Commit Graph

114 Commits

Author SHA1 Message Date
Ignacio 4e5b26e322 Merge branch 'develop' into misko_credential_probing 2020-11-18 11:30:43 -08:00
Bhavin Patel c8710c17ad Merge pull request #893 from davisshannon/develop
Data Exfil PR (fixed up)
2020-11-18 11:30:10 -08:00
Ignacio 9b8bc3ceaf Merge branch 'develop' into misko_credential_probing 2020-11-18 11:25:16 -08:00
Jose Enrique Hernandez 3c1cfbf4de Merge branch 'develop' into develop 2020-11-18 13:30:38 -05:00
Jose Enrique Hernandez 7d64ec2884 Merge branch 'develop' into misko_recon_use_cases 2020-11-18 12:22:12 -05:00
Ignacio 1db0cb220e Merge branch 'develop' into misko_credential_probing 2020-11-17 08:58:17 -08:00
Jose Enrique Hernandez 3e9513f4b8 Merge branch 'develop' into develop 2020-11-11 22:04:16 -05:00
Jose Enrique Hernandez 4acc8c3efb Merge branch 'develop' into mbjerkeland-develop 2020-11-11 22:03:44 -05:00
Xiao Lin e7e659e882 Merge branch 'develop' of github.com:splunk/security-content into TR162 2020-11-11 23:25:18 +00:00
Stanislav Miskovic 2b64634e2f Fix - renaming and providing adequate test set for log deletion detection (this was Mimikatz detection, not PowerSploit one) 2020-11-10 19:01:01 -08:00
Jose Enrique Hernandez dc7d3bf9ea Merge branch 'develop' into misko_illegal_management 2020-11-10 19:21:33 -05:00
Stanislav Miskovic 1969d4a9ab Illegal control of compromised resources via Mimikatz, PowerSploit and DSInternals modules 2020-11-10 00:58:27 -08:00
Mikael Bjerkeland 3675fa80ad Rename 2020-11-10 09:37:33 +01:00
P4T12ICK 1f3f1ae408 Merge branch 'develop' into mbjerkeland-develop 2020-11-10 09:24:55 +01:00
Xiao Lin 09c43eff66 Merge branch 'develop' of github.com:splunk/security-content into TR162 2020-11-09 18:10:02 +00:00
P4T12ICK ca7c9c878e detection test 2020-11-09 16:41:09 +01:00
P4T12ICK 87a7d64d66 new tests 2020-11-09 13:25:27 +01:00
P4T12ICK 079742338b deleting shadow copy test 2020-11-09 10:38:40 +01:00
Mikael Bjerkeland fb0398fafb Added test 2020-11-09 10:12:52 +01:00
P4T12ICK f7fad21b02 ransomware notes test 2020-11-09 09:36:01 +01:00
P4T12ICK 66e2341012 ransomware extension 2020-11-09 09:26:04 +01:00
Stanislav Miskovic fbb5ee4c7f Reconnaissance - adding detections for AD infrastructure, network connectivity, computers, domains, processes, services, registry, shares, etc. 2020-11-06 18:15:45 -08:00
Stanislav Miskovic 6eadeb857b Fix: Slip in renaming of tests 2020-11-06 15:01:54 -08:00
Stanislav Miskovic 391bb12781 Fix: File names of recon and use detections 2020-11-06 11:48:29 -08:00
P4T12ICK 85f349668c new detection testing file 2020-11-06 13:43:49 +01:00
P4T12ICK ee59a8150b new test file 2020-11-06 13:26:45 +01:00
Stanislav Miskovic b988641071 Reconnaissance and access to accounts groups and policies via Mimikatz and PowerSploit modules 2020-11-05 23:10:53 -08:00
Stanislav Miskovic 9b5ccc2f93 Adding Reconnaissance of Credential Stores and Services via Mimikatz modules 2020-11-05 19:12:04 -08:00
Shannon Davis 1ab400a565 mods 2020-11-06 10:57:35 +11:00
Stanislav Miskovic 5e845f4b3d Probing access and credential strength with stolen credentials 2020-11-05 09:46:23 -08:00
Xiao Lin 811ba865fa change test files to use ssa prefix 2020-11-05 17:36:30 +00:00
Xiao Lin fa2ca47546 test yml 2020-11-05 17:03:54 +00:00
Xiao Lin 04f8db150a Merge branch 'develop' of github.com:splunk/security-content into TR162 2020-11-04 22:40:23 +00:00
Jose Enrique Hernandez db0e7bd862 Merge branch 'develop' into misko_apply_set_stolen_credentials 2020-11-04 14:40:49 -05:00
Jose Enrique Hernandez c7b8e7166f Merge pull request #816 from splunk/misko_cred_extract_APIs_and_Filenames
Credential Extraction detected via common exploit modules ...
2020-11-04 14:03:02 -05:00
jzsplunk 7434975199 Merge branch 'develop' into misko_apply_set_stolen_credentials 2020-11-04 10:03:17 -08:00
Jose Enrique Hernandez c25465c174 Merge branch 'develop' into misko_cred_extract_APIs_and_Filenames 2020-11-04 12:26:48 -05:00
P4T12ICK ac27485034 Merge branch 'develop' into new_test_file_format 2020-11-04 17:58:26 +01:00
Stanislav Miskovic 16821b72b8 Applying and setting stolen cresentials - detections via PowerSploit, Mimikatz and DSInternals APIs 2020-11-04 01:02:47 -08:00
P4T12ICK 15a3dfed60 detection tests 2020-11-03 17:04:53 +01:00
P4T12ICK c952f06956 new format for test files 2020-10-30 09:11:41 +01:00
Stanislav Miskovic 470c94fc90 Credential Extraction: Changing passing condition to a new syntax 2020-10-29 00:42:19 -07:00
Stanislav Miskovic b5707c8e22 Credential Extraction: moving test data from SMLE's to AR's S3 bucket and renaming test links 2020-10-28 11:38:08 -07:00
miskoSplunk 2839525e0c Update and rename credential_extraction_ms_debuggers_z_option.test.yml to ssa___credential_extraction_ms_debuggers_z_option.test.yml 2020-10-28 01:30:16 -07:00
miskoSplunk 67be9820f8 Update and rename credential_extraction_ms_debuggers_kernel_peek.test.yml to ssa___credential_extraction_ms_debuggers_kernel_peek.test.yml 2020-10-28 01:29:01 -07:00
miskoSplunk f47a5e18af Update and rename credential_extraction_lazagne_command_options_ssa.test.yml to ssa___credential_extraction_lazagne_command_options.test.yml 2020-10-28 01:28:21 -07:00
miskoSplunk 2cdefdd198 Update and rename credential_extraction_fgdump_cachedump_v_option_ssa.test.yml to ssa___credential_extraction_fgdump_cachedump_v_option.test.yml 2020-10-28 01:27:38 -07:00
miskoSplunk 5f01133544 Update and rename credential_extraction_fgdump_cachedump_s_option_ssa.test.yml to ssa___credential_extraction_fgdump_cachedump_s_option.test.yml 2020-10-28 01:26:40 -07:00
Xiao Lin daea9d4192 change to use SSA input_event 2020-10-27 22:30:00 +00:00
miskoSplunk 3185517716 Update and rename credential_extraction_powersploit_modules_ssa.test.yml to ssa___credential_extraction_powersploit_modules.test.yml 2020-10-27 15:17:41 -07:00