Commit Graph

580 Commits

Author SHA1 Message Date
Ignacio 25b0334c73 Merge branch 'develop' into add_gitlab_ci 2020-10-26 08:41:24 -07:00
Ignacio Bermudez Corrales 9d139764bf fixed tests 2020-10-22 14:30:14 -07:00
Xiao Lin 91240efdab Merge branch 'develop' of github.com:splunk/security-content into tf23 2020-10-21 13:09:22 -07:00
Stanislav Miskovic 3984d0e5b4 Fixing detection categories and polishing some descriptions in Credential Extraction detections. 2020-10-20 13:20:25 -07:00
Bhavin Patel 8fef4fe2fe Merge pull request #775 from splunk/improved_kerberoasting_attack
Automated Detection Testing PR improved_kerberoasting_attack
2020-10-20 11:01:40 -07:00
Bhavin Patel 7a45ca7143 Merge pull request #774 from splunk/pass_the_hash_detection
Automated Detection Testing PR pass_the_hash_detection
2020-10-20 10:55:43 -07:00
Bhavin Patel 8210804332 Merge branch 'develop' into improved_kerberoasting_attack 2020-10-20 10:54:22 -07:00
peter 822d26dceb Merge branch 'develop' into misko_cred_extract_ssa 2020-10-19 16:24:52 -07:00
peter-cg 64e6680aca Fixed a couple typos 2020-10-19 16:23:48 -07:00
Jose Enrique Hernandez ca119d7cb5 Merge branch 'develop' into improved_kerberoasting_attack 2020-10-19 17:29:03 -04:00
Jose Enrique Hernandez ade78957f1 Merge branch 'develop' into lolbas-fixes 2020-10-19 17:19:18 -04:00
bpatel 988d123704 reorg dir 2020-10-19 10:10:09 -07:00
Bhavin Patel 029f0afff3 Merge branch 'develop' into gcploit 2020-10-19 10:08:21 -07:00
Stanislav Miskovic 3a65129f5c Removed non-alphanumeric characters from detection names 2020-10-19 09:47:34 -07:00
Stanislav Miskovic 8aa5392c50 Adding SSA detections for credential extraction from dumped secure stores or live Windows systems. 2020-10-19 01:42:14 -07:00
Stanislav Miskovic 6d76a4d268 Fix:
1) Adding both long and short name registry section names for Security, SAM and System
2) Adding a condition that command line marameter is not null (faster exit in case customer is not logging command lines)
2020-10-18 22:46:39 -07:00
Stanislav Miskovic c457ba1ce2 We need to do 2 fixes here:
1) comma sign is also possible between "comsvcs.dll" "MiniDump" in execution of this attack as described in https://risksense.com/blog/hidden-gems-in-windows-the-hunt-is-on/ and https://www.ired.team/offensive-security/credential-access-and-credential-dumping/dump-credentials-from-lsass-process-without-mimikatz and our notebook https://confluence.splunk.com/display/~smiskovic/Test+Events+for+SSA+Detections#TestEventsforSSADetections-DumpingLSASSprocessmemory, and

2) referenced pdf does not contain this detection (will fix this later when I make my notebook public, so we do not need to refer any external companies)
2020-10-18 22:23:18 -07:00
Xiao Lin 172b5e7d67 update to TF2.3 2020-10-17 00:21:28 -07:00
Ignacio Bermudez Corrales 43392488ee Merge remote-tracking branch 'origin/develop' into lolbas-fixes 2020-10-16 14:59:31 -07:00
peter-cg 02f8891e3b Merge remote-tracking branch 'origin/develop' into TR-193 2020-10-16 11:33:17 -07:00
Ignacio d857af2a0a Merge branch 'develop' into lolbas-fixes 2020-10-16 10:01:17 -07:00
root 85146bd2b8 Added detection testing service results inKerberoasting spn request with RC4 encryption 2020-10-16 09:57:44 +00:00
P4T12ICK d788863bca fixed kerberoasting detection 2020-10-16 11:29:46 +02:00
root 6555e32674 Added detection testing service results inDetect Activity Related to Pass the Hash Attacks 2020-10-16 08:43:40 +00:00
P4T12ICK 7fe760cf54 rebased with develop 2020-10-16 09:52:08 +02:00
P4T12ICK 1e392e631c improvment pth detection 2020-10-16 09:49:11 +02:00
Ignacio Bermudez Corrales 7981684b5f Merge branch 'lolbas-fixes' of github.com:splunk/security-content into lolbas-fixes 2020-10-15 14:54:18 -07:00
Ignacio Bermudez Corrales e04592401b unusual lolbas short time period 2020-10-15 14:53:59 -07:00
Jose Enrique Hernandez 8520f3a281 Merge branch 'develop' into lolbas-fixes 2020-10-15 17:14:34 -04:00
Ignacio Bermudez Corrales 5da1fde8cf Added notebook 2020-10-15 13:15:17 -07:00
Jose Enrique Hernandez 78784320fd Merge branch 'develop' into unit_test_prohibited_apps_spawning_cmdprompt 2020-10-15 16:04:26 -04:00
divious1 3113cff22c updating a mistake in sysmon 2020-10-15 16:04:01 -04:00
Xiao Lin a035e6311f change single quotation mark to back single quotation 2020-10-15 19:47:12 +00:00
Xiao Lin 98b7aa83dd update 2020-10-15 19:47:12 +00:00
Xiao Lin 9db448a52e update unit test 2020-10-15 19:47:12 +00:00
P4T12ICK 2f9fe75f9c Improved and tested pass the hash detection 2020-10-15 14:35:53 +02:00
Ignacio Bermudez Corrales c0e034ad04 fixed yaml and changed output for label 2020-10-15 01:43:56 -07:00
Ignacio Bermudez Corrales 8b52241175 fixed syntax 2020-10-14 09:53:15 -07:00
P4T12ICK 6938154a94 ready for PR 2020-10-14 16:13:55 +02:00
root 6aae51fa5c Added detection testing service results inSystem Information Discovery Detection 2020-10-14 12:23:58 +00:00
P4T12ICK c23fe12605 updated with develop 2020-10-14 09:26:19 +02:00
P4T12ICK 323138fe5f improved detection 2020-10-14 09:22:03 +02:00
Jose Enrique Hernandez b8ca9e5fd9 Merge branch 'develop' into gcploit 2020-10-13 22:08:22 -04:00
divious1 dca8fad264 Merge branch 'develop' into organize_detections 2020-10-13 20:19:08 -04:00
root 743ada6db8 Added detection testing service results inSystem Information Discovery Detection 2020-10-13 17:50:09 +00:00
P4T12ICK c19f355fb8 testing 2020-10-13 19:15:56 +02:00
P4T12ICK eeed5fb0b8 testing 2020-10-13 19:06:26 +02:00
root 565c8610cd Added detection testing service results inSystem Information Discovery Detection 2020-10-13 15:40:24 +00:00
root b355f71dbd Added detection testing service results inSystem Information Discovery Detection 2020-10-13 14:54:12 +00:00
P4T12ICK 1661a807f5 test 2020-10-13 14:56:54 +02:00