1j1f#Y~dk*zPCwB|3c9HfdNs*>j4!G3D2? z@cAnsEl_dzZHzfYkpra9Mf-a!>2et!AZEtj)*ZCZCr!%6X#1kRFM^5H5jaZ(dv8Og6Bv?heM7z z{FNIIeW7FI^YpWuK}|E$KSDBJ|5Xdp1QwLU%awAr>nITL5$QI!LST|@kC4|&IU$vk z;jfeeuc6k<5x=(fOA=u1J#{EA`ha5a&PaYMd5wu9AqO<>ebulTzP){&IDbUY{MX72 zCq1w^2N|y>9Flzsp84=_@rdB_L&sSJ#*&x>+Kbj+X#W07I}b8+P*r%|_6}E52YP?0 z{1o3fA57k=H8e89uAmT-&or%b_XztF%`%jbOAU#HRZ zMx*!`1h6Iq+JP$_d^Xw0^eaBk=@xjJaM;z1L$Z&65Y!JBB@60_o(?i}c>Cx-)x!Tu z#%dDGz}BZS=Q%cs6q!HMhg99F<|LUFo^95u{0bSaa?m9ph1)@i9<~dvq zlPt#|V(_l?;x{>C2s^~-!@b!5{Qv$JQB}={_KMTkEc!#Y@!tTtG2s)k8y3~_2&p5w zT5jtC_W!amMC^h7uQ|~4WO_43WZq79LxEFYi(6%7D?lT@(HSc{{pg0_=*^gD%Br|! zFYVsZW?Ztu{%euBi;oTzWb#m$|Akko8A_5Xr|1vKmeVXjcVC%qddY)TedlApDqHa` zML%!MI}hoZ#|V=$gFKxF|6mL=Ov|v!fPN`ov-ry>0FtYVO>B5-6CAPRhv)5 zt;d&7{(8DLZxI4gTA>JN1QVL52@2)UUQ$0?fE_ph+_9IrUUEO(V>%MQ>_u9^TpKcS zaS}xf5R$(bAiO`QElucqVyUE+T|Bahf1#~afg2>j%s@mxLqpd~pe5#FDF$*5tHuQ* zSn4r#-ykm+x%+oEuwzwTI?ESmw%L{UrP61~dMHLn+Py#0&tnZe)yE)JW{$bC$Ne|F zk)Auz-MVgPZ=#ZAoMw>#1~rdn{zIkJmu-?`TCJFr)L%bb;%u|Kvw7)FK4RfX2()uu zoC{Lv{MAP~a8?$Lwms~RCD`QehBffJk7P%_%%T~MnhBHg`j2URy$vEVibUvyq{-!) zPHz|ATpq=^r{Y>41y(EmUsjs-6++ExQSUH+M|a%bWMN8{6TZwtD;H|>J$3(}~OeDHpSIj7(y!ZMsAhWxrvikf)a9cBjJPh}a$GWkX zdzZrXt=RH886J6gEAGVSzJ6B|J;2A@PiJ)Om5f)wO*nR8d41vSHqybAD{hKXmh116k{l*sUn&u~+O7+yC1So-*4K z=Tc7E{vKC8J?pIXxh^l)xE0=!=hX@g{QgDTV@x` zO9iWT^efLSyzbvg=y(C`+#C_%fGB>BTGe0cic$XD`!%C~4)aaAsj*81W5r^)^V9w0 z($BUh9+UY{eIkOZ=F|-?spy&3gaC-Et)WXrQZ~u5(0^V>>OMK2G$)LcD9Nrvf z+>tMvVO>Jxj6I+G8tSOi;Di?!Hu&Fquz5*112P6&P=6T$U|etW_R5kr;)m(kKTGzN zb{e9!!!{^*@W}W@4&`A5<9xGt(-jAQZ3g6q)L8xWK+!HMue9Q|=*u+|!tOkT^;b&H z0ayHC+`Vh$5vOd|=|_au@gn|?Ek9_GWsYT)+sc~(?8>2MhkAWzYu!y+fG8-;@`eE zGnHnZG%R;E0j9RGG9VQ(RBWd$98`Q3c(5NH*%faP3me;;L1>Ufgdam8&zE;UOI+12 z5wLLbr|<>MzrdHmmSbVbird@d(jzn{nwk2={0a62n%H|@s-6R>!tR`$L^I7)-Svwr z?!9Xmv}WgK{w{uLUKAbuXjru)KR7KqdTr@?=I%6kn6U7F!>@_>txyfkY|x}>Y#-Py zCo)w|KE-Q?wf%`yk0gW3s{jkEdJ_5ym$IEO8{1jgrX?`MsoI}=1J;z%YexNkWzG38 zx|$%skBU})Ghvs_2g#b*hP9A7qU4X9dM(eP++r|D^Y=y!NsLG?sQ?KqIyh)++uL$> z$h&&3C#LbkODaX%O^vE`s_|_+k@Nleg?;FlSK-D}CUGC$9UyC2iLZqmoC13Ev|G^K}9RMi{Vz&o3m9E}c>_GS)H#dzn&v)1FPf===Pm%i*(06mE z7+vylzyW{?*8+qT5bTQ#XsPubw)b%_)7NVEHc0Buw2qX(N4qZ3)RSeUih z@OY2qOqT^n5%fLDqb!n<5(iy}K0EpLq3&&-6QKDOT6@M`RFQE%ooNV7J#3-_O+p&$ zd1NM0iC;A?pQuH>e&h~5*!vQE&^0P-d~YSx>JznsiEgfk2kpOVKm$-yOXg)rw4$AM zn%SSA0YKsSn(Tz^6aCTv{$;+Yq_^NBjgr6%`cZ$t!!^8 z;ETPOb>;Z;G==x|q z+n1l0_EsWvy-*7T$;HYieT|0IwzU4V5qH`X>smB&Etfe?>s5kxUoduJKdtxVixr8j z6_hy=4rhXnhiWhs{k|V~awm0ARmwG9k@_#{rGHAOMUT&m`o$HW@ST4lP5y*pIi*{< zko8K%#_UQ3twM-93ktUI7)AO+hJv34-~i;qyFNxp^5*n$0Y zD*E7iMWV9;_k;y?$5({~943wEp6F-V4 z^y_XS@y@kj9fYNW@`g2*u zA|O>yjkW>$8U96SOGzPGnKH&O=hSPP|5K3EmFRduoKKxMUzx%R3U#RPe+GVhD z+qLI_W_PYWC5}f~YnWfw^Cs`box$0RW;b14!cSD|Z!4n}Auq!(($QD`p+kQcR$;XqZzZEi;vSvCr0Mvene=`RU zPi=oj?Es8PavlV()tvs6N|2ymuS8GVRiF`irQmCZ z?w#7>c4^Z&f{4e>#_Qo1$!l-|QhA93k|Yw;tBsn!NWW+Rlo`^bozK);t=7HTO$7K! zPvBOI2EZ*`mPd(0@OOWDk8ii7HTy@b|LY+9y;-D}Df2{a~`TD>m^zAcdnn6gp&u{w>hlgh)s-{d^z&(zuUew!>Qf|bh zhxmhGt_k17J0v+UdUM}`y@?eM8x=3L((m;gd}-8ap!0`N%lvzaSG^f(_FykU4m=S6 zcwlwWzUh}sz+`DP`ftpKWIq8dI>1(AE~0mXE)WD4o8dzOV=n;2w|sXJmB-32^aj<6 zAf}wC9LW=6!@pC)HPb)O6R)TV2dkNX2DVDY!*Gn_FEjd2MDq7Pg`}S88mdM8VN1Om z){uFQrB0(Pde^iqS*FPTO9cxZ{VmXHc`xh@Hcs(Ix&v{37D(`YYSEg$$w6fJ<7ocv z9+dQU!;vSNDf(fDk!RFP9i_eHN4;-ER(t#&QCO^mgUr+qF7Z)csI=p#xEI8_Iz)I) zFsac5y-_jWC%!E%I+X;CjJWJIXIti_$~uU^DBy`Ug;i2FQ`yUOKA)4^S>t{S!;KFW zGL?<-Yx*zg7JluiW#oG<0e9SqJb`F^$2H(&sal4187d@BBJ;nk*yVfmlg2qn%bNlP z?Q$daYn-jq?-yjIqpPs49%H(}Q{)rM4th0~fjsh-^FTwJX_1Wht=-EM0)dUY*VXF&R$@kzTNO4&VrKxI79n`E zpBx*hev$uukX?H!M{|$^M5kf6q*UBk_i{)8z(TXa^uKHD$+bqE@8SfT;Yq!V0*DO< zv)<#MFpI-&;5DD{1<329%Q2if6Vw}Di^{hk4k<`-)HDYR>n5J!4xS#7hK-Xg^eLoj z97G7>U+cfUdv96>N_JAlcV?Kyy&pOm*sg0cP_`VSa+N)Gd$AO~N!*r_dP+#$d_&x>szj_1zO)ScLdv=3#iJs~R&!_5 z+p7`D-1cR$H4x$#zHZXyZzcu?2E6{{CrdxX(g<(7rd}86bgq<=s_!j)_rna$m7K`1 zK9V%TnT>j_R!wU{wO(Hk`Mc8pn;$|NIp(t_^v_mMYeC4-|EduspFJua@*OxIEw5V< z`$F7~50V~CO3x0$I4$te`~b!@VL+C)=iKogAwqwQ#dLMs*R00huJkso$=PhIAuV$z zP*;_#HlD=X7)`K9InA{3BlM4oLPx3gr);T&XQOTu zl1fG@Z}Z}fcGU!n9jaMQ%*GqG*PL^yJ>PTucV|a5%NN?%;KdiJW>;J}GEIOY2Jl_p z-BXXTYn`F;qF>zn%3q+b+IT=6r?mT4WT+k5Tk9y(w$~f2jzOQIA2L=R)uw{61EHNW3l_aX}yEp}bwagCGMp&;SxX!53el0Y;IWM@+D zp+>GrTBYq&ibr3GO;NUd@Y$YOq7AYoO~jN>%v30A+kVtX6=~@^{?T7wIc0%>fN$N9 zXi35a{TMBpK7d0&OGTMZrI1qz@~Rf4mJyA{|I6QGvFeiaE&#A=yOV*Nb*8=`Ft`)(($-F z2xxv2dFJar2;UhW>4lEKHIk#8))9W8f%0iAX-dSzBDUHBK#V`W9>)i|vE??qFG51-hqyU;TFBze&6QX58t<43+2n;zmg|j8T!@8fk`K zPX8>K)aq!xxi-BjeY(x_pL9WIrf%f+_IwA3`!b8(Gc<|qPRbKz7`LA!yFDwA*ZGEn z72_ka5$x));2Wi86|N&nuywWeIt1A(Xk`j_{85PKN^D>BxL0EZz9l=qv|>vC7LEs6 z{aZAz*X`0~5Im-L=inErz$g)tWJJi>tVWUpcReCD*@#*@bqdx}8xPB+r4LN%H# zSp@p}2bYe7I020^3Z%D4+ZV#h5dH)y3_7koR?DA)bB!_^CiK_)Vk(vVHmX#W*=?=~ zB=LO!-oB!Iq6d26l=3N%o&d>7cJ^x<6D|W|1a!p@3bWs&J-QQA((YknOYIXdZAhH=%%y>*m*#FKGtzvu zO0iy2H=~j8DKFPjae2Sq7naG~`q$GtfOlVX`Qn}M?=q#of`-}wCU5&y(Ys@WFY4AC z(jwf4Fml*AX;}ZpPp`IN0bFFNQYki44aq(zvcBr+$HOKC>%U9P%m%ss7h$Gh!8Ff0 zb&e+L*(ZmGKD;d*x^@*FS2)#OrK2k1R*fH?$Dk2g7r5aw$8Tq_oVV^ocXsu1Uw8&BlWZ7jceNNih>^_j++CU%-=po45@WQ}|#4^5M}Vf;dIXY;;s zY5EY-6WDgrti1Wi4BOyoy$q0t`Y7J7+!KL5eLp?Wqqyf>fe4tjaFDD9F>}9Nin-vY zD{8CXZi4jRjXqrE^XTQtN?@q5OS6zlF|h5ntSa|z_upNMFqk?gK)tCc+-`DA>l84{ z8`G1jl=tsS`HaMb{Jg(A+Bd8|WQ&ZTIM;<=jo^}qzQ_3vmO}1WUNC1w)_6|ZPnX+7 zxABuSgdeRBu}FneE2vxZXnf;Pp>8mx75~Ga^IjSFd33NwaE*-R9U*4Kgty08(o}(=Lt_#c@L~4~d!;g&6FVgto2XnEs-f$w2e?@)vntATS!h6Pu4rbW)&qOl zzLBX(fG>Dwqgl??$tnCCQnh44HvS+IPRg!&3&qq7ty}I?-^^TibL7njrs=%qC+VfU z%A#_^4ya}PY%S`ZE$YmOONs>a^F7Va#Hrrpt<=EfRA|9R|J~)<0R#Xjvg-4;H(fX~ z8EGlY38COUb%wiM(e*L&gImsj7G2B&V}AlRHmpypguB#$LLZSGbcnJ`@d!zKmCS@u)Zn@h6b+mznLQx(AUp>!h;QO@Jx; z2?uTD(WO2EWvejrp$%D@>yvwn4O4q~XgP4=jP%Z{SQhM7o_Suxf`JHk+`z3XKxQ$4 zF4c?r?2uD|(~pRo?)**#;oYU`rOi3f-f-czi=P?VY587Tiah$NX;O+O2u41Vlwm}} ztM0JU@_Qg9kqV~t3~@d+Gi+N9A{#)TB2-C1HRYod-PBR}^E(7wnk%&ot$GYfTpL)Q zbE^4%>y}@)JerS|{gCnZP~RuI*=hncd4nb>LteS2MZ!A%okImK+iT>C5oZ42MUJ_q zK%L-e*lDH{m#DIA_bq)^2FpRJ*UlC;q0hpqL|+K>K$z~Yc<}FIMv0i-%7p$@A%OzQ z2@il^X@Y-U#0B~md%LCRJ^~!+7Kb8$O#9de314XZMNNi;{7s-+03C?@S>s_}onx_x zi4TdYs^+>fzpoiYM_<$$GJ>#6nu4cvf9pjqNV=NMsE zjO&7*(AKDp1Fr`$bG|1-w-j2ziNsc}G@elQ(<@ybCn5M$E6L%@zSt&M&1T7o%htDj zVLOqg9vxw-sY-FXl0U<7MC{0!Uk)5jXZ+%R!Sr5q;f2m;vxw1wXCuHX;$osgRzJJJmsL`y=%_0y__dRhE1>%<`RYz&_9dSbh zl7w@jrN0wnv5oe0SImDbscckHBiw`M7(rnT+*xKrt(}tQxB1mJX0u)SaRoO%Y6RDu ztFZ)ndrW|=0NfjSkFt};nw`?+D!Z$4Ouf0FP#9xP ziQZG8FpsAz0T60BVOR>3S2a6?!MlsVf!&6%+su8h^hGTcF-<4*PQ-&3}@y~fCNDz z72Kb6#wY5+FN_DbJR2%)F5u8nK{fb$Dxr7#EW7jFG0WJ#fv5-oG^HvX7obd#rXSk7 zJCr$ePbqAx;5r3v$cYs=d(bJ-FVdKUtc=qMk5O{ z8jVA}2EEPiLM|D-#aktCdEMb=YK0x7tqNuZ>llMe0 z*6X1w;ZoN6G+uzI_4tA3pxJl}f`K-HEk zfLb-?xyzY|R!S1HE42|B4XdB&HFfqKcRFlIFOeD z-J-bD0zU{-NVl?UQS`aFtKIV`U9nX|&??4OLi75RqnnbxB0RH6Ov%!qz9TJp^Q z^Fv2}j)awstrjKuQ)>W`IYdb&g7GFiPk0=o{Ua8Gk#0(5e^@qLxfaqDqxP82%T5Q` z+^Le%-U;rr*ScU?DQKK)VQPRDXjoIBO_2Q?3eRJk?vL#oQhXw`_PCgPHRdP02jVfw z4K4janVR3CJE|$+d>J4H*6XX?oq3-ng~$ALMaC+6Krbh~lmQSiW4aa#-?v)Nw9LF9 zFVU5(;)CMdjuZdq=2rfim6^!}IX1R(W;iK;3NgJp|8!bMqP(`sy$WI#fZq;Xb2=W$ z>*WF_S62GUi=ElOF$4JiToLDga4ev3GM>r`L}r+79CGQZem!%`MzMkkDC+v`;%zxNZF@=57-@C zhQzE!nyJ^G>oi#qKKDOALHO5XtnWHNNmi{d&$b4!Qi zbo@F^w{O(Q+Ir@I6t_RmGI`r7VLMj!-a|E~5Ua#@I{(Bhnj`-!v&adDE2EK|wpO^o zWpPhyc6V%##UeD}GvS<q_|Xy~Wf#tfj8tb;&6~J}E5FPE3HTT= ziF(MUa&desI(Th2NwK1m<>U_~Yt$L~By^gBPYVm+K_c&s>$-#+iJSCag?|7OQdZUS zg5?4BF&54Cmcr*>X&=rrH{poYp#FV19qs5{);8tOk>`W_KH3qluZoThI)TbRB#+&J zawpBg=BpGu$sb}VuynEW!;(tc%lcFjX<$8A(}Dr;Y@Wv%eaXL&7urH*zTP4>VZvo{ z#TL#WXv?`O9+91X5lt6U$V`lHFw#qe?$OMl(j?uOFJYP~y-NFxHFaiFm1wdeKCj=4zP^kt8&zWs?Hzo_CU>M)v z&l}c+jCcm*O)X$dy&u%p8AOuln>O;fBH%(kaC&vNjWrzgCY z&ocyn2DC;Qae?aFdgFZz_G#3i`5yba(DThD^vFuH(d}dwS%j*`%CL_#Wmo_}&g&zf zo2&YV;`Ik=_J@|!m;|Dn&INgQy4u(bM|Ao$3TZ(=sncvI2IwN`<_t-ygCg8q%8SNu zZV-h3eZBK@5$Sv(0WADNWw$N_dE0|j9F<(BF^+My_q^OYL$^tRzXf~%-D7~fO=Bj} z8lZfpHF zr>y$4o^40~sLWkRysyC9dufGCq;TW`9*i(|9PDZc0ao>U-{l*enFIm{15%66aTBy< zrRjiw@V~zxZO|MADA9HFi@UWoVMoG7_BLUdo~Wh*LeR+I+!uAQve@LY?kDY7W&wXh z*#oO9^31&?(z8&FF$GhLa4>;%>~G@?FfQ-;)RD%BQWWOiwfEqYd0kTt(-}GRA@@$n)A5t>fDBF0Juyhv%!uFp9ewFXcIUKIP?(jlI zaL&(_2Vh6N?SXJl>&XVm;-9>d+a6*yGl362yfNczM$;{E2AUAWU0)~fZI>6BUsGyX ztgHBZJ7E9oK!+t;8w}WX6b;AEGlzpdd3Bd<+2rn+B+6%s9msk2k6IM_K~qjZ1IYt3 zGi(v+NKuRJ`Ef9Z<;49MXx+x>_Kyxg%5tX(CEq=`dQT~{TDnSzjZT0&NZ$^u8DW!U zB|m&##gXAEuFHX4-%bQ?Xfjx0TULPrvXparqtt%tUvE@w!+Y>m+96n)I(%&RPp4Tv z(DuM{*Y{#v57at275si2lLp}PHV=9CA)!%~x|KnOSG#({h~G$6n{w&_#)ze#t4_Tn zFm_}=9VfH5J@MPa8;>8pI|-af)h22RKwXu4sLit9CBqqt>wDw-z#&BPNAH*S$M3)y?18-F zbnQ-0`@u&4v>H)N+CPk8C_{~D@9`Qqg}#zWnmH^j&!61Q`_mj6mA$!vIlNUfp}9Km zsXLcB!IBmAX}h8H;_Jt~d^1p$DdbXkW(?h(en=0Mgd-+*TtdMw*Yoy#a8=s!>FDlCBpJ7=HvOz!8 zur-D#zL}83f(ghE?+**~^^mFX$3)XU)UovF!ggw}1Vr!_c|SKMnR7YE%&&frJaW2ZxP5zO53dknI&3UMPQ_Z09o6uM|(>kJP(N`FNP}N_}%<5@s zU^<%V1Li1sQ%$$$%R}A9fAgBQ)C|kVw{7ganbJqyp z;H{jKV7#X-^ysa^(C=~mZ>iMkf5FsIH#r#a$QrOjJTg?r4BbRu#~d0(px6erl#Gj@{x zsP)gb1bE`gvHQWaq@h4fXcASE?85hOOHo7)u~cO3A>-mKKFF!9<}Po0o4ZZk83y4=KHMyxK&)_{aGH z!>~O_jutRx4jmqMy8b$tV*l18e|+2Sui*_iTEt~pb@>z6PTYm^_(0+DqdmgF_og0? zTc@~5fMnu%S4iEpdv)rFz>Uttqu+H3matW{2!9V32+AG2lbsJLUi@WKo;tyyhvr0H z>zuObGR4qDbYDviR)?ps@WKx2eDx9qra%73EQDdG!1(4DGk_k;l3gia52@-#Z?Y z(-^ZSv4x~c++S|SMU>Uppvl^Kw`(rY;`eM@QmWJv6Az$O5bVBc7$iSNih%^nDpW(N zW;ICeQC#HQvZ;(r_Q`gKf~4;5rnKAN^`zS9<72#Lj8(GiRvokr3^tZV$?MB%-Bi~(W)nyYSa>j^Y&=xMKv*^H2x|#{ zk994|;`;fI=zGmm4rWEdBeJHN=S}rLnt@*2dsLc*hj!3xtU&A5+?)wipll3o;;Xc+ z@3<=JNXm5&61s*|6zsRnlb(GQ8~ZkC8xXSE^ya}mS@e}w6X}3b_+0L*26esdLw8`A zjF}HWS2>?r0t@RcR;vKTXYh_KSJ@H=ivU`27DCQVs*z9GVvtyUN@faq)AQm`$FmyMExH3;W37lkDd9(L!mZ zp<2N*+57qYR-axU_Ay>{SdQYDN<^rPI31Q-uKCSh>vO4tzVF-;blaNOr+)r=s79Fm z?^mXqtT>fc%GG6Uja35%0z01x-AJ%ode6k4@)uzvbuNbuE(=J5MQ_esS~URE=m)QG z1O4tw0Ymr~g#lnMhiJAp7T_-$Sb2#-*r19T6Ff{Tx2|!R(?XQqr4YcT>CT2-fNx=6 zZ7%gw515yjd)(by3Uf+r;!#gW^qasMR6`2n?~@u!OiGNP$_3GY7;3&fmxZ#S?8wWD zOVMNmYC7=~xwmVSeaB}cUeG`FOzYqOR`5ab5;m|trXj+5r}*QLlje}G((;KBT)B((BCCT=&O0~G*w<2*-E)Hg_19K#gLb^ynCNpB0hJUczII0$?>O%d#f;pb+U8YA0CkL- z5{*w?T{wxVvYyR{jCXME_1HbNIp)`awT}xL(k0Aa%bISAn(k(11phh8=6EisSdjx_ zmH^sBTNJly24r}YZNa{7H_%8)uQhM{5|UhYNNfgNS8R#(3&gZP)DSn$iM-_8Uu?RY zwba;n0KKEVbsNml-XcEkB-_6Zn(`Q$ruuXX;S-uDT!5Lp(>sUe)rD-{+!`%eRbS2I zx^_i?w!I7?!JWK3*=0%vDdGuR6KDN;S>LGByv4PU;#yRjYW2~4%5KXmQkc81O}=IL z-u&J*u0iXr32+jP6z9=VX-d+o%fVV#{HwVmFE4!`3`~G9l;M9YqO8X&Q)Fh|SEJ2w zwW!DWH8G}r4j!_Xa-VG`n(J)Es#fT-D-Zk3^H+?8;yM7wjMx`3U4W)kPmpt202^|-dUz3W}uZIa7tL=h=4MVLwe=?N!R}DYj6HOE@Q;y*JG|5v4Zh8VyqTjslB?I zdEiEW0T6MGKj3#V{sklR zPPZvT1px+IS??Uo#bB6qs?G#$?6hbk%69B*E?vC*&LS+iH1<3t{#sm{4p5EZS`~oHd+AQ`Qyj)J-*it4|~>$T`xJR ztab3m#6#An0zq?A%Y&f5%Xe{VBK)BS=JWgwkNQc}#p!AYtLp5J<;%`90Gr8;d<3Tj zgJk+0m(N!Zs}MT7?R#>S$^o*%sK!d8%YUF(6!$Ck9SVIFRQL3Dm6N{qSXu`yXZ!Ef zq|1xpNtB}46MITA1=Nl69BDgNIi^Kol+6vB6n-_QU5XoiwfhB+F~o^e`BcSh%ltrK z?EF|2^n$qz8XKz7lc60oN7=o(G#Le$8ncYCJIzklo9FsW#%~{4_;U9g&_4;3F(5-x zC8?7zYfSJ~%fTo8_r4nNxEAXViSr9(i>TZuxE3@EAFyuz{@!EiqrGrOULq2lqjdOj zG;P^|^rb4~5otdvGXB0asO_H{(gw%c4|yA}ioP}ZyhH4hCJ><6iGe-G_O|~4HEJbw z8lWB_EG+N4Wsbv@@<7Z;v&-Qc>is%Vd{fYZs~5iczV6GXI6@Qk=r8?`0NtLmtd&TX%a zHYP}sU3d{~FNVhOWjDi}^U>0GUn6|?ps zZ#zIEe#4zNCf|P{(TIcafn#qqi!7K}TkQrkYz^i0dT7=0H~y=lus0otPL~iU*t}rs z$*Rp=bFAk!&QW~)*n#BPhFQF4&4n_3q&RLr<^i`n~KRqkCseBzTP);Jtq_Gi@e zTbFciKKL@`T1oMg{`WLO^;|Epz6tW$#ZL7-Ju)W!I|R^AB^9XZ1*9&^q7@odKu2kP z^oYpEH)#Nfls!>NtHJZQ2JL>BSZCi&lfqvN)e!pq<2CTxq@(l86Wt&Ii`Yhx-LyxO z_c{utKnH^SUq?Gw9_$9H0V|N*|1NqQGnR|vC~(H0?WIcGwCgMTjx7z$;1{#=X%Wo^q`}=~P>jn7$EBO)4kSL`HWSNNA3;yH?}caDJ4%l(}^hQ~>Pb*z9?171hLJNH;GsA2Ac*(R&OfldYGFtV3R|Xs;|A_qKE?TY0`* z0P?CI6P0b3V{~y=)rFV}0U5iF@Xp``XZ%{LdyZSYlJSarEy@Y`V2NhdJPf|nZx|GY z%Uu#5{!c4K)3Q^vz$ZsiusoS1#L&f{=3=iuDt z`6=JsCPW9qfM2_G=~BanqrudBM}s19ff?-kO<3WnTZM()TT0mD&EaazB92O`9L7m1 zUe~g|=wr>!J>dft)|R|y)e2mdID%=QapS;9$K3R*b4~Zu)osG*f0D<_Cx^w~nh5J{ zeBU^U4?zZD2uJE*NLu|*F<3gYf^-9=g&VkV~;0%sDV?72$;!H0$ zL`ff!D8EP71vRI`-=cr_^Yb=^5vYM%Ja&=yn@8wwDh+V6Zw5*!P#K zth-}`B1Vqz`uO#T85)6nHj69?4!R1#attm`bT-O`Ss6AmFd$pL+=>TQZp1wwKG99q zkc?tL?v^hSJ{;JiHGlXbob1LWQcXBeu(IVYx$l*>A@9Y2kg_Ccb0|Vm zqXIHml3pK9n-SzAdk7s4E+KW%iqcz3#4fpGR;ltz0%~Rz*8a&pTIX{>yF|&oVBf7J z0<4EV+H-(ixkZzRl?0SAY>Y1-aMOmScgolx>^$xj_9v^4DvKSsVMP0_Wx9B%Mz)o| zq!sVL7B$CY_leIQVi>K~e!>niam{@n2ko1u2CTj4%^5K4-+pB{g32}qUv#{Z26N1_CPU_M}9VMuJnga-&)3g9O3EUHgf7i=CZG1Zm z44%c&RsVJ7Kb545d`Z^CHE-gKf!+PoI? z99EciW{r6s`fMz?hQep5zwats*#BXT)A_XagKqrblx73L{UQHIYS{nI?G)Nq3WZo% z^Y(iV4f|uocw#_OH;hrK#~l}Z%?`}LW7b&stjcT|YEduww`lt`LTAaLY?j8vZwVcd z&x7sFkdDsN13lDH^A6`f{||Hso6Rhvp?$X`M!f@Z7?VqW#oJu&;e0Uojg1ip(D!Hw zy-gl=E^rx&SzgpA*_ZJbn`OZa)<7m9b#;;RO6if&O#jiUO0r+pdzjzM`DMvg2WV_y zx$(;_yHoAeR!^gB95Z~-{U*wb#XLT5la4v?Der8mlr{d1qR>sFj%*ZF6L8s}?Vn~! z=K_>RrWO@dq?rpqodLtu>(uY<&_BEWW1Q>m^A(8bsDo@0|EviPo7u58I}$dEE8{x^ zfuruHWQkF8bMfNV+iQa5P#)?uIIH4G(*KFWJcGwIq;z1RH^Ah;t+yMBeZzq6|Yw`z+m|6N!2EjvG zr}u{*m1Lq<|7QE-p50nX@akb1FT1oM`~F0)tweIi`o!z%tsPuRzq`a11ky<<68`GG z5TPpIm5?Iy_WiXmcI2rA1r3_NX1e*uRClQlCMpoUo%QmF&)HOWi6x7f-**x|G$Wx& zYG%coO;XyYC5CsV6NI00x$fd`a9oclr4ZjUy}N1-PFtn_{x(+??nvj@-7kQa4Jme5 z+UtMA5HoNB1crkL4^D9}88^)&1j7d}U8_NlgwqQ?)2MsOSA6Bpy{Ybj8e;Q2ZYf__ zV3R;7dBbQU-#x$G-Cd75Z;;Vg?AT-NRLW*HBcs=>vy8(b$KsQ(orLTp$gu#z5qL%2 z`W>a!A?_whC)}BXFV?S@{->**FaPp~AiwKQH{9Wn-Xal+D7Vxud&l=oL*lMCsCl-Ihs+>~6+g6JPM^3x66;q?&O})c zbXXR+jal}=S4sw~@M{?VtIC@nTc>V7$-j>l_-bFc{pmE9q@n`0nvgoUGiXz>3&7)y z#@CmPU%#8lkZQ%3Zw7*QdXUj6RlW_DuyN^Pzd?eFa+uKtemL=s zpTl(H-MJ_H_pYJwUonyIZ?Hue$&Vi$uvk~EFg~YpEy=!-WecM!=QesYnIG=wAmf9{ zp7ok*R3VVhmb#9a!K^?_YlXwXXG)*C6=u^e677cBSG+ew6pS`8AJXSDG$cBx^=ic~dMTA;-58mO|IFEW z^5qW$=jqH0J}xMwWnkL06LP8Wk2i19mH;Aav06n{3J3^z!o|Hqc_L5IB=?PAE)C+$ zx`LMmn*62wtSn&Dx;D6KLiBq^f!j))B!T;CIhEV}i(C)GB&-x}L)KbHFxyxnN)>K% zDRJ@hT-v2IZ(h%DQ^aARgvMG%fm<+amN-=jPQAok-;tsemXhuNBQebj>yKX&Nn>YI zzK>8|N)$O9!58pb;MQ{aZU@w`X?GlrfCWw2P!%_dae${`n%?(J1N|94T`-viEA>B~ zv^QiH5Krh&3GqjXOlHc3+l^x+Vjc+MGliGjtLO#!OKzAcfxs;q@+F6%)n+I=|NLO= zmJt8u=4OL-wp)&H)x9cu+p4)`{u58-p+u2_*{u=t7{6lYfsS&DpH8UCUuOYSE=?7; z=xCtHGg8wc@)q3H)zu!O_|B&;1F6ei>$>jY7;=;s^NzCq${2!>>Nh6vxhCMbrTmDi z1Fm|mo=GJ2xT!U0v>_WIq_%wFxkwTGJRdFq_L*|TJ+d#`J<6*Sj{Q`VLU}DSRg^}( zbu&#Gm1Geor0Y6PZoTbG?3sFH6V12W^Q?)_Qu}@ugZ(p&s5WjR--MlI?i!0+c;m;6 zdMUUEOu~B*BX3EZEhoAnEUUNH>e!;11Q0=k{)|ArCN%jjLA(MsAcY^QA9kJEV-2Gy z_?y|3zSdWL*AvtJ2tqUcyOomG!<2YG+3S-xl4(L_GLxYRIpRyL6tQWLFlfRxuR~%- zI;Av^bZ2rZfr~DPXeh<{^X6Om0oH5;CaBwd>TQ{Y#V)*K-MHShESKLGg1b{2%22TQ zvaj#mTj%`kG{1&csAA5dGlI%C?M|gsKeWvS_YV2G>};>V8b>RodZv5Qb_m2|SWWP%#Y;a!(vQS^tE#+!6?gcwv&Uo_*&}!76MBFG zHXBTMYZdlI;ioXl?t_-Sm#aVN3UR>ZNgGU1atyCCpLq|V+p)0E%HMUzdl}A+&@^!1uZ$HK{5ajPO+;vTOP>=G}bf!f%A$GqOJX(MyjX;qO=pC;| zC7?GN@Y4dhyd}E1TFN`nIfyFUx3wKriXV~+x@@dW$RSR0Vvqx5s~3E4&bn1iV_(VG z>jW)BA*ZOT<7k1+O4GX%-5FpLRjXWG+y0;SzB{hzEbDtj9mR%#f`EXdGz%aCQUx4^ zh%}Lo6cyH>ba!YWOl!R$>rgD;;e|7RoIU{GkGS$}OQ$&|K z$6p@b#a~V6A&#_&^Yp3}N9Yx!yFz&tCV(M5KcBE2a4Jqf!q~68k-0J1mOR&btnh0C z!+#tN1RP*a@Ey&ZSZ+~LzLi}vK^x)HBZZo8SC}9u^l2L_o5#GrvMmsHLiH%f#@u9K zmEA}{HB>ilYCr5KmLb~NUH{ai{Y@1XX-`?|cINtPWmzB`6MWa*V4kXfjeV+T8&*4~ZRGyVt|INN+;rlL-T(a(D>jYxG$r`v%3d=}E3-7h& z7zG!L%^F9fcr|IHC37LTH@QQ8sfyq1FzfNxFi$+4Z_|Y?@FT7yXB!^LRz|BPZB0bi!M4_LJrXt*+-s|= z`kB10UzRs&qPFyCznM;w-FP$Td0L?2FwwE@oBPbSdVTpk$<*y1@AKDl(OL}wYV#D>rVaFW}Z%6(5J0z_*eiH-2RF`iR;UO9{#tNjKsq10+2uEs}|%{gv_XgB-nX@j(K`A?AR z|E_-Tt|9J)7P|#;;4$8%3^-d6Vpc=FsuV1?p2#%J^^`P}*(#U#kOxCys-8Da4JLQY zSzB+dwr_D`*21x&`+4|+BXkt2O&5w42%&OrQ*}?3mgpNz%Kox{S^W`US*=Qt7YJK~ zI0r2g1R;YuZroDJ%)C-sm$waWs0G%C_h z=#w0&vXqi>8fTDuB=*>vfSm$6D&NqNS+#{lSqgYwN%Kv=x)k|nuqfSIYVA(f!vS0L zmQQ)%U45S0^rsrPOPJsn@W{mW+XapZ_d6vgfJ=3R``i?%gA&162>%#v>^&0F)75?f zS13F4^5H~_CD})M{1gufhf+@B%t-hl;QU^xM7Wf-siJ$E??kjR?M}RJ2BRB&uxUpF zl}_MPBC|f&F(|autbC-}wa!*))SQP?GyMu}u5F_@*8W#uupzx8A9K&7I~=_^S{!(ktMJ1k_YdyDL(xV3Zozz|U+6W%f>owry`t>;uC z#cpI`{P1t{ydQhhK4v1*@Y9e%7JlyS%+m z=g0CFX~#n4*84Ihe?J-Ws)O*BdY7QRSU=ri@5Vt{d~4S(D;~s0PrBS%VHYl77Xf8^ zVdar-X7$!~{%2T3&!R#5{t=?cX=9I-?7XdQyXs2B$ZD0dsI9kR^puDsE^O&4CSx+w z2+KX4L>sP=N0NxUwGX}YE@2tx8xSI04oMO)ww@3yONP2Zoepn#PWW22;Cy=&2 zB+lpSq)|B|^C`pwPv8!2udbX&ZfV~M)QR@P@wj%xZ@Dj-v98oKM~TO7@p@r-ByC!= zI7q9jb-+F6HLV8%y?P81D9fUI#$s8sd7$Rb=Oh&O=;aUa|J%@MDo+E>4(JTy%w~~m{ST8*(Pqj^A~Kj zj}i+{WGHO6R=-G{m&Ew^-rQ;JJw-69vcG>rN#ngi_2g+_5$)_qY}2q#WtXn2Ng(Z^XPdUAbK z*L()H4oUOxd+SI3%{~|gEqmH=n__|N2E{+mQQfGpm#PfQN$WlJ7CK$TF?jmj}^+XEJurszIe4Ia0!=+`$Es$$am{=G_;d4Z6{ z@&sqYoV3pTWvO$(z(p_E0Y0Hv$ca$1B;Eu5=bZ-+AxSce!HxWjAv%7`UBHDIVZ*q7 z8hAMEXgQ@Ho>0Ak#Bj9Bjz5YyC+K@diTp7=_V6Pk-$JFUZESbdmygyWhVd@48D zY<9XNv;G7E*6X1O1<0ldB%xJ=Q5S6+(}|sx{O7ONxhm`|N6^$29i|;RIKXK>#bgb? zr%0QHHA?Cz$@y=h`RjQd`yy>DpnewZa#pH><1_0UANTjMtY56}i!C>rWV%A29IbMx;>{3JjyYU)XaviQQ zD;Jc;FK~*~(#mM)-s22f6Cun4QmxR|(P-~SBh_>Pz9?^xSsrk8U4J>me>5>B@;Gp0 zW{f1AZ7R-Nf7Iotf8I60ue|xn=I0(km6uvfgm&j&diOE-t-&*6w0GwpI^K=>rb@M` zT_AU~L&yU97Q47U_U95|zAEzTk~&qFGFgh}!ZWK-AJf&<)ozyS%-fiFIqx9}8;52X z#d?G;1I=asF!y@rw{1Bk+mQj`mIh2C^f9}rOOk!Fy>;kxkQ;ThAnhWCdeOB&CgFtA zGKxQx1u;fz+h-2AaDyUa^kFq8E%29&z+W#zm_}I~PZX!l?f9w-8S&Ra%dLYk#sPPc z_cXIU%@{2<)S+8)Hx^}=nkfl3Qd zzTW%SIh}rfIno~iO$!c$@GRisSYhQ2%a-`+DK*%GqjuC0?U-d^TsmM+M zP;>)TN|a^GADPHN{Gh@IRJX1>OpIZf$G`)pBb)yHAJY5|byD8L8oY<#ZGParWiE)FzwP~h_dOXztCdx);?4Ak(hLfMaum2e#U z%n@)Gp*;WmP0Pg62~KkCr0q2?BsSnXwnsE@P zW@zVd@{o4UMF!1uq3TPg#iv@yN+(|MyZt;|a969=JUCR2{>Av-`w#saV-#aIyp};` z*~(PotCkl=sDeiV$;*2qooUjig@|uWB-X%co{K=MtQ+48MPl~g`x*+;@_-7$$mtFc z2sl^8|3Z+L*Q+xbxQA7uqE#|E}K|0grSqMv3uD`NJy?2Tr#r9t%C3sUV9Aztf;T;&lR zO*PgEyw>1GPL49NI3IH}av{?F^J~GL`yXKjPdc}BOnR~KR|0$?M%vH^8csrscRg_9 z2>8cU@iDp?*v_rxQ zMRZeXcpxl0+#RAX96B_!z6(}!D+6LJ<*2qI_jO`iy9~Aiq#vMuVk;CpnABkFub^S0iuX>n(PYdj{}vmKhLAXWc8p|SV}E*O zMTX}W`r(A81c%N0H}`bD`Q;9VAbX&*V)k2!k8=s4U@r_=iDfMn$QR3Ek z>oyI`!QAy#&I96dn_gfKI$(00#%Z-8E>mBejZ$^d(UIPk?xsh%(?TJo)WfTZJgC74 ziOr z5AWiw6nMdp_*wd{ub>QWiYHg}=#95lr$TPr{6fJOlh_sF;Dzm*2rJ?