From facc82325551ef44ce98dfbdfbde2c1e035cb3db Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Thu, 3 Jun 2021 14:20:59 -0600 Subject: [PATCH] Updated Analytic Stories --- detections/endpoint/detect_psexec_with_accepteula_flag.yml | 1 + detections/endpoint/detect_renamed_psexec.yml | 1 + detections/endpoint/detect_sharphound_command_line_arguments.yml | 1 + detections/endpoint/detect_sharphound_file_modifications.yml | 1 + detections/endpoint/detect_sharphound_usage.yml | 1 + 5 files changed, 5 insertions(+) diff --git a/detections/endpoint/detect_psexec_with_accepteula_flag.yml b/detections/endpoint/detect_psexec_with_accepteula_flag.yml index d257cbbeff..4853444bb1 100644 --- a/detections/endpoint/detect_psexec_with_accepteula_flag.yml +++ b/detections/endpoint/detect_psexec_with_accepteula_flag.yml @@ -35,6 +35,7 @@ tags: - DHS Report TA18-074A - HAFNIUM Group - DarkSide Ransomware + - Lateral Movement asset_type: Endpoint automated_detection_testing: passed cis20: diff --git a/detections/endpoint/detect_renamed_psexec.yml b/detections/endpoint/detect_renamed_psexec.yml index 41bbe076ed..c680170fbe 100644 --- a/detections/endpoint/detect_renamed_psexec.yml +++ b/detections/endpoint/detect_renamed_psexec.yml @@ -32,6 +32,7 @@ tags: - DHS Report TA18-074A - HAFNIUM Group - DarkSide Ransomware + - Lateral Movement dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/atomic_red_team/windows-sysmon.log kill_chain_phases: diff --git a/detections/endpoint/detect_sharphound_command_line_arguments.yml b/detections/endpoint/detect_sharphound_command_line_arguments.yml index a8af92e86d..40a71caa63 100644 --- a/detections/endpoint/detect_sharphound_command_line_arguments.yml +++ b/detections/endpoint/detect_sharphound_command_line_arguments.yml @@ -31,6 +31,7 @@ references: tags: analytic_story: - Discovery Techniques + - Ransomware dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log kill_chain_phases: diff --git a/detections/endpoint/detect_sharphound_file_modifications.yml b/detections/endpoint/detect_sharphound_file_modifications.yml index f8595c2a4d..cd97b9e36d 100644 --- a/detections/endpoint/detect_sharphound_file_modifications.yml +++ b/detections/endpoint/detect_sharphound_file_modifications.yml @@ -41,6 +41,7 @@ references: tags: analytic_story: - Discovery Techniques + - Ransomware dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log kill_chain_phases: diff --git a/detections/endpoint/detect_sharphound_usage.yml b/detections/endpoint/detect_sharphound_usage.yml index 815ba5b41c..5cac410070 100644 --- a/detections/endpoint/detect_sharphound_usage.yml +++ b/detections/endpoint/detect_sharphound_usage.yml @@ -34,6 +34,7 @@ references: tags: analytic_story: - Discovery Techniques + - Ransomware dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log kill_chain_phases: