Commit Graph

132 Commits

Author SHA1 Message Date
P4T12ICK 2861d04434 merged with ba ocsf work 2023-03-03 13:28:14 +01:00
P4T12ICK 78909f6429 merged with develop 2023-03-03 12:40:16 +01:00
P4T12ICK d115bfd4e0 converted ssa detections to ocsf 2023-02-28 12:00:16 +01:00
P4T12ICK fd0c8b349f updated tags 2023-01-09 09:33:30 +01:00
P4T12ICK 5ae53c9368 Migrated all detections to v4 2023-01-03 13:42:10 +01:00
Michael Haag c6db7b5415 CISA AA22-320A 2022-11-16 12:10:42 -07:00
Michael Haag 2fa429127b CISA AA22-257A tag 2022-09-15 10:07:38 -06:00
d1vious f5a53d0a64 fixing base on feedback from users 2022-07-28 13:48:29 -04:00
d1vious 3c62e835df removing 2022-07-19 12:59:03 -04:00
pyth0n1c a11c62e121 Branch was auto-updated. 2022-06-28 11:33:22 -07:00
d1vious 3bd6477ec7 moving complex pipelines to deprecated 2022-06-28 14:13:38 -04:00
pyth0n1c dd922baf2a Branch was auto-updated. 2022-05-16 13:53:47 -04:00
d1vious 5b9febe81a removing all the stuff in bin 2022-05-03 14:18:22 -04:00
pyth0n1c 578e6bb088 Updated a very large number of detections whose references were returning HTTP Status 301 - resource moved. For example, this includes a large number of fireeye reports, which are now under mandiant, cobaltstrike info, and microsoft links. 2022-05-02 17:12:50 -07:00
mhaag-spl 305a20bc54 Hunting
Changed to hunting, added renamed logic to not use the process_macro

Issue #2010
2022-04-07 14:39:56 -06:00
Rod Soto b3cd632c29 hermeticwipertagswindowsprivesc 2022-04-05 07:55:03 -07:00
Rod Soto 8298acf18e powershelldetectionstaghermetic 2022-03-31 15:29:51 -07:00
Lou Stella 41b3c74785 Migrated old detections to new story 2022-03-28 13:23:02 -05:00
patel-bhavin 99829330c1 all the changes again 2022-03-16 13:35:48 -07:00
P4T12ICK 5dd13ea167 fix broken detections 2022-03-14 15:51:05 +01:00
P4T12ICK e6c8254ede Added automaticc generation of finding report 2022-03-14 12:12:48 +01:00
P4T12ICK 6f0ee68913 Refactored security content 2022-03-09 14:43:09 +01:00
Jose Enrique Hernandez d78bb53baa Revert "Refactored security content" 2022-03-04 15:13:04 -05:00
P4T12ICK 68543a8dc1 merged with develop 2022-03-03 13:11:56 +01:00
research bot 5c8268f137 updating docs and package bits [ci skip] 2022-02-15 23:10:10 +00:00
pyth0n1c b42ec08d85 Fixed spacing on detection_of_dns_tunnels.yml
Added line was too long.
2022-02-15 10:39:23 -08:00
pyth0n1c 1035b056b7 Branch was auto-updated. 2022-02-15 10:30:08 -08:00
patel-bhavin e99b973973 note updadte 2022-02-15 10:27:42 -08:00
patel-bhavin 085cec0b0d adding note 2022-02-15 10:26:12 -08:00
pyth0n1c e01f9b37a4 Branch was auto-updated. 2022-02-09 10:11:43 -08:00
mhaag-spl 0fa295eee0 Ordinal 2022-02-09 08:01:49 -07:00
research bot 3212249c52 updating docs and package bits [ci skip] 2022-02-07 21:03:48 +00:00
P4T12ICK 1d880e6b0e merged with latest content and fixed bugs 2022-02-07 15:58:50 +01:00
P4T12ICK 5fbff3630e merged with develop 2022-02-07 14:55:34 +01:00
P4T12ICK f9468a908a generate SSA package 2022-02-02 08:41:54 +01:00
mhaag-spl e8dd9051bc pkexec
Deprecating two detections that identified all rundll32 executions.
Added linux pkexec pwnkit detection.
2022-02-01 09:52:52 -07:00
P4T12ICK 4fd8604b9a removed SAAWS and automated_detection_testing flag 2022-01-27 09:50:45 +01:00
P4T12ICK a95e0e5aa6 fixed detections metadata 2022-01-20 13:42:50 +01:00
P4T12ICK 6e34aa9cc8 fixed more detections 2022-01-18 13:58:57 +01:00
P4T12ICK 84092434a2 fixed more detections 2022-01-18 12:53:54 +01:00
d1vious 2d3acc2019 moved detections to deprecated 2022-01-10 18:11:10 -05:00
d1vious ede5fd35af moving ssa detection deprecated 2022-01-10 18:06:45 -05:00
research bot ff3319329e updating docs and package bits [ci skip] 2021-12-15 02:58:27 +00:00
mhaag-spl 370ef774ed minor fixes - passed validate 2021-12-03 06:01:32 -07:00
mhaag-spl c21877ceb8 A Nightmare on Haag Street
## Updated Analytics
Attempt To Delete Services
Attempt To Disable Services
Attempted Credential Dump From Registry via Reg exe
Delete a net user
Deny Permission using Cacls Utility
Detect Dump LSASS Memory using comsvcs
Disable Net User Account
First time seen command line argument
Grant Permission Using Cacls Utility
Prohibited apps spawning cmdprompt
Potential Pass the Token or Hash Observed at the Destination Device
Rare Parent-Child Process Relationship
ptt pth kerb ntlm origin device
Resize Shadowstorage Volume
sdelete application execution