%oe(a-Qk{aG zueU-eaSxTaWE1?Q2we8JUee#(`i7~RPp!!;*GP0In{^7PLMhL7)+64?>dkQR#&zc* zbcq*ibz#t8&#&i{vFDD_G;Roe19AUnIP>2TO?fNc7*y=!pAx62 zf5%XO_pt7qSz;JIcW6{+-fp5JYrwbBU&rJc$SGt}EW;NU26Qv(PS7-{oIzi4@0oMC zm@t-5&&_-4U5B7j^$VA7exZ>&bN%Uo*tddL6;G|Kh~5ySM6WOI`G2y-#uX5-yW9ah z4s!%2KBq_-MO`$PnM%1L&mHj=cUbLrjUK>Uh714*^7Vz!QN=%!)>k8K6vV;WNPk`% z?VdXOVQ6h1#eoiQ7K!_xqfjZCA7Q`(y!k-{EO2`#rqKEWqYQw*von8>Z_rXnSF7gl z{Y3JTjK=B6i%zu;rR}M-S<}iR2CSiPw+e4 zUg}5B#n6Ce7d?zlP#YpP88fhZH5YKKdM2WU^|BHyCDJNQH<#}`15fQtMH&TJCTZr~ z_peV_b|AJyoCGiJ#OPUw`g@^AnzV`B>y1zhx=pT z_!?eK3wtUPEU&E&L+3}9zdM6>sl395YB((% z3YLe1uGmJ|r=r1-TL%1JG1{ToV+>yD4T9HFNwsQ1{N{-Ik_;8rZA4^ZjV!!P zR@WA|J+f>QXs;c}>)ELKHqf;8hD-O&$Gof}T@)S`fPVdJJi}sAZT=VZnU8k0pl-Wi zSFcfH(Pj+$#7k9;+bvVD3}#jDhi#sUrlofFcPfrg3JOowpIQu78R)ev*aJu;hxMSB zas#2j@ygNadqC!qhVN-*g?ec4iUdO&e1&c138_{aT$*>7)xEN5-owbn@)Y78v1k>U zER5Ri-+4yhl?Wi~9nVVzfPAn11RT+4_Me#55!njld`M-AXLJA|%$O&!!t#IGLcx{N#d5$aV`SI>*FA7$r-XYSOpkw?sK$$c zAfR_iBqCWz-0~1&N<$SJP!!nZ5WAw`D)}k=R1p3aF8I0K;x0oMN{B_Ly zY!TW|DmOd#f~elAQ|I|Mwqx%a_mnCx=IObN{X@@mGxNV z{w9`cT3hL2wa3H8>Vq*N0iZQ}{ffoLL`{p!5XIPUVQ=zLMZyztHdOho7pq{0)dk1u z*VUyHf4ubIy#O1yPcKKR9E9 zCEqSFQ$;x0a=1(=r+h-;VdKb>>V&RLD|puZ*xB?QmHkTTsa-cg+U_#2R}psS_Ww7J zpZvE+_tFjyQ44Ny__zzp$-w@5TL{-Kt<$(yR05A7;epEO9S6)RWwm9;yN%&Z5$do3 zkK9fA8`pMoufo@X#pahLbcfzb1L|CWFqpz!LFkAlfC)?{a8@zaEe868wlcmF#La1a z<{8L7mDRPytkXs+H!GRC(%ORUB~yDJV+#nOrOUq2y;0FsDigW`wpT!HcZ@reg;TP- zo`VX=s`oJPfw>JH zyLPyAnxKFy&%|J(fJ}c7;4^6gYGPOLfOBYQUk>z@Lx+GB-~EPB4p+I^&DmS9Iz5!^ zsRQzG*Vd#96)i9{)%p;0(S-nvhBR6v)H~vRgR8>0REG_@{==y#Yo< ztX>Mx@qx4$obqwN#}SO%XAX>9`@yB#)Fg>^HT4H7Bq-&BO_-Hne5kW|Ol&Bj-aaTl zbxjzYdU-Y|X)Xf!wI@?A3Ntt(;8O&!F<((U)o}-;)R=sq00kfgd!GkQzshxhno*}T zK?f>^_5&I!@bGiER9-cBO8JKX`EBCGePJTtZ&gn20GGGKegU-7%?6vC6s=g0gDl^658P^36bB2YhU}ODEmS29*a!s| z|D#?L=^Y{g0va4;);-PFg@W!dpM849oa5;kliqv#E~UY1x8rf66@B^T2S%$$VdoGTe@3Ez6#QzA2E&vH11jX{i z+rCq-6DMsAy=1vH&JS&~@9{8-I;ATxG-5~YXcy_;>S*w4FP9FZb?r}%#!UQDy7W58 zidyXK`pGSMgeb=E)oGu%=)X5^S;2i^*#YD0>w8M!dRvZA{>Xh?^Y!fX(AqhblmAWH zkLy1>?f0i#BHjiALfp2*5}h;hchuK*zHh?}>w8O(^O|!GU3lXyVX}4K(C?4QN;4Zw zn0PUA3db)dn?W>Em>Cm{s!L?wV|i1{`e|H9)W|Q*OZLT!-Uxs9l~iNI%6?wo2GDL? ze3YI;szYv48@UO$SLrMW0d3`#GS`6;@jw!NK_R17ZlVc2;ep&}B#vTyVUs3h(k{QU zU$@XuET=qkIb2PLfCf{q$*5>mj$|6O)EWQcxu1T_wfY0h!IjFEl%96g_E6ru6=Gv1 z^A+B?-gh=Fn|>|w8OYky%-QY!S`qvAj>!b0|1*DV+T`G?ERC}y&P>6s##+7tlg>(i zC`_j{O?lb4-=J&4*iq}T7?(3jtLYL}HaiJnTEu=ds$qTMMrH-SwDfj%eUq)uo4==} zdC0eY71&Vuymk&1pAUtJwj8(^5*`Yr8_r)?y(t*>R=n6K+!O-EQVl#kn?0xHX2#z1 zBzmfa7U_KyH|gwvDbx7@z+)YFX*$Vct|@0fpQT%Edj=M3q%Kd%y}GQsUbgx4^l9;x z_DrEOv{@dDzTPkB$U5{Hlano@cWID0f9&Nci*-WtdJ(u~6HIhtzv2E6J z@Z9*ntB~ez(r7LdoAPn+$SQ$qtR9Cx8)`j+9{t7F*E8}I5fo{0@O{fZT3aAbSUN?+ zr6^|YSeGqXdJ1Jn;+b&~jo{`at`H@Y&dzZd-wiE4E>o9F*1~B;QM`$RYg}>ekwtRu z!ssxBtW~`Uv6_XhS0t;Uow0CtbsgialR)~gk~!&>Rdr!7)-MuF!oze~*JEx|hjaH| zlvbI@Q*=2HX6;{Xt(S$g-<$ZIMMHnHR)#Z;n7|dh-GuJ?@#U<60xL=|R}ZVrmLPdF zDXE!ocydF$8E-lG0rz!>z9xl(7T8d8)AI2cb{)9_3X|`G)4Efs<3hWYm7wd}8DZ)+ z*Hu?xBhS5qw#H4_ptu-dxwni5E+3Twa9PooEho*oa{h4cGljmKz`n}mlBXW&dLLog zR}`Cn3~#e{o<@UItWjdit?lj*l@jQUC3qwWjmgEt`E>)O`-M-5xEPLY$0a{Ix24pi z_6CVdzTt203DV(vQ_O2<3@`h;GtKPNeSavenu|>DVLdR<_bZ)F@4s;N`S}SBRlFs) zz#mn}1va5uywd)YM)YB|1^3%c0EvaIw|{PrYZg=WR)-ahgyrw(jWRMnFO@}MBL%jb zvVzyN_|CL@YLwFlPydJ#p3o>zhnetK`+W4W8n4;an6^c;BBmp$edTvOj+5US0EFsh zKEHcWS<`0YU{S^am2Cjz2CxBrB29^Vdxck{%4A78Hm!cCWplGl?Ip5)O5$IaJpH$1 zWW9^Z2XXb&HT=>1=&c#Ilew8g6_ya`rm+#&CZB=p~u)?_SK^VMw<= zm$ItKlp35Nf=j1Uw|Bk8()FSlyrVu3F;px&UDkfLKhaZ&KLk*UUp|c1&x#I}e*zL^ zIRqs^qMbh9V_uG#I$BxnrCx@Kg;2ct3S?ZLC_*3YNsxTFPX*2Fn$AHLN_r(OtLgO zVs{q9*E`r;nTt0JERscy_%?ty=q4{oO^rvSe#8PsGLHh-KcQd?%gE{>-mMTYg zTuf#>ngYElL5wHO3_X7IStvles$c1TNpj_QjtN4~$?qm&be371KNc<}HU6e|1A_f5 z3T*lgSP_QFt{cl%nT_b4Tmv)zR%TbgyC|wHwH=9@Q+~KJ&@w+Us3F2nf2eFGEz_UP zg@W$mm{U~%41-XJ*G*>eaOxf(9p$aSmiyivy~!d2L*_VC}xsn>`oNb!hZy z92PTijjDM$yayhR`rYKhlr{r4+Qkt$y;Z}Qg{$(-^4ALPeu*3E(AB=8$h}il*M5h* z2U2YR1E^mP!zM#*H~8ai6JMbu(a#?_hhRdZ!AJ3JGC9Gb@iHN2?&68*r#}VFcG>PL zmNQLu_;~hVl>eHb#P`ef z%XH?L`4Y5Hl!B`KiA787W2R)sWYOhlQ-$ooC=m^t=J2>D{yE>k2#LbC*4Q8+{;JKx zoOO>m&5!c%`yI2OymsR*#uC6hC5y;M%FhE340#mUnZBQDsz3(5FLZjcd9NyRM=req znp_Dq`OY21IpgXlZ^=ncZvGk zEq&E{Dod7Sbo_%zK`q|=J0^nZw)A)X^JBjenv6yXznlnFJf%c? zoU0#?7zp|lxQpNK<%qdRH*ju#);y)f77$pitivW$`yF#fM!3F2V-V9 zhjhRh6&$yL=WB?kmuQEUUspt#ZiSx}v4pFW%?bY44)d|S;DsnDWp2}rz$`czJfWEvP*VFh-cxQ_C(8dGdpcza9IYx0 zhwJyE>d^V0g8j7~y}yi27Jl8Hqt5U(1=JoY!emd!4}v3bL>1Zq$h8gWoa zHRYi2aDQt)(um7eDY+pk?@hSu)TNi2Oza4xSeNk{qu2{%r~d3R2KwhADg$9Wrxdnj zXV34BL^NDgaxm)bxVG-p_~ufyDC!JrdTe{@Q<=I!;3f9jCQt3mPsydR829^)9bp9y z+9@H2v@D4@&p4GFNLp?@o=|f*Mh)V%>p)n7iAP3`tK3}Pqq!QifCDMYx*!35kK?m% zi@Ebt&<_t-u=k~S25R3lrp#`>2iKNQ}+bwu76#n6x012 zD@Z1U{`XSf6O9~613ta$2WHS9;5~e&5T$+{q+^^kL&8zT&WJOH*!zgp_4y-OZCea z^?yGdAe&!@zOMNY^pSff%nV7RG11-h-1K_(jR`=x%C)csv5&sz5!37HQ{HFpmJtV= zJlU5a9^jorF*DSaJ5rKD42xdn=KZ}_6yt_h9Nhs|$|*$(&g-@0DQtc>ER0gHuwfW z#fROQz60}6KLx^+WhW0NbIF+LMrI#@=W6YEb5Of(rI{5oiM+ z?SbbZe)cwpd>fcv zj+QjQeumnc?9)=@KJx3vFs4k|>z=$6LvQkav&WGtK+~9opvJ_YUixO{T<-R&>q*ItZ(#LW*5+c%>yi=~iszbvfBbs=`}Ys9X*;7@=$k#5U)W>+WBB5K z0*?MbLLZrjlB8uT>w&6I&jjwf_a`3s$;R^RdP;Od+t(zmJD{f}l&#z*c3uJ*5ME9y zf9YB0cdwzt{Zf#LG>otvzF%9E2Yxt((MfCU&A##4ws9R^Ng_HhUDx1Nue>sl>;mLk z^G&Y*HYW7%d|Ryq%RhlHQ?31*O{wtt4jAaal-)Ce>U=UBXGha;`|>SWK96@9Ra(J~ z2|hKnbV`hdQc{j|9^uo_?N141u4Ats zf<%05-dbL>OIP;L>oi+mYZBUg0k8k?MKj&63-e=y(bypj)0O=hOO6lp{^Ng?S_TNi zA9>=ZJ(cKi>k>5Yo2!bQm>)AU-ks5j>kXl7f_xseD{YI^ zTN)YZ+gFAT8JS!AdkAP9UUGbvnR5;!AD+5rL%QC;DAtl!U2o@R+(brZYi?*tI+MSa zYmdQ{5v)^x8z!}M?$k==3Hyu(mU?C$QRJR5De&0Z$(-`$&ABUar^fpJ)x(BBV3t(X z^3T+)W&$55oqOvk?^{+-BJ7)2b#zPBo0fS)<4 z*nCs9;`t;=gPGy*)yr)9NI`&fJ@3TaZh8JUT5Q7(uuuKd8zIi!Z-2z7 z$y+7kWd1+@vf2p(S&`Zrpx5zQmtzphw(wNAfRK~WVl21nE%8SRH#tHvvyOBf8uYUFP5tT?dj8u3T2Fg`(O6R zE*Wg!x{2d=q{V)ZS0N{?59H(9Oa&TkxNpzWE8DJ&vhYVT?yuf11Mo9{&G5{QrCS|M&3!$te8cdigH~?+?Zo z-29L`i=YI@{FTwk1xT@=1Ijl_r^;U`o&PM?>AOik|JN?g?&!5YM!H!KEP", 0], + ["artifact:*.cef.destinationDnsDomain", "==", "hunt_domain_1:action_result.parameter.domain"], + ], + logical_operator='and', + name="filter_1:condition_1") + + # call connected blocks if filtered artifacts or results + if matched_artifacts_1 or matched_results_1: + get_system_info_1(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1) + + return + +def get_system_info_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + + assets = get_specific_assets("get system info", ["Carbon Black"]) + + if (not assets): + phantom.debug("Carbon Black::get system info not found returning.") + + # collect data for 'get_system_info_1' call + filtered_container_data = phantom.collect2(container=container, datapath=['filtered-artifact:*.cef.sourceAddress', 'filtered-artifact:*.id'], filter_artifacts=filtered_artifacts) + + parameters = [] + + # build parameters list for 'get_system_info_1' call + for filtered_container_item in filtered_container_data: + if filtered_container_item[0]: + parameters.append({ + 'ip_hostname': filtered_container_item[0], + }) + + if parameters: + phantom.act("get system info", parameters=parameters, assets=assets, name="get_system_info_1") + else: + phantom.error("'get_system_info_1' will not be executed due to lack of parameters") + + return + +def filter_4(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + phantom.debug('filter_4() called') + + # collect filtered artifact ids for 'if' condition 1 + matched_artifacts_1, matched_results_1 = phantom.condition( + container=container, + action_results=results, + conditions=[ + ["hunt_file_1:action_result.data.*.binary.total_results", ">", 0], + ["artifact:*.cef.fileHash", "==", "hunt_file_1:action_result.parameter.hash"], + ], + logical_operator='and', + name="filter_4:condition_1") + + # call connected blocks if filtered artifacts or results + if matched_artifacts_1 or matched_results_1: + file_reputation_1(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1) + + return + +def filter_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + phantom.debug('filter_2() called') + + # collect filtered artifact ids for 'if' condition 1 + matched_artifacts_1, matched_results_1 = phantom.condition( + container=container, + action_results=results, + conditions=[ + ["action_result.summary.positives", "==", 0], + ["artifact:*.cef.fileHash", "==", "file_reputation_1:action_result.parameter.hash"], + ], + logical_operator='and', + name="filter_2:condition_1") + + # call connected blocks if filtered artifacts or results + if matched_artifacts_1 or matched_results_1: + get_file_2(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1) + + return + +def hunt_domain_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + + assets = get_specific_assets("hunt domain", ["Falcon Host API"]) + + if (not assets): + phantom.debug("hunt domain/Falcon Host API not found returning.") + + # collect data for 'hunt_domain_1' call + container_data = phantom.collect2(container=container, datapath=['artifact:*.cef.destinationDnsDomain', 'artifact:*.id']) + + parameters = [] + + # build parameters list for 'hunt_domain_1' call + for container_item in container_data: + if container_item[0]: + parameters.append({ + 'domain': container_item[0], + 'count_only': True, + # context (artifact id) is added to associate results with the artifact + 'context': {'artifact_id': container_item[1]}, + }) + + if parameters: + phantom.act("hunt domain", parameters=parameters, assets=assets, callback=filter_1, name="hunt_domain_1") + else: + phantom.error("'hunt_domain_1' will not be executed due to lack of parameters") + + return + +def get_file_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + + assets = get_specific_assets("get file", ["Carbon Black"]) + + if (not assets): + phantom.debug("Carbon Black::get file not found returning.") + + # collect data for 'get_file_2' call + filtered_container_data = phantom.collect2(container=container, datapath=['filtered-artifact:*.cef.fileHash', 'filtered-artifact:*.id'], filter_artifacts=filtered_artifacts) + + parameters = [] + + # build parameters list for 'get_file_2' call + for filtered_container_item in filtered_container_data: + if filtered_container_item[0]: + parameters.append({ + 'hash': filtered_container_item[0], + }) + + if parameters: + phantom.act("get file", parameters=parameters, assets=assets, callback=filter_3, name="get_file_2") + else: + phantom.error("'get_file_2' will not be executed due to lack of parameters") + + return + +def detonate_file_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + + assets = get_specific_assets("detonate file", ["Threat Grid"]) + + if (not assets): + phantom.debug("Threat Grid::detonate file not found returning.") + + # collect data for 'detonate_file_1' call + filtered_results_data_1 = phantom.collect2(container=container, datapath=["get_file_2:filtered-action_result.data.*.vault_id", "get_file_2:filtered-action_result.parameter.context.artifact_id"], action_results=filtered_results) + + parameters = [] + + # build parameters list for 'detonate_file_1' call + for filtered_results_item_1 in filtered_results_data_1: + if filtered_results_item_1[0]: + parameters.append({ + 'vault_id': filtered_results_item_1[0], + 'file_name': "", + 'vm': "", + 'force_analysis': "", + 'private': "", + # context (artifact id) is added to associate results with the artifact + 'context': {'artifact_id': filtered_results_item_1[1]}, + }) + + if parameters: + phantom.act("detonate file", parameters=parameters, assets=assets, name="detonate_file_1") + else: + phantom.error("'detonate_file_1' will not be executed due to lack of parameters") + + return + +def filter_3(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + phantom.debug('filter_3() called') + + # collect filtered artifact ids for 'if' condition 1 + matched_artifacts_1, matched_results_1 = phantom.condition( + container=container, + action_results=results, + conditions=[ + ["get_file_2:action_result.data.*.vault_id", "!=", ""], + ], + name="filter_3:condition_1") + + # call connected blocks if filtered artifacts or results + if matched_artifacts_1 or matched_results_1: + detonate_file_1(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1) + + return + +def file_reputation_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + + assets = get_specific_assets("file reputation", ["TitaniumCloud"]) + + if (not assets): + phantom.debug("ReversingLabs/TitaniumCloud::file reputation not found returning.") + + # collect data for 'file_reputation_1' call + container_data = phantom.collect2(container=container, datapath=['filtered-artifact:*.cef.fileHash', 'filtered-artifact:*.id'], filter_artifacts=filtered_artifacts) + + phantom.debug(container_data) + + parameters = [] + + # build parameters list for 'file_reputation_1' call + for container_item in container_data: + if container_item[0]: + parameters.append({ + 'hash': container_item[0], + # context (artifact id) is added to associate results with the artifact + 'context': {'artifact_id': container_item[1]}, + }) + + if parameters: + phantom.act("file reputation", parameters=parameters, assets=assets, name="file_reputation_1", callback=filter_2) + else: + phantom.error("'file_reputation_1' will not be executed due to lack of parameters") + + return + +def run_query_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + + assets = get_specific_assets("run query", ["Splunk Enterprise", "Carbon Black"]) + + if (not assets): + phantom.debug("Did not find any asset configured, supporting run query") + return + + container_data_src = phantom.collect2(container=container, datapath=['artifact:*.cef.sourceAddress', 'artifact:*.id']) + container_data_dst = phantom.collect2(container=container, datapath=['artifact:*.cef.destinationAddress', 'artifact:*.id']) + + parameters = [] + + # build parameters list for 'run_query_1' call + + phantom.debug("Got the following assets:") + phantom.debug(','.join([x for x in assets])) + + for container_item in container_data_src: + if container_item[0]: + parameters.append({ + 'query': container_item[0], + 'display': "", + 'type': "process", + # context (artifact id) is added to associate results with the artifact + 'context': {'artifact_id': container_item[1]}, + }) + + for container_item in container_data_dst: + if container_item[0]: + parameters.append({ + 'query': container_item[0], + 'display': "", + 'type': "process", + # context (artifact id) is added to associate results with the artifact + 'context': {'artifact_id': container_item[1]}, + }) + + if (parameters): + phantom.act("run query", parameters=parameters, assets=assets, name="run_query_1") + else: + phantom.error("'run_query_1' will not be executed due to lack of parameters") + + return + +def hunt_file_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + + assets = get_specific_assets("hunt file", ["Carbon Black"]) + + if (not assets): + phantom.debug("Carbon Black::hunt file not found returning.") + + # collect data for 'hunt_file_1' call + container_data = phantom.collect2(container=container, datapath=['artifact:*.cef.fileHash', 'artifact:*.id']) + + parameters = [] + + # build parameters list for 'hunt_file_1' call + for container_item in container_data: + if container_item[0]: + parameters.append({ + 'hash': container_item[0], + 'range': "", + 'type': "binary", + # context (artifact id) is added to associate results with the artifact + 'context': {'artifact_id': container_item[1]}, + }) + + if parameters: + phantom.act("hunt file", parameters=parameters, assets=assets, name="hunt_file_1", callback=filter_4) + else: + phantom.error("'hunt_file_1' will not be executed due to lack of parameters") + + return + +def on_finish(container, summary): + phantom.debug('on_finish() called') + # This function is called after all actions are completed. + # summary of all the action and/or all details of actions + # can be collected here. + + # summary_json = phantom.get_summary() + # if 'result' in summary_json: + # for action_result in summary_json['result']: + # if 'action_run_id' in action_result: + # action_results = phantom.get_action_results(action_run_id=action_result['action_run_id'], result_data=False, flatten=False) + # phantom.debug(action_results) + + return \ No newline at end of file diff --git a/playbooks/hunting.yml b/playbooks/hunting.yml new file mode 100644 index 0000000000..4dc40bc20b --- /dev/null +++ b/playbooks/hunting.yml @@ -0,0 +1,24 @@ +name: Hunting +id: fb3edc76-ff2b-48b0-5f6f-63da6351ad63 +version: 1 +date: '2021-01-21' +author: Philip Royer, Splunk +type: Investigation +description: The hunting Playbook queries a number of internal security technologies in order to determine if any of the artifacts present in your data source have been observed in your environment. +playbook: hunting +how_to_implement: "Be sure to update asset naming to reflect the asset names configured in your environment." +references: [] +app_list: +- "Splunk" +- "Reversing Labs" +- "CarbonBlack Response" +- "Threat Grid" +- "Falcon Host API" +tags: + platform_tags: [] + playbook_type: Automation + playbook_fields: + - fileHash + - vault_id + product: + - Splunk SOAR \ No newline at end of file