updating src files

This commit is contained in:
research bot
2019-02-06 22:24:59 +00:00
parent 0c7cd53e4b
commit fa77807a02
3 changed files with 2251 additions and 2251 deletions
+4 -4
View File
@@ -199,7 +199,7 @@ category = Malware
creation_date = 2019-01-29
data_models = ["Alerts", "Authentication", "Network_Traffic", "Risk", "Vulnerabilities", "Web"]
description = Leverage searches that allow you to detect and investigate unusual activities that relate to the ColdRoot Remote Access Trojan that affects MacOS. An example of some of these activities are changing sensative binaries in the MacOS sub-system, detecting process names and executables associated with the RAT, detecting when a keyboard tab is installed on a MacOS machine and more.
id = bd91a2bc-d20b-4f44-a982-1bea98e86390
id = ad7eb6e0-f06c-4781-b145-a42bd59c56e9
version = 1.0
mappings = {"mitre_attack": ["Command and Control", "Execution", "Collection", "Persistence"], "cis20": ["CIS 4", "CIS 8"], "kill_chain_phases": ["Command and Control", "Installation"], "nist": ["DE.CM", "DE.DP", "PR.PT"]}
modification_date = 2019-01-29
@@ -368,7 +368,7 @@ data_models = ["Application_State", "Authentication", "Email", "Endpoint", "Netw
description = Detect rarely used executables, specific registry paths that may confer malware survivability and persistence, instances where cmd.exe is used to launch script interpreters, and other indicators that the Emotet financial malware has compromised your environment.
id = bb9f5ed2-916e-4364-bb6d-91c310efcf52
version = 1.0
mappings = {"mitre_attack": ["Third-party Software", "AppInit DLLs", "Commonly Used Port", "Command-Line Interface", "Registry Run Keys / Start Folder", "Persistence", "Defense Evasion", "Execution", "Authentication Package", "Account Discovery"], "cis20": ["CIS 7", "CIS 12", "CIS 2", "CIS 3", "CIS 8"], "kill_chain_phases": ["Exploitation", "Delivery", "Installation", "Command and Control", "Actions on Objectives"], "nist": ["ID.AM", "PR.DS", "PR.IP", "PR.PT", "DE.AE", "DE.CM"]}
mappings = {"mitre_attack": ["Third-party Software", "AppInit DLLs", "Commonly Used Port", "Command-Line Interface", "Registry Run Keys / Start Folder", "Persistence", "Defense Evasion", "Execution", "Authentication Package", "Account Discovery"], "cis20": ["CIS 7", "CIS 12", "CIS 2", "CIS 3", "CIS 8"], "kill_chain_phases": ["Exploitation", "Actions on Objectives", "Delivery", "Installation", "Command and Control"], "nist": ["ID.AM", "PR.DS", "PR.IP", "PR.PT", "DE.AE", "DE.CM"]}
modification_date = 2018-12-03
reference = ["https://www.us-cert.gov/ncas/alerts/TA18-201A", "https://www.first.org/resources/papers/conf2017/Advanced-Incident-Detection-and-Threat-Hunting-using-Sysmon-and-Splunk.pdf", "https://www.vkremez.com/2017/05/emotet-banking-trojan-malware-analysis.html"]
providing_technologies = ["Bluecoat", "Bro", "Carbon Black Response", "CrowdStrike Falcon", "Linux", "Microsoft Exchange", "Microsoft Windows", "Palo Alto Firewall", "Splunk Enterprise Security", "Splunk Stream", "Sysmon", "Tanium", "Ziften", "macOS"]
@@ -627,7 +627,7 @@ data_models = ["Application_State", "Authentication", "Endpoint", "Risk"]
description = Monitor your environment for suspicious behaviors that resemble the techniques employed by the MUDCARP threat group.
id = 988C59C5-0A1C-45B6-A555-0C62276E327E
version = 1.0
mappings = {"mitre_attack": ["AppInit DLLs", "Command-Line Interface", "Registry Run Keys / Start Folder", "Scripting", "Authentication Package", "Execution", "PowerShell", "Persistence"], "cis20": ["CIS 7", "CIS 3", "CIS 8"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "nist": ["PR.PT", "DE.AE", "DE.CM", "PR.IP"]}
mappings = {"mitre_attack": ["AppInit DLLs", "Command-Line Interface", "Registry Run Keys / Start Folder", "Persistence", "Authentication Package", "Execution", "PowerShell", "Scripting"], "cis20": ["CIS 7", "CIS 3", "CIS 8"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "nist": ["PR.PT", "DE.AE", "DE.CM", "PR.IP"]}
modification_date = 2018-12-03
reference = ["https://intelgraph.idefense.com/#/node/threat_group/view/29fbec10-8cc8-4662-8362-2c24c1eeb74c", "https://intelgraph.idefense.com/#/node/intelligence_alert/view/62bb3669-9386-4264-b51a-59876cf50ffe", "http://blog.amossys.fr/badflick-is-not-so-bad.html"]
providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Linux", "Microsoft Windows", "Splunk Enterprise Security", "Sysmon", "Tanium", "Ziften", "macOS"]
@@ -698,7 +698,7 @@ data_models = ["Application_State", "Authentication", "Network_Resolution", "Net
description = Detect instances of prohibited network traffic allowed in the environment, as well as protocols running on non-standard ports. Both of these types of behaviors typically violate policy and can be leveraged by attackers.
id = 6d13121c-90f3-446d-8ac3-27efbbc65218
version = 1.0
mappings = {"mitre_attack": ["Command and Control", "Exfiltration Over Command and Control Channel", "Commonly Used Port", "Exfiltration Over Alternative Protocol", "Exfiltration", "Defense Evasion"], "cis20": ["CIS 12", "CIS 13", "CIS 8", "CIS 9"], "kill_chain_phases": ["Command and Control", "Delivery", "Actions on Objectives"], "nist": ["PR.PT", "DE.AE", "DE.CM", "PR.AC", "PR.DS"]}
mappings = {"mitre_attack": ["Command and Control", "Exfiltration Over Command and Control Channel", "Commonly Used Port", "Exfiltration Over Alternative Protocol", "Exfiltration", "Defense Evasion"], "cis20": ["CIS 12", "CIS 13", "CIS 8", "CIS 9"], "kill_chain_phases": ["Command and Control", "Actions on Objectives", "Delivery"], "nist": ["PR.PT", "DE.AE", "DE.CM", "PR.AC", "PR.DS"]}
modification_date = 2018-07-24
reference = ["http://www.novetta.com/2015/02/advanced-methods-to-detect-advanced-cyber-attacks-protocol-abuse/"]
providing_technologies = ["Bluecoat", "Bro", "Linux", "Microsoft Windows", "Palo Alto Firewall", "Splunk Enterprise Security", "Splunk Stream", "macOS"]
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff