Commit Graph

2360 Commits

Author SHA1 Message Date
Stanislav Miskovic 1969d4a9ab Illegal control of compromised resources via Mimikatz, PowerSploit and DSInternals modules 2020-11-10 00:58:27 -08:00
Mikael Bjerkeland 3675fa80ad Rename 2020-11-10 09:37:33 +01:00
P4T12ICK 1f3f1ae408 Merge branch 'develop' into mbjerkeland-develop 2020-11-10 09:24:55 +01:00
P4T12ICK 4059b769a2 new detection test 2020-11-10 09:20:22 +01:00
P4T12ICK 70466c9301 new detection test 2020-11-10 09:02:24 +01:00
Jose Enrique Hernandez 54eddbd393 Merge branch 'develop' into ryuktestsfiles 2020-11-09 14:12:10 -05:00
Xiao Lin 09c43eff66 Merge branch 'develop' of github.com:splunk/security-content into TR162 2020-11-09 18:10:02 +00:00
P4T12ICK ca7c9c878e detection test 2020-11-09 16:41:09 +01:00
P4T12ICK 87a7d64d66 new tests 2020-11-09 13:25:27 +01:00
P4T12ICK 079742338b deleting shadow copy test 2020-11-09 10:38:40 +01:00
Mikael Bjerkeland fb0398fafb Added test 2020-11-09 10:12:52 +01:00
P4T12ICK f7fad21b02 ransomware notes test 2020-11-09 09:36:01 +01:00
P4T12ICK 66e2341012 ransomware extension 2020-11-09 09:26:04 +01:00
Rod Soto f8a131528d widowswsecuritysamsearch 2020-11-08 11:30:34 -05:00
Rod Soto e21455a145 fixnamedaddedantispyware 2020-11-08 11:10:49 -05:00
Rod Soto 2fd9f07c75 winconhostryuksearch 2020-11-08 10:57:02 -05:00
Rod Soto 7af33cfd4f ryuktestfilestestfile 2020-11-08 10:27:03 -05:00
Stanislav Miskovic fbb5ee4c7f Reconnaissance - adding detections for AD infrastructure, network connectivity, computers, domains, processes, services, registry, shares, etc. 2020-11-06 18:15:45 -08:00
Stanislav Miskovic 6eadeb857b Fix: Slip in renaming of tests 2020-11-06 15:01:54 -08:00
Stanislav Miskovic 391bb12781 Fix: File names of recon and use detections 2020-11-06 11:48:29 -08:00
P4T12ICK 85f349668c new detection testing file 2020-11-06 13:43:49 +01:00
P4T12ICK ee59a8150b new test file 2020-11-06 13:26:45 +01:00
Stanislav Miskovic b988641071 Reconnaissance and access to accounts groups and policies via Mimikatz and PowerSploit modules 2020-11-05 23:10:53 -08:00
Stanislav Miskovic 9b5ccc2f93 Adding Reconnaissance of Credential Stores and Services via Mimikatz modules 2020-11-05 19:12:04 -08:00
Shannon Davis 1ab400a565 mods 2020-11-06 10:57:35 +11:00
Stanislav Miskovic 5e845f4b3d Probing access and credential strength with stolen credentials 2020-11-05 09:46:23 -08:00
Xiao Lin 811ba865fa change test files to use ssa prefix 2020-11-05 17:36:30 +00:00
Xiao Lin fa2ca47546 test yml 2020-11-05 17:03:54 +00:00
Xiao Lin 04f8db150a Merge branch 'develop' of github.com:splunk/security-content into TR162 2020-11-04 22:40:23 +00:00
Jose Enrique Hernandez db0e7bd862 Merge branch 'develop' into misko_apply_set_stolen_credentials 2020-11-04 14:40:49 -05:00
Jose Enrique Hernandez c7b8e7166f Merge pull request #816 from splunk/misko_cred_extract_APIs_and_Filenames
Credential Extraction detected via common exploit modules ...
2020-11-04 14:03:02 -05:00
jzsplunk 7434975199 Merge branch 'develop' into misko_apply_set_stolen_credentials 2020-11-04 10:03:17 -08:00
Jose Enrique Hernandez c25465c174 Merge branch 'develop' into misko_cred_extract_APIs_and_Filenames 2020-11-04 12:26:48 -05:00
P4T12ICK ac27485034 Merge branch 'develop' into new_test_file_format 2020-11-04 17:58:26 +01:00
Stanislav Miskovic 16821b72b8 Applying and setting stolen cresentials - detections via PowerSploit, Mimikatz and DSInternals APIs 2020-11-04 01:02:47 -08:00
P4T12ICK 15a3dfed60 detection tests 2020-11-03 17:04:53 +01:00
P4T12ICK c952f06956 new format for test files 2020-10-30 09:11:41 +01:00
Stanislav Miskovic 470c94fc90 Credential Extraction: Changing passing condition to a new syntax 2020-10-29 00:42:19 -07:00
Stanislav Miskovic b5707c8e22 Credential Extraction: moving test data from SMLE's to AR's S3 bucket and renaming test links 2020-10-28 11:38:08 -07:00
miskoSplunk 2839525e0c Update and rename credential_extraction_ms_debuggers_z_option.test.yml to ssa___credential_extraction_ms_debuggers_z_option.test.yml 2020-10-28 01:30:16 -07:00
miskoSplunk 67be9820f8 Update and rename credential_extraction_ms_debuggers_kernel_peek.test.yml to ssa___credential_extraction_ms_debuggers_kernel_peek.test.yml 2020-10-28 01:29:01 -07:00
miskoSplunk f47a5e18af Update and rename credential_extraction_lazagne_command_options_ssa.test.yml to ssa___credential_extraction_lazagne_command_options.test.yml 2020-10-28 01:28:21 -07:00
miskoSplunk 2cdefdd198 Update and rename credential_extraction_fgdump_cachedump_v_option_ssa.test.yml to ssa___credential_extraction_fgdump_cachedump_v_option.test.yml 2020-10-28 01:27:38 -07:00
miskoSplunk 5f01133544 Update and rename credential_extraction_fgdump_cachedump_s_option_ssa.test.yml to ssa___credential_extraction_fgdump_cachedump_s_option.test.yml 2020-10-28 01:26:40 -07:00
Xiao Lin daea9d4192 change to use SSA input_event 2020-10-27 22:30:00 +00:00
miskoSplunk 3185517716 Update and rename credential_extraction_powersploit_modules_ssa.test.yml to ssa___credential_extraction_powersploit_modules.test.yml 2020-10-27 15:17:41 -07:00
miskoSplunk 575fd73422 Update and rename credential_extraction_mimikatz_modules_ssa.test.yml to ssa___credential_extraction_mimikatz_modules.test.yml 2020-10-27 15:16:05 -07:00
miskoSplunk 8ec9c06f2e Update and rename credential_extraction_getaddbaccount_from_dump_ssa.test.yml to ssa___credential_extraction_getaddbaccount_from_dump.test.yml 2020-10-27 11:36:01 -07:00
miskoSplunk abf692795d Update and rename credential_extraction_dsinternals_modules_ssa.test.yml to ssa___credential_extraction_dsinternals_modules.test.yml 2020-10-27 11:34:40 -07:00
miskoSplunk 2cd4512d65 Update and rename credential_extraction_dsinternals_conversion_modules_ssa.test.yml to ssa___credential_extraction_dsinternals_conversion_modules.test.yml 2020-10-27 11:32:33 -07:00