## Deprecated BA Analytics
ssa___applying_stolen_credentials_via_mimikatz_modules.yml
ssa___applying_stolen_credentials_via_powersploit_modules.yml
ssa___assess_credential_strength_via_dsinternals_modules.yml
ssa___credential_extraction_dsinternals_conversion_modules.yml
Ssa___credential_extraction_dsinternals_modules.yml
Ssa___credential_extraction_getaddbaccount_from_dump.yml
Ssa___credential_extraction_powersploit_modules.yml
ssa___illegal_access_user_content_via_powersploit_modules.yml
ssa___illegal_account_creation_via_powersploit_modules.yml
ssa___illegal_account_enable_disable_via_dsinternals_modules.yml
ssa___illegal_log_deletion_via_mimikatz_modules.yml
ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml
ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml
Ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml
ssa___illegal_privilege_elevation_via_mimikatz_modules.yml
ssa___illegal_service_and_process_control_via_mimikatz_modules.yml
ssa___illegal_service_and_process_control_via_powersploit_modules.yml
Ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml
ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml
ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml
ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml
ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml
ssa___recon_and_use_computers_domains_via_powersploit_modules.yml
ssa___recon_and_use_computers_via_mimikatz_modules.yml
ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml
ssa___recon_and_use_shares_via_mimikatz_modules.yml
ssa___recon_and_use_shares_via_powersploit_modules.yml
Ssa___recon_connectivity_via_powersploit_modules.yml
ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml
ssa___recon_defensive_tools_via_powersploit_modules.yml
ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml
ssa___recon_process_service_hijacking_via_mimikatz_modules.yml
ssa___recon_processes_and_services_via_mimikatz_modules.yml
ssa___setting_credentials_via_dsinternals_modules.yml
ssa___setting_credentials_via_mimikatz_modules.yml
ssa___setting_credentials_via_powersploit_modules.yml

ssa___credential_extraction_fgdump_cachedump_s_option.yml
Ssa___credential_extraction_fgdump_cachedump_v_option.yml
ssa___credential_extraction_ms_debuggers_kernel_peek.yml
ssa___credential_extraction_ms_debuggers_z_option.yml
Ssa___credential_extraction_lazagne_command_options.yml
2021-12-03 05:57:54 -07:00
research bot 750c81fb5b updating docs and package bits [ci skip] 2021-12-02 18:50:01 +00:00
David Dorsey 27f5949819 Merge branch 'develop' into ssa_why_chrome_why 2021-11-11 18:04:06 -06:00
Xiao Lin aff959cb32 deprecate detect_pass_hash 2021-11-10 11:18:34 -08:00
research bot a1afa0fa60 updating docs and package bits [ci skip] 2021-10-28 19:55:37 +00:00
Drew Church 3b18c5abcb Added CVE tags to 35 files 2021-10-22 10:03:24 -07:00