mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
updating src files
This commit is contained in:
@@ -199,7 +199,7 @@ category = Malware
|
||||
creation_date = 2019-01-29
|
||||
data_models = ["Alerts", "Authentication", "Network_Traffic", "Risk", "Vulnerabilities", "Web"]
|
||||
description = Leverage searches that allow you to detect and investigate unusual activities that relate to the ColdRoot Remote Access Trojan that affects MacOS. An example of some of these activities are changing sensative binaries in the MacOS sub-system, detecting process names and executables associated with the RAT, detecting when a keyboard tab is installed on a MacOS machine and more.
|
||||
id = bd91a2bc-d20b-4f44-a982-1bea98e86390
|
||||
id = ad7eb6e0-f06c-4781-b145-a42bd59c56e9
|
||||
version = 1.0
|
||||
mappings = {"mitre_attack": ["Command and Control", "Execution", "Collection", "Persistence"], "cis20": ["CIS 4", "CIS 8"], "kill_chain_phases": ["Command and Control", "Installation"], "nist": ["DE.CM", "DE.DP", "PR.PT"]}
|
||||
modification_date = 2019-01-29
|
||||
@@ -368,7 +368,7 @@ data_models = ["Application_State", "Authentication", "Email", "Endpoint", "Netw
|
||||
description = Detect rarely used executables, specific registry paths that may confer malware survivability and persistence, instances where cmd.exe is used to launch script interpreters, and other indicators that the Emotet financial malware has compromised your environment.
|
||||
id = bb9f5ed2-916e-4364-bb6d-91c310efcf52
|
||||
version = 1.0
|
||||
mappings = {"mitre_attack": ["Third-party Software", "AppInit DLLs", "Commonly Used Port", "Command-Line Interface", "Registry Run Keys / Start Folder", "Persistence", "Defense Evasion", "Execution", "Authentication Package", "Account Discovery"], "cis20": ["CIS 7", "CIS 12", "CIS 2", "CIS 3", "CIS 8"], "kill_chain_phases": ["Exploitation", "Delivery", "Installation", "Command and Control", "Actions on Objectives"], "nist": ["ID.AM", "PR.DS", "PR.IP", "PR.PT", "DE.AE", "DE.CM"]}
|
||||
mappings = {"mitre_attack": ["Third-party Software", "AppInit DLLs", "Commonly Used Port", "Command-Line Interface", "Registry Run Keys / Start Folder", "Persistence", "Defense Evasion", "Execution", "Authentication Package", "Account Discovery"], "cis20": ["CIS 7", "CIS 12", "CIS 2", "CIS 3", "CIS 8"], "kill_chain_phases": ["Exploitation", "Actions on Objectives", "Delivery", "Installation", "Command and Control"], "nist": ["ID.AM", "PR.DS", "PR.IP", "PR.PT", "DE.AE", "DE.CM"]}
|
||||
modification_date = 2018-12-03
|
||||
reference = ["https://www.us-cert.gov/ncas/alerts/TA18-201A", "https://www.first.org/resources/papers/conf2017/Advanced-Incident-Detection-and-Threat-Hunting-using-Sysmon-and-Splunk.pdf", "https://www.vkremez.com/2017/05/emotet-banking-trojan-malware-analysis.html"]
|
||||
providing_technologies = ["Bluecoat", "Bro", "Carbon Black Response", "CrowdStrike Falcon", "Linux", "Microsoft Exchange", "Microsoft Windows", "Palo Alto Firewall", "Splunk Enterprise Security", "Splunk Stream", "Sysmon", "Tanium", "Ziften", "macOS"]
|
||||
@@ -627,7 +627,7 @@ data_models = ["Application_State", "Authentication", "Endpoint", "Risk"]
|
||||
description = Monitor your environment for suspicious behaviors that resemble the techniques employed by the MUDCARP threat group.
|
||||
id = 988C59C5-0A1C-45B6-A555-0C62276E327E
|
||||
version = 1.0
|
||||
mappings = {"mitre_attack": ["AppInit DLLs", "Command-Line Interface", "Registry Run Keys / Start Folder", "Scripting", "Authentication Package", "Execution", "PowerShell", "Persistence"], "cis20": ["CIS 7", "CIS 3", "CIS 8"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "nist": ["PR.PT", "DE.AE", "DE.CM", "PR.IP"]}
|
||||
mappings = {"mitre_attack": ["AppInit DLLs", "Command-Line Interface", "Registry Run Keys / Start Folder", "Persistence", "Authentication Package", "Execution", "PowerShell", "Scripting"], "cis20": ["CIS 7", "CIS 3", "CIS 8"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "nist": ["PR.PT", "DE.AE", "DE.CM", "PR.IP"]}
|
||||
modification_date = 2018-12-03
|
||||
reference = ["https://intelgraph.idefense.com/#/node/threat_group/view/29fbec10-8cc8-4662-8362-2c24c1eeb74c", "https://intelgraph.idefense.com/#/node/intelligence_alert/view/62bb3669-9386-4264-b51a-59876cf50ffe", "http://blog.amossys.fr/badflick-is-not-so-bad.html"]
|
||||
providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Linux", "Microsoft Windows", "Splunk Enterprise Security", "Sysmon", "Tanium", "Ziften", "macOS"]
|
||||
@@ -698,7 +698,7 @@ data_models = ["Application_State", "Authentication", "Network_Resolution", "Net
|
||||
description = Detect instances of prohibited network traffic allowed in the environment, as well as protocols running on non-standard ports. Both of these types of behaviors typically violate policy and can be leveraged by attackers.
|
||||
id = 6d13121c-90f3-446d-8ac3-27efbbc65218
|
||||
version = 1.0
|
||||
mappings = {"mitre_attack": ["Command and Control", "Exfiltration Over Command and Control Channel", "Commonly Used Port", "Exfiltration Over Alternative Protocol", "Exfiltration", "Defense Evasion"], "cis20": ["CIS 12", "CIS 13", "CIS 8", "CIS 9"], "kill_chain_phases": ["Command and Control", "Delivery", "Actions on Objectives"], "nist": ["PR.PT", "DE.AE", "DE.CM", "PR.AC", "PR.DS"]}
|
||||
mappings = {"mitre_attack": ["Command and Control", "Exfiltration Over Command and Control Channel", "Commonly Used Port", "Exfiltration Over Alternative Protocol", "Exfiltration", "Defense Evasion"], "cis20": ["CIS 12", "CIS 13", "CIS 8", "CIS 9"], "kill_chain_phases": ["Command and Control", "Actions on Objectives", "Delivery"], "nist": ["PR.PT", "DE.AE", "DE.CM", "PR.AC", "PR.DS"]}
|
||||
modification_date = 2018-07-24
|
||||
reference = ["http://www.novetta.com/2015/02/advanced-methods-to-detect-advanced-cyber-attacks-protocol-abuse/"]
|
||||
providing_technologies = ["Bluecoat", "Bro", "Linux", "Microsoft Windows", "Palo Alto Firewall", "Splunk Enterprise Security", "Splunk Stream", "macOS"]
|
||||
|
||||
+525
-525
File diff suppressed because it is too large
Load Diff
+1722
-1722
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user